Trust
What protects your list, and what we do not have.
You are about to hand us other people’s email addresses. This page says what we hold, what we do not hold, where the data lives, and what stands between it and someone who should not have it. Everything on it is something we can show you today.
Certifications
Start with what we do not have.
A buyer who finds this out later stops believing the rest of the page, so it goes first. SendBeam is a small, self-funded UK company. We hold no security certifications, and we do not present our suppliers’ certificates as ours — our hosting, database and payment providers hold their own, and those are theirs, not SendBeam’s.
| Standard | Do we hold it? | The honest answer |
|---|---|---|
| SOC 2 (Type I or Type II) | No | We hold no SOC 2 report and are not in an audit window for one. |
| ISO/IEC 27001 | No | We are not certified, and we are not working towards it today. |
| Cyber Essentials or Cyber Essentials Plus | No | Neither is held. |
| PCI DSS | Not ours to hold | Card details never reach SendBeam. Payments are taken by Stripe, which handles the card data. |
| A data protection officer | Not appointed | One is not required of a company of our size and processing, and appointing one voluntarily brings statutory duties we would then have to meet properly. |
What we have instead
- 01 A data processing agreement that applies to every account automatically, published in full, with nothing to negotiate.
- 02 A sub-processor list naming every provider, what it does for us and where it processes — published openly, with 30 days’ notice before we add or replace one.
- 03 A vulnerability disclosure policy with response times we commit to in writing, and a safe harbour for good-faith research.
- 04 A penetration test of the application in September 2026, and backups we have restored and checked.
If your procurement process requires a certification we do not hold, tell us which one and why, and we will give you a straight answer about whether and when we could get it — rather than a badge borrowed from a supplier.
Where the data lives
Who holds your data, and where.
- The website and the application Cloudflare.
- The database and sign-in — where account data and the contacts you upload are stored Supabase, in the United Kingdom.
- Email delivery Resend, in the United States, is the route customer email takes today. A United Kingdom route through Microsoft Azure Communication Services is in trial on selected workspaces.
- Payments Stripe. Card details go to Stripe and are never held by us.
- Analytics Google Analytics, on these public marketing pages only — never inside the application, and only if you allow analytics cookies.
The full list — every provider, what each one does for us and where it processes — is published in the privacy notice, openly and with nothing to ask for. Our DPA commits us to at least 30 days’ notice before we add or replace one, and gives you the right to object.
Protection
What stands between your list and someone else.
Deliberately, this section says what protection exists and not how it is built. Publishing the shape of a defence helps the people it is there to stop.
- Encrypted in transit Everything between you and SendBeam travels over HTTPS, and browsers are told to refuse anything else.
- Credentials are not readable, even by us API keys are stored as a one-way hash — we cannot show you an existing key, and nor could anyone who reached the database. Credentials you hand us for an import, or the secret behind a form’s spam protection, are encrypted before they are stored.
- Opt-outs are kept without keeping the person A suppressed address is stored only as a one-way hash. The opt-out keeps working after the contact record is gone, and the address itself is not retained to do it.
- One workspace cannot see another Every workspace’s contacts, lists, campaigns and keys are separated from every other’s, and that separation is enforced in the database as well as in the application.
- Staff access is limited, and recorded The platform tools are reachable only by SendBeam staff, signing in there requires a second factor as well as a password, and what staff do there is written to a log that cannot be edited or deleted afterwards.
- Backups are encrypted Database backups are encrypted before they leave the system they came from, and are kept apart from it.
Penetration test · September 2026
In September 2026 we ran a penetration test of the application. It covered whether one workspace could reach another’s data across the product and its API, how sign-in and sessions behave under attack, cross-site request forgery, and the security headers the site sends. Everything it found was fixed. We are telling you it happened and what it covered; we do not publish the findings themselves, and we did not publish them at the time either. This was our own testing, not an independent firm’s — when that changes, this page will say so.
Backups
A backup you have never restored is a hope, not a backup.
The database is backed up automatically, encrypted, and stored apart from the system it came from. Every backup is restored into a clean database and checked against the data it was taken from as it is made; a copy that does not restore is not kept.
