> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.withpersona.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.withpersona.com/_mcp/server.

# Security

> Learn about Persona's security principles, compliance program, and platform controls.

Security is at the core of our culture and we have operated from a security-first mentality from day one.

Persona's security philosophy follows three principles:

* Building defense-in-depth against external threats
* Protecting against human error
* Guarding against misuse of insider access

For more information about our security measures, see our [Security Statement](https://withpersona.com/security) or [contact us](https://app.withpersona.com/dashboard/contact-us).

## Domains and IP addresses

### API access IP restrictions

If you are calling our external API with static IP addresses and want an additional layer of security beyond API key based authorization, you can restrict the IPs that Persona accepts requests from. To add IP addresses to the allowlist, visit the [API Key Configuration](https://app.withpersona.com/dashboard/api-keys) section within the Persona dashboard.

### Webhook and Workflow requests

The full list of IP addresses that webhook and workflow requests may come from is:

##### Germany

```
35.246.155.45
34.89.193.61
34.89.158.43
35.198.149.197
34.159.83.62
34.159.68.157
```

##### India

```
34.93.21.229
35.244.13.71
34.93.90.104
34.93.222.99
```

##### United States

```
35.232.44.140
34.69.131.123
34.67.4.225
34.66.30.174
34.123.74.158
34.41.116.165
34.145.62.98
34.105.116.226
34.168.249.74
35.199.156.187
34.105.58.25
35.230.80.200
```

### Email sender domains

By default, emails sent to your end users use the following sender domains:

| Region         | Sender domain        |
| -------------- | -------------------- |
| Non-EU         | `frompersona.com`    |
| European Union | `eu.frompersona.com` |

Emails sent to members of your organization's team use the following sender domains:

| Region         | Sender domain        |
| -------------- | -------------------- |
| Non-EU         | `withpersona.com`    |
| European Union | `eu.withpersona.com` |

If you configure a custom sender address, it replaces the applicable default sender address.

### Standard domains for allowlisting

If your organization has network security policies that require allowlisting external domains, you should include the following Persona domains to ensure proper functionality:

```
withpersona.com
app.withpersona.com
cdn.withpersona.com
docs.withpersona.com
inquiry.withpersona.com
miniapp.withpersona.com
sdk.withpersona.com
status.withpersona.com
t.withpersona.com
webrtc-consumer.withpersona.com
webrtc-stun.withpersona.com
```

If you have configured a custom subdomain for your organization, you should also allowlist:

```
<custom-subdomain>.withpersona.com
```

For information on how to set up a custom subdomain, see our [Subdomains documentation](/hosted-flow-subdomains).