Skip to main content
Commune is built with security as a foundational layer, not an afterthought. Every email — inbound and outbound — passes through multiple security systems designed specifically for AI agent use cases.

Security architecture

Defense layers

Email Authentication

DKIM signing, SPF records, and DMARC policies ensure your emails are trusted and not spoofed.

Encryption at Rest

AES-256-GCM encryption for email content, webhook payloads, and secrets stored in the database.

Spam Prevention

SpamAssassin scoring on inbound emails + outbound content validation to prevent your agent from sending spam.

Prompt Injection Detection

AI-specific threat detection that analyzes inbound emails for prompt injection attempts targeting your agent.

Rate Limits

Per-second, daily, and burst-based rate limiting to prevent abuse and protect sender reputation.

Security by default

These protections are active for every Commune account — no configuration required:

Security headers

All API responses include standard security headers:
  • Strict-Transport-Security — HSTS enforcement
  • X-Content-Type-Options: nosniff
  • X-Frame-Options: DENY
  • X-Request-Id — Unique request identifier for debugging

Authentication methods

Commune supports three authentication methods depending on who is making the request:
Standard API key authentication for backend integrations. Every request includes a comm_ prefixed key.
  • Keys are HMAC-SHA256 hashed before storage
  • Scoped to an organization
  • Can be rotated without downtime
  • Full docs

Infrastructure

  • Transport: HTTPS-only (HTTP is rejected)
  • Authentication: Multiple methods (API key, agent signing, OAuth) — see tabs above
  • Database: MongoDB with encryption at rest
  • Secrets: Webhook secrets and encryption keys are never exposed in API responses
  • Key management: Three-layer encryption key protection with fingerprint locking and canary verification

Compliance

  • GDPR: Full data deletion API with preview, confirmation tokens, and audit trail
  • Data residency: Email delivery through AWS regions (configurable per domain)
  • Audit logs: All operations logged to MongoDB with automatic TTL expiry
  • Key rotation: Dual-key rotation mechanism for zero-downtime encryption key changes

Explore security features

Email Authentication

DKIM, SPF, and DMARC — authenticate every email your agent sends.

Encryption

AES-256-GCM encryption for email content, secrets, and attachments.

Spam Prevention

Inbound spam scoring and outbound content validation.

Prompt Injection Detection

AI-specific threat detection on every inbound email.

Rate Limits

Burst detection, warmup gates, and sending health gates.

Data Deletion

GDPR-compliant deletion API with preview and audit trail.
Last modified on March 19, 2026