RefreshListTrust center
EVIDENCE REGISTER / TRUST CENTER

Trust should be inspectable.

RefreshList documents what the product does, which controls are implemented, and what must be completed before public commercial launch. No certification, accuracy guarantee, or security promise is implied beyond the evidence shown here.

Last reviewed 14 September 2026 · Read the limitations beside every control.
THE SHORT ANSWER

What does the RefreshList trust center cover?

It covers workspace isolation, administrator access, encrypted provider credentials, payment boundaries, list lifecycle, verification limits, and operational launch requirements. It is a plain-language evidence register—not a badge wall.

CURRENT RELEASEPrivate review → public website

The public marketing site is live. Commercial operations remain gated until identity, payment, scheduling, retention, support, and provider checks are complete.

SECURITY RULENever compromise platform security.

When evidence is missing, RefreshList labels the gap instead of filling it with a claim.

01 / CONTROL REGISTER

Implemented controls, stated precisely.

Server-enforced access

Customer workspace access and administrator operations are checked on the server. The admin console is a separate operational surface.

Read security controls

Encrypted provider credentials

Verification and payment provider secrets are stored through the server-side encrypted configuration path and are not rendered into the browser UI.

Review the security boundary

Signed payment events

Stripe and Cashfree webhook signatures are checked before a payment can settle credits. Duplicate events are idempotent.

See billing rules

Evidence-first results

Valid, invalid, and unknown remain distinct. Unknown is not converted into a confident-looking score, and no independent accuracy benchmark is claimed.

Read the methodology
02 / DATA LIFECYCLE

Your list has boundaries.

RefreshList uses uploaded content to inspect records, map duplicates, send eligible addresses to the configured verification provider, and produce categorized reports.

  • Original non-email columns stay in RefreshList storage for row-preserving exports.
  • Eligible email addresses may be sent to the configured provider.
  • Delete stored files is available after processing stops or completes.
  • Provider-side retention is separate from RefreshList deletion.
Read the full data lifecycle
RETENTION NOTEUp to 30 days intended

The public review environment does not yet establish automatic all-job enforcement from upload time. Sensitive production lists should wait for retention enforcement, provider terms, and access-control review.

Read privacy information
03 / PAYMENT BOUNDARY

Checkout is separated from card data.

RefreshList sends the customer to the configured payment gateway. The app records the order, provider reference, credit amount, and reconciliation state needed to deliver the purchased balance.

No card number stored by RefreshListSigned webhooks before settlementTest and live balances kept separate
WHAT WE DO NOT CLAIM

Trust is not a shortcut around evidence.

RefreshList does not claim SOC 2, ISO 27001, an independent penetration test, a security SLA, a comprehensive disposable-domain dataset, or a universal delivery guarantee.

Those statements remain intentionally absent until independently verified and approved for publication.

Read the operating terms
04 / BEFORE YOU UPLOAD

A responsible customer checklist.

01Confirm authorization

Only upload data your organization is authorized to process.

02Review the provider

Understand where eligible addresses go and which provider terms apply.

03Limit access

Protect workspace credentials and revoke exposed API keys promptly.

04Delete after use

Download the required reports, then remove stored files when processing is complete.

COMMON QUESTIONS

Trust questions, answered.

Is RefreshList SOC 2, ISO 27001, or GDPR certified?+

RefreshList does not claim SOC 2, ISO 27001, independent penetration-test, or blanket certification status. The trust center describes implemented controls and separates them from launch requirements and legal obligations.

How are administrator permissions protected?+

Administrator actions are server-enforced and separated from normal customer workspace access. Opening an admin URL does not grant administrator privileges.

Are payment card numbers stored by RefreshList?+

No. Checkout is handled by the configured payment gateway. RefreshList stores payment references and credit records needed to reconcile an order, not the customer card number.

How long are uploaded lists retained?+

The intended retention window is up to 30 days, with early deletion available after processing stops or completes. Automatic production enforcement and provider-side retention must be reviewed separately before commercial launch.

What should I verify before uploading sensitive data?+

Confirm that you are authorized to process the list, review the provider terms, check the retention controls, use least-privilege access, and delete stored files when processing is complete.

READ THE EVIDENCE

NO BADGES. JUST BOUNDARIES.

OPEN SECURITY PAGE

Privacy information · Data handling · Methodology · Support