Die englische Fassung dieser Seite ist der verbindliche Vertrag.
Sicherheit
Was wir heute umsetzen, woran wir arbeiten, und wie Sie uns zur Sicherheit erreichen.
Zuletzt aktualisiert: 2026-05-27
Overview
SendRad is an early-stage product. We take security seriously and implement controls in code and infrastructure. We are not GDPR-certified or SOC 2 Type II certified today. We are building toward those practices.
For privacy details, see our Privacy Policy. To report a security concern, contact hi@sendrad.com.
Official Meta Business Partner

SendRad is an official Meta Business Partner. WhatsApp, Instagram, and Messenger connect through Meta's official partner path. That is the approved way to message customers, so your number stays on a supported setup instead of an unofficial tool that can get an account restricted.
You still follow Meta's own messaging rules. We connect the official way so the channel itself is not put at risk by the tool you use.
Controls we implement today
- Authentication: Supabase Auth with server-side session handling and secure cookie defaults in production.
- Database isolation: Postgres row-level security (RLS) on tenant tables; workspace membership checks on server actions and API routes.
- Webhook integrity: Verified signatures for messaging and billing webhooks before processing payloads.
- Secrets: API keys and tokens kept server-side; Google refresh tokens encrypted at rest when
TOKEN_ENCRYPTION_KEYis configured. - AI safety: Structured JSON outputs validated before sends; idempotency keys for agent runs and outbound messages to reduce duplicate replies.
- Rate limiting: Auth and sensitive endpoints throttled to reduce brute-force and abuse.
- Analytics: PostHog EU Cloud for product analytics and (when enabled) session replay, with consent before non-essential cookies. Inbox chat content is excluded from replay. Vercel Web Analytics remains a cookieless backup on marketing pages.
- Logging: Operational logs use correlation IDs; we avoid logging full message bodies or secrets.
GDPR readiness. Where we are
GDPR is a compliance program, not a certificate. For a solo founder selling globally, a practical path looks like this:
- Done or in progress: public Privacy Policy and Terms, RLS, consent-gated PostHog analytics, signup consent with versioned acceptance records.
- Next: records of processing (ROPA), data subject request playbook, retention/deletion schedule, breach response checklist, signed DPAs with key vendors, international transfer documentation.
- When you scale: lawyer review for EU/UK customers, DPA template for B2B buyers, optional EU data residency discussions with Supabase/Vercel.
Rough timeline for a small team: basic GDPR-ready documentation in weeks; mature program often 2–6+ months with legal help.
SOC 2 readiness. Where we are
SOC 2 Type I is a point-in-time design review; Type II requires operating controls over months (often 3–12). Funded startups usually pursue SOC 2 when enterprise customers require it.
- Foundation (now): access control on production, secrets management, dependency updates, incident logging.
- Policies (next): written security policy, vendor review, onboarding/offboarding, change management, backup and restore tests.
- Audit path: Type I when policies + controls exist; Type II after evidence period with an auditor (typical cost: tens of thousands USD depending on scope).
For a pre-revenue solo founder, SOC 2 is usually not urgent until enterprise sales require it; focus first on Privacy Policy accuracy and secure product defaults.
Your responsibilities as a customer
You choose what data to connect, how agents are instructed, and whether AI is enabled. Use strong passwords, limit workspace access, comply with messaging platform rules, and obtain lawful consent from your leads.
Contact
Email: hi@sendrad.com
Contact form: sendrad.com/contact