Tenvio Docs
Operational boundary

Keep credentials narrow and delivery claims precise.

Tenvio separates sending authority from resource-management authority and applies account isolation at every public resource lookup.

Credential handling

  • Keep tv_live_… and mg_live_… secrets server-side.
  • Never put secrets in browser code, URLs, repositories, logs, screenshots, or support messages.
  • Create named least-privilege management keys per automation and revoke them independently.
  • Give each sending key only send:email, read:email, or both; Free permits one active key and Custom permits five.
  • Rotate an exposed key by stable key ID with a short overlap, verify the replacement, then revoke the old key.

Tenant and resource isolation

Domains, optional external_id values, senders, and email history are account-scoped. Foreign identifiers are indistinguishable from unknown ones. Sending is authorized only for an active sender beneath a ready domain in the same active account.

Data and delivery

Transient email content is encrypted at rest and removed by the retention lifecycle. Delivery history lasts 14 days on Free and 30 days on Custom. Expiry removes child history and clears subject, To/Cc/Bcc addresses, sender display metadata, and attachment filenames from the parent tombstone. Minimal opaque accounting and bounded security/fraud evidence are separate from customer history. An explicit audited legal hold pauses cleanup only for the held submission. accepted means the recipient SMTP server accepted the message. It does not guarantee inbox placement, reading, or downstream handling.

DNS checks

DNS checks use bounded service capacity and a fixed lookup deadline. Temporary resolver failures are preserved as temporary rather than rewritten as missing or invalid configuration. DNS read/write authority is part of the domain scopes.