Security architecture
Defense layers
Email Authentication
DKIM signing, SPF records, and DMARC policies ensure your emails are trusted and not spoofed.
Encryption at Rest
AES-256-GCM encryption for email content, webhook payloads, and secrets stored in the database.
Spam Prevention
SpamAssassin scoring on inbound emails + outbound content validation to prevent your agent from sending spam.
Prompt Injection Detection
AI-specific threat detection that analyzes inbound emails for prompt injection attempts targeting your agent.
Rate Limits
Per-second, daily, and burst-based rate limiting to prevent abuse and protect sender reputation.
Security by default
These protections are active for every Commune account — no configuration required:Security headers
All API responses include standard security headers:Strict-Transport-Security— HSTS enforcementX-Content-Type-Options: nosniffX-Frame-Options: DENYX-Request-Id— Unique request identifier for debugging
Authentication methods
Commune supports three authentication methods depending on who is making the request:- API Key
- Agent Signing
- Commune OAuth
Standard API key authentication for backend integrations. Every request includes a
comm_ prefixed key.- Keys are HMAC-SHA256 hashed before storage
- Scoped to an organization
- Can be rotated without downtime
- Full docs
Infrastructure
- Transport: HTTPS-only (HTTP is rejected)
- Authentication: Multiple methods (API key, agent signing, OAuth) — see tabs above
- Database: MongoDB with encryption at rest
- Secrets: Webhook secrets and encryption keys are never exposed in API responses
- Key management: Three-layer encryption key protection with fingerprint locking and canary verification
Compliance
- GDPR: Full data deletion API with preview, confirmation tokens, and audit trail
- Data residency: Email delivery through AWS regions (configurable per domain)
- Audit logs: All operations logged to MongoDB with automatic TTL expiry
- Key rotation: Dual-key rotation mechanism for zero-downtime encryption key changes
Explore security features
Email Authentication
DKIM, SPF, and DMARC — authenticate every email your agent sends.
Encryption
AES-256-GCM encryption for email content, secrets, and attachments.
Spam Prevention
Inbound spam scoring and outbound content validation.
Prompt Injection Detection
AI-specific threat detection on every inbound email.
Rate Limits
Burst detection, warmup gates, and sending health gates.
Data Deletion
GDPR-compliant deletion API with preview and audit trail.

