Security

A pager holds your phone numbers and your worst nights.

Here is how Transmit is built to protect them. Each point below is enforced in code and tested, not just a policy.

Looking for Transmit Mail’s security page? It is atmail.transmit.dev/security.

Practices

Your organization comes from your key

Every API request is scoped to the organization of the key that made it, and every alert to the organization of its integration key. Nothing in a request can name another organization, and a test that tries fails the build.

Keys are stored hashed

API keys and integration keys are kept only as SHA-256 hashes and shown once, when they are made. Only owners and admins can create API keys, from a signed-in session.

One service’s key reaches one service

Integration keys belong to a service. A key for one service cannot open incidents on another, or silence another service’s heartbeat.

Sign in with an emailed code

There are no passwords to reuse or leak. The dashboard keeps its session in an httpOnly cookie on its own server; the token never reaches the browser’s JavaScript.

A link never acknowledges by itself

Mail scanners open every link in an email. The link in a page only shows a confirmation page with no outside scripts; acknowledging takes a button press.

Only verified numbers are paged

Transmit will never text or call a number until its owner confirms a code sent to it, and nobody can confirm a number for someone else. Imported numbers start unverified.

People choose what an organization sees

Someone who joins another organization shares only their sign-in email until they choose to share a contact method with it.

Your Opsgenie key is never stored

The importer uses your Opsgenie key for the import that is running and keeps no copy. It only ever reads from Opsgenie.

Where your data lives

Infrastructure

Services that process Transmit customer data, as of October 2026.
ProviderWhat forWhere
Google CloudAPI, worker and dashboard (Cloud Run), secretsUnited States (us-central1)
PlanetScalePostgres databaseGoogle Cloud, United States (us-central1)
Transmit MailDelivering email pages and sign-in codesUnited States

Data is encrypted in transit with TLS. SMS and voice providers will be listed here before those channels are switched on.

Found something?

If you think you have found a security problem in Transmit, tell us through the contact form and we will reply. Please don’t test against other customers’ data.

Move before the deadline, not on it.

Transmit is in early access. Tell us about your on-call setup, and we will help you import it and check it against Opsgenie before you switch.