The purpose of this page is to provide customers of Core Email Protection API with the information necessary to assess how the product can support and enhance their data privacy strategy.
Core Email Protection API (CEP API) – Product Statement
Core Email Protection API (CEP API) is a cloud-based email protection solution that employs a fully integrated layer of behavioral AI to help detect and prevent inbound and internal email threats such as business email compromise and lateral phishing while providing end-users with in-moment warning banners to help them decide whether an email is safe.
Email Data Processed by CEP API
CEP API filters and processes inbound and internal emails, collecting and analyzing data in those emails to detect threats. This includes email sender and recipient names, subject line, header data, email addresses, IP addresses, content, attachments, URLs, sender reputation, message characteristics, and threat intelligence.
CEP API Data Processing Locations
CEP API assigns your tenant to a regional data center (currently in the EU or US) based on your organization’s location or to the data center you choose to utilize. To detect, identify, and remediate threats, certain email data and threat indicators may be processed by Proofpoint's global detection infrastructure, which may include processing and storage in the US. Where cross-border transfers occur, Proofpoint implements appropriate data transfer safeguards, such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses, where required by applicable law.
How Proofpoint Retains Records
To protect organizations from email threats, Proofpoint analyzes the data collected through CEP API and applies the results to its scanning and filtering process. All data collected is retained in an aggregated form until securely deleted.
Proofpoint’s Use of Subprocessors
Proofpoint utilizes subprocessors to provide its services. A comprehensive list of the subprocessors may be found on the Trust site.
Security
Proofpoint maintains a documented information security program that is aligned with the requirements of NIST 800-53 and ISO 27001. Security controls include:
Data in transit is protected using HTTPS/TLS, and data at rest is encrypted using AES 256. Access control mechanisms restrict physical and logical access to the facilities and infrastructure hosting the service. Proofpoint has policies and procedures for identifying and remediating vulnerabilities and runs a distributed security monitoring infrastructure with a 24/7 network operations center that responds to security alerts. The information security program undergoes an annual SOC 2 Type II audit covering the Availability, Confidentiality, and Security trust principles.
Data collected through CEP API product functionality is retained in aggregated form, encrypted at rest, until securely deleted. Processing and filtering results are only accessible to the customer's authorized personnel.
© 2026 Proofpoint. All rights reserved. The content on this site is intended for informational purposes only.
Last updated July 24, 2026.