Built for the security review you'll face on day one
The compliance spine is funded before the pixel, not bolted on after. Here's what that means, concretely.
SOC 2 Type II
Independently audited controls: the first thing procurement asks for, ready before you need it.
GDPR · DPA + SCCs
A customer-facing DPA and standard contractual clauses for every serious buyer and international transfer.
Person-level, gated
US-only, behind a DPIA, CMP consent and an in-script geofence. EU/UK subjects excluded from the database.
Erasure & suppression
One-operation DSAR erasure across signals, receipts, leads and sessions, plus a global suppression list so no one resurfaces.
Encrypted & isolated
Row-level security per workspace, AES-256 credentials at rest, HMAC-verified inbound webhooks.
Read-only mail scopes
Gmail / Outlook are requested read-only. We cannot send even if we wanted to, provably.
We never touch SMTP. We can't send, so we can't lose your domain.
Structurally immune to spam liability. The destination sends; you keep deliverability and control.
Sub-processor list published · data retention auto-expires · EU representative on file · this is not legal advice