All systems operational · 99.97% uptime · 90 days

Built for sales teams
handling regulated data.

Encryption, access controls, and audit trails that satisfy procurement reviews from banks, healthcare networks, and government suppliers.

SOC 2 Type II
Audited annually
ISO 27001
Certificate #2026-PR-0419
GDPR
Data Processing Addendum
CCPA
California-aligned
HIPAA
BAA available on Enterprise
Three pillars

Defence in depth,
by default.

01 ·

Encryption

TLS 1.3 in transit. AES-256 at rest. Tenant data encrypted with per-team keys derived from a hardware-backed root in AWS KMS.

  • TLS 1.3 + HSTS preload
  • AES-256-GCM at rest
  • Per-team data keys
  • Quarterly key rotation
  • Forward-secret session cookies
02 ·

Access control

Zero standing access to production. Engineers request just-in-time roles that auto-expire and log every command.

  • SSO + SAML on Enterprise
  • Granular team roles & permissions
  • Mandatory hardware 2FA for staff
  • JIT prod access via approval bot
  • Audit log retained 12 months
03 ·

Monitoring

Every API call, AI request, and recipient view is logged, hashed, and shipped to a tamper-evident store. Anomalies page humans within 60 seconds.

  • 24/7 anomaly detection
  • PII redaction at the log boundary
  • Daily restore drills
  • Quarterly third-party pentests
  • Public status page
Practices

The full list.

If your security team needs more detail, email security@presender.app for the full questionnaire response (CAIQ, SIG-Lite).

Data
  • Tenant isolation enforced at the ORM, query, and storage layer.
  • Recipient analytics deletable in one click; cascades within 60 seconds.
  • No customer data ever leaves the EU on the EU residency plan.
Application
  • Dependency scanning on every PR; criticals block merge.
  • CSP, SRI, and signed cookies enforced site-wide.
  • Recipient verification (email gate / password gate) opt-in per presentation.
Infrastructure
  • Hosted on Laravel Cloud + AWS (eu-north-1).
  • Daily encrypted backups; 30-day point-in-time recovery.
  • 99.97% uptime trailing 12 months — see status.presender.app.
People
  • Background checks on every hire with production access.
  • Annual security training and live phishing drills.
  • Acceptable-Use Policy signed by all contractors.
Subprocessors

Six. No more.

We notify Enterprise customers 30 days before adding any new subprocessor.

Vendor Purpose Region
Laravel Cloud Application hosting EU (Stockholm)
AWS S3 Object storage EU (Stockholm)
Anthropic AI text generation US, no training opt-in
OpenAI Voice transcription US, zero data retention
Stripe Payments EU + US
Postmark Transactional email EU
Responsible disclosure

Found something?

We pay bug bounties up to €5,000 for valid reports. Please give us 90 days before public disclosure. PGP key on the dedicated page.