Security
How Templater keeps your templates and sends safe.
What we do today, stated plainly. Nothing here is a promise we don’t keep in code.
Where it runs
- Templater runs on Amazon Web Services in the Mumbai region (ap-south-1).
- Every request travels over HTTPS.
Keys and secrets
- API keys are hashed at rest and shown only once, when you create them.
- SMTP passwords and AI provider keys are encrypted with AES-256-GCM before they are stored.
- Account passwords are hashed with Argon2id. Two-factor sign-in is available to everyone, and a workspace can require it.
Templates and renders
- Templates run in a sandboxed Handlebars with a fixed set of helpers, so a template can never run code on our servers.
- Signed PDF links stop working after 24 hours.
- The free tools render in your browser; the free PDF download loads nothing from the network while it prints.
Access in your workspace
- Owner, Admin, Developer, Editor and Viewer roles, plus custom roles.
- Per-folder template access for members who should see only part of the library.
- Test API keys that can only send to your own team.
Webhooks
- Every webhook is signed with HMAC-SHA256 over its timestamp and body, so your backend can check it came from Templater.