Security
Least privilege to your SES templates.
You create the role. We never get permission to send mail.
What the Huskar role can do
IAM role created by your CloudFormation stack
- Create, update and read your SES email templates
- Read SES account status
- Can’t send email
- Can’t read recipient data
- Can’t access any other AWS service
Temporary credentials, 15 minute expiryRevoke by deleting the stack
How Huskar connects to SES, and how it’s secured.
- Connection to AWS
- Huskar connects to each of your AWS accounts through an IAM role that you create with a CloudFormation template we provide. The role trusts only Huskar, and only with an ExternalId unique to your connection. Each publish uses temporary credentials that expire in 15 minutes and are never stored. No long-lived credentials from your side are held by us.
- Permissions
- The role can manage SES email templates and read SES account status. It can’t send email, read recipient data, or access any other AWS service. Your info-sec team can review the template before deploying it.
- Audit
- Every AWS call we make is logged in your CloudTrail, tagged with the Huskar user who made it. Huskar also records every publish (who, when, what changed), and it warns before overwriting a template that was edited directly in SES.
- Revocation
- Delete the CloudFormation stack and our access ends immediately.
- Your data in Huskar
- All traffic is encrypted in transit with TLS. Access to templates is scoped to your workspace, so users only see their own workspace’s templates.
Where things live
- Template content lives in your Huskar workspace. Connection details and publish records for AWS live in Huskar’s API account, not mixed into the app database as AWS credentials.
- The IAM role is the default and recommended method. Access keys are offered only if needed.
- Marketers without AWS access can use Send to your AWS admin, with copy-paste instructions from the connect wizard.
Subprocessors
- Customer auth and workspace data use hosted Supabase.
- Payments, when you’re on a paid plan, are processed by Razorpay. We never see your full card details.