On 6 September 2026 we did it by hand, end to end: a backup was fetched, decrypted, restored into an empty database, and every table checked row by row against the original. It all matched. We also proved the backup could be decrypted with the key held outside our systems entirely, so a total loss of our own infrastructure is still recoverable. We hold a written recovery plan, and the drill is scheduled to repeat.
Almost nobody in this market claims this, because almost nobody has done it. Anyone can write “we take backups”.
Sending, consent and abuse
The other half of trust on an email platform.
A platform that lets anyone mail anyone is a security problem for everybody on it, including you. These are not optional extras here.
- Authenticated sending Mail leaves on a domain you verify, signed so receiving providers can check it really came from you, with a return path aligned to the same domain. You never hand us a provider key.
- One-click unsubscribe Every marketing message carries the one-click unsubscribe headers mailbox providers act on, as well as a visible link. A one-click unsubscribe is processed straight away, not queued.
- Suppression that cannot be undone An address that unsubscribes, hard bounces or reports spam is suppressed for that workspace and stays suppressed. There is no way to clear it — not in the app, not through the API, and not by re-importing the address.
- Automatic pause Sending health is measured per workspace. If complaints or bounces cross the line, that workspace’s sending pauses on its own and its admins are told, before it damages anyone else. The rules are in the Acceptable Use Policy.
- Imports are checked Addresses on domains that cannot receive mail at all are dropped at import rather than mailed, and suppression is applied to an import before anything is sent.
- Consent is yours to hold You decide who is on your list and what you send them, so under the UK marketing rules you are the sender and we are the platform. We do not supply lists, choose your recipients or send on our own initiative.
Your rights and the paperwork
Everything you would ask for, already published.
- Data Processing Addendum Our Article 28 processor terms. They form part of the Terms of Service and apply to every account from the moment you sign up — there is nothing to request and nothing to sign.
- Privacy notice What we hold about you as a customer, why, how long for, and the sub-processor list.
- Acceptable Use Policy What may be sent through SendBeam, the consent you must be able to evidence, and how we enforce it.
- Terms of Service The contract itself.
- Vulnerability disclosure policy How to report a security problem, what is in scope, what we promise back, and the safe harbour.
- How do I get a data processing agreement?
- You already have one. The DPA forms part of the Terms of Service and is in force for every account, so there is nothing to request and no signature to chase. If your own process needs a countersigned copy, ask us and we will sort it out.
- Can I get my data out?
- Yes, yourself, whenever you like. Contacts export to CSV from the app and from the API, with the fields and engagement columns you choose. Nothing is held hostage and there is no charge for leaving.
- Can I delete it?
- Yes. Deleting a workspace removes its data, and you can do that yourself from the app. Copies inside backups age out on the schedule set out in the privacy notice. Suppression records survive deliberately, as a one-way hash of the address only, so that people who opted out stay opted out.
- Who is the controller of my contacts’ data?
- You are. We process it on your instructions as your processor, which is what the DPA sets out. For the data we hold about you as a customer, we are the controller, and the privacy notice covers that.
- What happens if there is a breach?
- We tell you without undue delay after we become aware of one affecting your contact data, with what we know at the time, as the DPA commits us to. Where the law requires it we also report to the Information Commissioner’s Office. We hold a written incident response plan for this.
Reporting a problem
Found something wrong? Tell us.
Email [email protected]. Our vulnerability disclosure policy sets out what to include, what is in scope, the times we commit to replying and fixing within, and the safe harbour that protects you for testing in good faith. You do not need an account, you may report anonymously, and we will not ask you to sign anything.
If a SendBeam customer is sending something abusive, that is a different inbox: [email protected]. For anything else about this page, including a security questionnaire you need answered, send us a message.
Keeping this honest
Last reviewed 8 September 2026.
We review this page at least twice a year, and we update it whenever something on it changes — a new provider, a certification gained, a test run, a promise we can no longer keep. If we ever hold something we do not hold today, it will appear here; if we lose something, that will appear here too. Nothing on this page is aspirational: if it is written in the present tense, it is true now.