New TrueSend v3.0 — AI-powered send-time optimisation is live. See what's new →

Security You Can Send With Confidence

From infrastructure to inbox, TrueSend’s enterprise-grade protection powers every campaign.

Encrypted
AES-256
TLS 1.3
In Transit
SOC 2
Certified
GDPR
Compliant
0
Data breaches in TrueSend's entire history
256-bit
AES encryption for all data at rest and in transit
99.9%
Infrastructure uptime backed by enterprise SLA
1hr
Security incident response and customer notification time
Defence in Depth

Layered Security. Total Protection.

With a defence-in-depth strategy, TrueSend secures your email marketing infrastructure through multiple, independent security layers.

TRUESEND SECURITY ARCHITECTURE - 5 LAYERS

Network Edge Threat Protection

Enterprise WAF, DDoS mitigation, IP allowlisting, and Anycast routing ensure all inbound traffic is filtered, verified, and secured before infrastructure access.

WAFDDoS Protection Rate LimitingIP FilteringCDN Edge
Active

Secure Data In Transit

TLS 1.3 enforced connections with certificate pinning, HSTS, and Perfect Forward Secrecy ensure encrypted, tamper-proof communication across all endpoints globally.

TLS 1.3Certificate Pinning HSTSPFS
Active

Identity Driven Access Control

OAuth 2.0, RBAC, and mandatory MFA enforce least-privilege access, with secure session management, anomaly detection, and comprehensive audit logging across systems.

OAuth 2.0MFA RBACSAML/SSOAudit Logs
Active

Encryption For Stored Data

AES-256 encryption with per-tenant key isolation, HSM-backed storage, and automated key rotation ensures maximum protection for all stored customer data.

AES-256Per-Tenant Keys HSMKey RotationIsolation
Active

Continuous Threat Monitoring Response

24/7 SOC operations with SIEM integration, real-time anomaly detection, and rapid incident response ensure threats are identified, contained, and resolved quickly.

SIEMML Anomaly Detection 24/7 SOCPen Testing<1hr SLA
Active
Data encryption infrastructure - replace before deploy
AES-256
Encryption
TLS 1.3
In Transit
90 days
Key Rotation
Encryption

Protected At Every Byte

With continuous, end-to-end encryption, TrueSend ensures your data remains secure throughout its entire journey, without exception.

AES 256 Encryption At Rest

All subscriber data, email content, and campaign metadata are encrypted using AES-256, a widely adopted symmetric standard for high-assurance data protection globally.

TLS 1.3 Secure Data Transit

All data in motion is protected using TLS 1.3 with modern ciphersuites and Perfect Forward Secrecy, ensuring session-level encryption isolation.

Hardware Secured Key Management System

Encryption keys are generated and stored within FIPS 140-2 validated HSMs, enforcing strict access controls, tamper resistance, and automated key lifecycle management.

Compliance

Engineered for Regulatory Confidence

TrueSend is designed to align with diverse compliance needs across industries, ensuring trust in every environment.

SOC Compliance
Independently audited security and operational controls
Certified 2024

Annual third-party audits validate security, availability, and processing integrity controls.

Security controls independently audited
Availability monitoring continuously verified
Confidentiality safeguards formally validated
Next audit: Q1 2026 · Report available on request
GDPR Compliance
Full adherence to European data protection laws
Fully Compliant

Supports lawful processing, data rights, and cross-border compliance requirements.

Data processing agreements available
Data subject rights supported
EU data residency options
EU data stored in Frankfurt (AWS eu-central-1)
ISO Certification
Globally recognised information security management standards
Certified 2024

Certified ISMS ensures structured risk management and policy enforcement.

Annual surveillance audits conducted
Risk register continuously maintained
Vendor assessments regularly completed
Certificate expires: November 2027
PCI Compliance
Highest standard for secure payment data handling
Level 1 Certified

Meets stringent requirements for large-scale card transaction processing systems.

Annual QSA security audits
Secure card data handling
High-volume transaction compliance
Powered by Stripe · PCI DSS v4.0
HIPAA Readiness
Designed for healthcare data protection requirements
BAA Available

Enables compliant handling of protected health information across systems.

Business associate agreements supported
Healthcare data safeguards enabled
Secure PHI processing controls
Contact sales to sign a BAA
CCPA Compliance
California consumer privacy rights fully supported
Fully Compliant

Ensures transparency, access, and control over personal consumer data.

Consumer data access tools
Data request handling portal
Privacy rights fully supported
CPRA amendments included
Privacy and data protection - replace before deploy
GDPR Ready
EU data protected
Your Rights
Always respected

Your Privacy is Our Priority

We treat privacy as a fundamental right especially in this digital age. Our goal is to build trust beyond basic compliance standards.

Subscribers can request a complete copy of all personal data held, including email activity, preferences, consent records, and profiling information.
Subscribers can request permanent deletion of their personal data, ensuring all identifiable information, records, and backups are securely removed without delay.
Subscribers can correct inaccurate or incomplete personal data, ensuring all stored information such as names, preferences, and contact details remain accurate
Subscribers can object to data processing for marketing purposes, including profiling, ensuring they can opt out of targeted campaigns anytime.
Incident Response

Swift Action When Things Go Wrong

TrueSend responds instantly to incidents, minimising impact and restoring system integrity quickly.

1

Detect & Triage

Continuous 24/7 SIEM monitoring identifies anomalies in real time and prioritizes incidents based on severity.

<5 minutes
2

Contain & Isolate

Impacted systems are immediately isolated to prevent lateral movement and limit potential damage across infrastructure.

<15 minutes
3

Notify Affected Customers

Impacted customers are informed via email and status page updates within one hour, aligned with global regulatory expectations.

<1 hour (GDPR requires 72h)
4

Remediate & Report

Comprehensive root cause analysis is conducted, with a detailed post-incident report shared transparently within defined timelines.

<5 days post-incident
System Status · Live
Email Sending API
Operational
Campaign Dashboard
Operational
REST API v2
Operational
Deliverability Engine
Operational
Analytics & Reports
Operational
Data Storage Layer
Operational
30-day uptime
99.97%
Last 30 days

Deliver Your Best Work With True Send

  • No Credit Card Needed
  • Unlimited Time On Free Plan