Server-enforced access
Customer workspace access and administrator operations are checked on the server. The admin console is a separate operational surface.
Read security controls
RefreshList documents what the product does, which controls are implemented, and what must be completed before public commercial launch. No certification, accuracy guarantee, or security promise is implied beyond the evidence shown here.
Last reviewed 14 September 2026 · Read the limitations beside every control.It covers workspace isolation, administrator access, encrypted provider credentials, payment boundaries, list lifecycle, verification limits, and operational launch requirements. It is a plain-language evidence register—not a badge wall.
The public marketing site is live. Commercial operations remain gated until identity, payment, scheduling, retention, support, and provider checks are complete.
When evidence is missing, RefreshList labels the gap instead of filling it with a claim.
Customer workspace access and administrator operations are checked on the server. The admin console is a separate operational surface.
Read security controlsVerification and payment provider secrets are stored through the server-side encrypted configuration path and are not rendered into the browser UI.
Review the security boundaryStripe and Cashfree webhook signatures are checked before a payment can settle credits. Duplicate events are idempotent.
See billing rulesValid, invalid, and unknown remain distinct. Unknown is not converted into a confident-looking score, and no independent accuracy benchmark is claimed.
Read the methodologyRefreshList uses uploaded content to inspect records, map duplicates, send eligible addresses to the configured verification provider, and produce categorized reports.
The public review environment does not yet establish automatic all-job enforcement from upload time. Sensitive production lists should wait for retention enforcement, provider terms, and access-control review.
Read privacy informationRefreshList sends the customer to the configured payment gateway. The app records the order, provider reference, credit amount, and reconciliation state needed to deliver the purchased balance.
RefreshList does not claim SOC 2, ISO 27001, an independent penetration test, a security SLA, a comprehensive disposable-domain dataset, or a universal delivery guarantee.
Those statements remain intentionally absent until independently verified and approved for publication.
Read the operating termsOnly upload data your organization is authorized to process.
Understand where eligible addresses go and which provider terms apply.
Protect workspace credentials and revoke exposed API keys promptly.
Download the required reports, then remove stored files when processing is complete.
RefreshList does not claim SOC 2, ISO 27001, independent penetration-test, or blanket certification status. The trust center describes implemented controls and separates them from launch requirements and legal obligations.
Administrator actions are server-enforced and separated from normal customer workspace access. Opening an admin URL does not grant administrator privileges.
No. Checkout is handled by the configured payment gateway. RefreshList stores payment references and credit records needed to reconcile an order, not the customer card number.
The intended retention window is up to 30 days, with early deletion available after processing stops or completes. Automatic production enforcement and provider-side retention must be reviewed separately before commercial launch.
Confirm that you are authorized to process the list, review the provider terms, check the retention controls, use least-privilege access, and delete stored files when processing is complete.
Privacy information · Data handling · Methodology · Support