SendBeam

Trust

What protects your list, and what we do not have.

You are about to hand us other people’s email addresses. This page says what we hold, what we do not hold, where the data lives, and what stands between it and someone who should not have it. Everything on it is something we can show you today.

Certifications

Start with what we do not have.

A buyer who finds this out later stops believing the rest of the page, so it goes first. SendBeam is a small, self-funded UK company. We hold no security certifications, and we do not present our suppliers’ certificates as ours — our hosting, database and payment providers hold their own, and those are theirs, not SendBeam’s.

StandardDo we hold it?The honest answer
SOC 2 (Type I or Type II)NoWe hold no SOC 2 report and are not in an audit window for one.
ISO/IEC 27001NoWe are not certified, and we are not working towards it today.
Cyber Essentials or Cyber Essentials PlusNoNeither is held.
PCI DSSNot ours to holdCard details never reach SendBeam. Payments are taken by Stripe, which handles the card data.
A data protection officerNot appointedOne is not required of a company of our size and processing, and appointing one voluntarily brings statutory duties we would then have to meet properly.

What we have instead

If your procurement process requires a certification we do not hold, tell us which one and why, and we will give you a straight answer about whether and when we could get it — rather than a badge borrowed from a supplier.

Where the data lives

Who holds your data, and where.

The full list — every provider, what each one does for us and where it processes — is published in the privacy notice, openly and with nothing to ask for. Our DPA commits us to at least 30 days’ notice before we add or replace one, and gives you the right to object.

Protection

What stands between your list and someone else.

Deliberately, this section says what protection exists and not how it is built. Publishing the shape of a defence helps the people it is there to stop.

Penetration test · September 2026

In September 2026 we ran a penetration test of the application. It covered whether one workspace could reach another’s data across the product and its API, how sign-in and sessions behave under attack, cross-site request forgery, and the security headers the site sends. Everything it found was fixed. We are telling you it happened and what it covered; we do not publish the findings themselves, and we did not publish them at the time either. This was our own testing, not an independent firm’s — when that changes, this page will say so.

Backups

A backup you have never restored is a hope, not a backup.

The database is backed up automatically, encrypted, and stored apart from the system it came from. Every backup is restored into a clean database and checked against the data it was taken from as it is made; a copy that does not restore is not kept.

On 6 September 2026 we did it by hand, end to end: a backup was fetched, decrypted, restored into an empty database, and every table checked row by row against the original. It all matched. We also proved the backup could be decrypted with the key held outside our systems entirely, so a total loss of our own infrastructure is still recoverable. We hold a written recovery plan, and the drill is scheduled to repeat.

Almost nobody in this market claims this, because almost nobody has done it. Anyone can write “we take backups”.

Sending, consent and abuse

The other half of trust on an email platform.

A platform that lets anyone mail anyone is a security problem for everybody on it, including you. These are not optional extras here.

Your rights and the paperwork

Everything you would ask for, already published.

How do I get a data processing agreement?
You already have one. The DPA forms part of the Terms of Service and is in force for every account, so there is nothing to request and no signature to chase. If your own process needs a countersigned copy, ask us and we will sort it out.
Can I get my data out?
Yes, yourself, whenever you like. Contacts export to CSV from the app and from the API, with the fields and engagement columns you choose. Nothing is held hostage and there is no charge for leaving.
Can I delete it?
Yes. Deleting a workspace removes its data, and you can do that yourself from the app. Copies inside backups age out on the schedule set out in the privacy notice. Suppression records survive deliberately, as a one-way hash of the address only, so that people who opted out stay opted out.
Who is the controller of my contacts’ data?
You are. We process it on your instructions as your processor, which is what the DPA sets out. For the data we hold about you as a customer, we are the controller, and the privacy notice covers that.
What happens if there is a breach?
We tell you without undue delay after we become aware of one affecting your contact data, with what we know at the time, as the DPA commits us to. Where the law requires it we also report to the Information Commissioner’s Office. We hold a written incident response plan for this.

Reporting a problem

Found something wrong? Tell us.

Email [email protected]. Our vulnerability disclosure policy sets out what to include, what is in scope, the times we commit to replying and fixing within, and the safe harbour that protects you for testing in good faith. You do not need an account, you may report anonymously, and we will not ask you to sign anything.

If a SendBeam customer is sending something abusive, that is a different inbox: [email protected]. For anything else about this page, including a security questionnaire you need answered, send us a message.

Keeping this honest

Last reviewed 8 September 2026.

We review this page at least twice a year, and we update it whenever something on it changes — a new provider, a certification gained, a test run, a promise we can no longer keep. If we ever hold something we do not hold today, it will appear here; if we lose something, that will appear here too. Nothing on this page is aspirational: if it is written in the present tense, it is true now.