Security
AllStackd is an operations layer on Amazon SES accounts you own. Delivery stays in your AWS account. Monitor every Amazon SES account, region, and domain from one workspace. Keep delivery in your AWS account, and optionally send transactional mail through a durable API.
AWS connection
You download a per-connection CloudFormation template from AllStackd and create the stack in your account. The stack creates an IAM role that trusts only AllStackd’s runtime role ARN, conditioned on a unique External ID generated for that connection. Sessions last at most one hour. AllStackd never asks for long-lived access keys or SES SMTP passwords.
The template also creates an SNS topic and SES configuration set so delivery events can reach AllStackd. Event callbacks verify the SNS signature and the expected topic ARN for that connection.
Observe permissions
Observe mode is read-only against SES configuration and reputation APIs. The role policy uses Resource: "*" for these SES actions (SES APIs are account-scoped). Review the generated template before you create the stack.
- ses:GetAccount
- ses:GetEmailIdentity
- ses:GetConfigurationSet
- ses:GetConfigurationSetEventDestinations
- ses:GetReputationEntity
- ses:GetTenant
- ses:ListConfigurationSets
- ses:ListEmailIdentities
- ses:ListRecommendations
- ses:ListReputationEntities
- ses:ListResourceTenants
- ses:ListSuppressedDestinations
- ses:ListTenantResources
- ses:ListTenants
Control permissions
Control mode adds send and configuration actions on top of Observe. Today that includes unrestricted ses:SendEmail plus identity and configuration-set management. Narrowing send by configuration set or From address is on the hardening roadmap; until then, treat Control as full SES operational access for that account and region, and start with Observe when you only need health.
- ses:CreateConfigurationSet
- ses:CreateConfigurationSetEventDestination
- ses:CreateEmailIdentity
- ses:CreateTenant
- ses:CreateTenantResourceAssociation
- ses:DeleteEmailIdentity
- ses:PutConfigurationSetReputationOptions
- ses:PutConfigurationSetSendingOptions
- ses:PutConfigurationSetSuppressionOptions
- ses:PutEmailIdentityConfigurationSetAttributes
- ses:PutEmailIdentityDkimAttributes
- ses:PutEmailIdentityFeedbackAttributes
- ses:PutEmailIdentityMailFromAttributes
- ses:PutSuppressedDestination
- ses:PutTenantSuppressionAttributes
- ses:SendEmail
Message content
In Control mode, message payloads are encrypted at rest with AES-256-GCM while queued, submitted through your SES account, then deleted within 24 hours. Status APIs return delivery state, not bodies. API keys are hashed at rest and shown in full only once.
Customer webhooks
Outbound event webhooks are signed with HMAC-SHA256. Destinations are validated against private and link-local addresses, credentials in URLs, and unsafe redirects, with short timeouts.
Account deletion
Deleting your account cancels Stripe billing first. Workspace data and the Clerk sign-in are removed only after billing cancellation succeeds. If Stripe is unavailable, deletion stops and the account remains so billing cannot orphan after data is gone.
Subprocessors
Clerk (auth), Neon (database), Vercel (hosting), Stripe (billing), and AWS in accounts you authorize. Full list: Terms → Subprocessors.
Questions: support@allstackd.com. Setup walkthrough: Docs → Prepare Amazon SES.