Security & privacy

Security starts with a clear boundary.

The public demo lets you evaluate the experience with fictional mail. Real identity documents and mail handling stay closed until the operational, storage, access, and authorization controls behind them are verified.

Until your signed-in account shows that sensitive setup and service are available, do not upload identity documents or send mail to EverAddress.

Physical mailroomIdentity verificationRole-based accessPrivate storageAction recordsYour authorization

Current boundary

What you can verify today.

This ledger separates the public experience you can inspect now from the controls required before sensitive service can activate—and the badges or approvals EverAddress does not claim.

Current trust boundary

A sensitive step stays unavailable until every control behind it is ready.

  • Available now

    Public demo

    Explore the product model without entrusting us with your identity, payment information, or mail.

    • Fictional sample mail

      The demo uses invented names, addresses, images, amounts, and documents—not customer information.

    • No personal data required

      No account, payment card, identity upload, or real mailing address is needed to explore it.

    • HTTPS delivery

      The public website is delivered over HTTPS. That protects the browser connection, not a future private document workflow.

    • Visible simulated states

      Requests move through labeled demo states so you can understand the workflow without implying that staff work is instant.

  • Fail-closed release gates

    Required before sensitive activation

    Real mail and identity workflows remain unavailable unless the full path behind them is ready and verified.

    • Confirmed operating and postal path

      The receiving process, responsible operator, identity evidence, and postal authorization must be reviewed before an address activates.

    • Private storage and access checks

      Uploads, envelope images, and scans require private storage, file validation, and server-side authorization.

    • Restricted staff access

      Sensitive staff routes require role-limited access, stronger authentication, and tested session boundaries.

    • Recorded customer instructions

      Mail actions require an authenticated request, a durable status record, and an extra confirmation before destruction.

  • No borrowed trust

    Not claimed

    We will not turn a design goal, registration requirement, or familiar badge into proof it does not provide.

    • No security certification claim

      EverAddress does not claim SOC 2, HIPAA, or PCI certification or compliance.

    • No inflated security grades

      We do not describe controls as bank-grade, military-grade, or unbreakable.

    • No postal endorsement

      EverAddress does not claim USPS approval, certification, endorsement, or government sponsorship.

    • No universal address acceptance

      Banks, agencies, carriers, and jurisdictions make their own address-acceptance decisions.

Required means fail-closed: if a dependency or control is unavailable, the sensitive step remains unavailable rather than falling back to a less protected path.

Customer authorization

Sensitive mail actions begin with your instruction.

  • Request before opening

    For live service, an eligible mail item must remain sealed unless an authenticated account holder asks for a contents scan.

  • See the real request state

    A production mailbox must distinguish requested, queued, in progress, complete, and failed work instead of implying instant staff action.

  • Confirm irreversible actions

    Discard and shred requests must explain that the result is irreversible and show any policy-defined cancellation window before completion.

  • Use a verified privacy channel

    Export, correction, and deletion options appear only when the request process and retention rules behind them are operational.

Account access

If secure access is unavailable, access stays closed.

  • Short-lived email codes

    Customer sign-in uses an email-code design. If verified email delivery is unavailable, sign-in stays closed instead of bypassing verification.

  • Server-side authorization

    Every private customer and staff route must validate the session and permission before returning sensitive data or accepting an action.

  • Stronger staff controls

    Sensitive staff access requires shorter sessions and additional authentication before identity documents or mail operations are exposed.

  • Recovery without shortcuts

    A support or recovery path cannot silently weaken the same authorization boundary it is meant to restore.

Claims discipline

No borrowed badges. No implied endorsements.

Trust claims should be specific enough to verify and narrow enough to stay true.

  • HTTPS is not a storage claim

    The public website is delivered over HTTPS. That fact alone says nothing about private identity-document or mail-scan storage.

  • Physical package storage, stated narrowly

    Eligible packages can be held in a locked office area at the Dawsonville location. Pickup is available Sunday–Friday, 9:00 a.m.–6:00 p.m.; closed Saturday. Account activation, item eligibility, release instructions, and any fees are confirmed separately.

  • Certifications are named only as exclusions

    SOC 2, HIPAA, and PCI appear here only to make clear that EverAddress does not currently claim them.

  • Registered status, stated precisely

    Registered with the Post Office responsible for delivery as a Commercial Mail Receiving Agency. That postal operating requirement is not USPS endorsement and does not guarantee acceptance of an address.

  • Demo intelligence is not customer-document processing

    The public assistant works with fictional fixtures and is not presented as production analysis of customer mail.

If a claim changes, this page should change only after the supporting control, document, and operating path have been verified.

Report a concern

Tell us without sending sensitive material.

Use the contact page to report a possible security or privacy issue. Describe the concern, but do not attach or paste passwords, identity documents, mail scans, payment details, or other sensitive files. A submission receipt does not promise a response time.

Contact security

Go anywhere

Evaluate the workflow without handing over anything personal.

The fictional demo lets you see how EverAddress is designed to ask, confirm, and show status before a sensitive action moves forward.