Skip to content
TRUST & COMPLIANCE

Built for the security review you'll face on day one

The compliance spine is funded before the pixel, not bolted on after. Here's what that means, concretely.

  • SOC 2 Type II

    Independently audited controls: the first thing procurement asks for, ready before you need it.

  • GDPR · DPA + SCCs

    A customer-facing DPA and standard contractual clauses for every serious buyer and international transfer.

  • Person-level, gated

    US-only, behind a DPIA, CMP consent and an in-script geofence. EU/UK subjects excluded from the database.

  • Erasure & suppression

    One-operation DSAR erasure across signals, receipts, leads and sessions, plus a global suppression list so no one resurfaces.

  • Encrypted & isolated

    Row-level security per workspace, AES-256 credentials at rest, HMAC-verified inbound webhooks.

  • Read-only mail scopes

    Gmail / Outlook are requested read-only. We cannot send even if we wanted to, provably.

We never touch SMTP. We can't send, so we can't lose your domain.

Structurally immune to spam liability. The destination sends; you keep deliverability and control.

Sub-processor list published · data retention auto-expires · EU representative on file · this is not legal advice