- The Art of Deception, by Kevin Mitnick, is required reading for all new employees who deal directly with customer data. Fatal System Error, by Joseph Menn, is extra credit.
- All employees sign a Privacy Safeguard Agreement outlining their responsibility in protecting customer data
- All new employees are given security guidelines for using social media, including information about social engineering.
- We have an employee termination ("aka change management") process in place
-
In order to protect our company from a variety of different losses, MailChimp has established a comprehensive insurance program. This program has been designed to cover us for standard business losses that all businesses can face as well as those losses that are unique to what we do in the technology industry. Additionally, we have selected a carrier that is financially strong and purchased substantial limits for the following general coverages.
- Property and Business Interruption
- Commercial General Liability
- Workers Compensation and Employers Liability
- Business Automobile
- Umbrella Liability
- International Property and Liability
- Technology Errors & Omissions Liability
- Management Liability
Protecting Ourselves Against You
Yes, you heard that correctly. We can secure ourselves like Fort Knox, but if your computer gets compromised and someone gets into your MailChimp account, that's not good for either of us.
- We monitor and will automatically suspend accounts for signs of irregular or suspicious login activity.
- Certain changes to your account, such as your password, trigger email notifications to the account holder.
- Omnivore monitors account and campaign activity for signs of abuse
- In addition to our scalable algorithms, we employ another layer of human reviewers, who monitor for anomalous account and email activity
Investing in Your Privacy
- Our General Counsel / Chief Privacy Officer works with our developers to make sure our features comply with applicable international spam and privacy laws.
- We retain a law firm in the UK to consult on EU privacy issues.
- Our privacy policy is monitored by TRUSTe and is EU SafeHarbor compliant.
- We are members of the ESPC, OTA, and MAAWG
* A Note to Hackers (and lawyers)
Hi there. Yes, we know that none of the stuff we listed above means we're totally hacker safe or impenetrable. But our customers constantly ask for this stuff, so we're listing (some of) what we do for security. If you find a vulnerability, please get in touch.