SendBeam

Security · Questionnaire pack

Security questionnaire answers

The answers a security review asks for, in the order the standard questionnaires ask them. Every answer is a fact stated elsewhere on this site. Last reviewed 25 September 2026.

Need it as a document, or have a bespoke questionnaire? Send it over and we answer from the same facts. The long-form version of most answers is on Security and trust.

01 · Company and service

Company and service

What is SendBeam?
Email marketing and transactional email for people who run more than one website: one account, a workspace per site, each with its own lists, forms, automations and sending domain.
Where is the company based?
The United Kingdom. Governing law for the contract is England and Wales.
Is there a Data Processing Addendum?
Yes. The DPA forms part of the Terms of Service and applies to every account from signup; a countersigned copy is available on request.

02 · Hosting and data location

Hosting and data location

Where is customer data stored?
The database and authentication run on Supabase in London (United Kingdom). The application runs on Cloudflare’s network. Email is delivered through Resend (United States) and, for selected workspaces, Microsoft Azure Communication Services (United Kingdom).
Is there a published sub-processor list?
Yes, in the privacy notice, with what each provider does and where it processes. Customers get at least 30 days’ notice before a sub-processor is added or replaced.
Can data residency be chosen?
Not as a per-customer option today. Storage is in the UK; delivery routes are as listed above.

03 · Access control and authentication

Access control and authentication

How do users authenticate?
Email and password, a one-click email link, GitHub, or single sign-on through the customer’s SAML 2.0 identity provider (Business plan).
Is multi-factor authentication available?
Yes, with an authenticator app. An account admin can require it for every member. Platform staff are required to use it.
Can access be restricted by network?
Yes. An account admin can set an IP allow-list; sessions from outside it are refused.
Is user provisioning and deprovisioning automated?
Yes. SCIM 2.0 at /scim/v2 lets the customer’s identity provider create, update and deactivate people on the account; deactivation removes every seat the same day.
Can single sign-on be made mandatory?
Yes. An account admin can require SSO; a password, link, GitHub or passkey session is signed out and sent to the identity provider.
Are session lifetime and idle timeout configurable?
Yes. An account admin sets a maximum session lifetime (hours) and an idle limit (minutes); either ends the session and requires a fresh sign-in.
Are passkeys supported?
Yes. Passkeys (WebAuthn) are the recommended sign-in; they are phishing-resistant and count as two factors.
How is access within the product controlled?
Workspace roles (admin and member), per-workspace membership, and per-API-key permission scopes. Platform staff access is a separate plane, audited.
Is there an audit log?
Yes. Workspace admins see their own log under Settings → Audit log and through the API: sign-ins, keys, team, sending, webhooks, connections, exports and policy changes, each with actor, target, time and source address. Entries cannot be altered and are kept for 12 months. Platform staff actions are recorded separately.

04 · Data protection

Data protection

Is data encrypted?
In transit with TLS everywhere; at rest by the storage providers (Supabase Postgres and Cloudflare R2 for backups). Backups are additionally encrypted with a key held by the company.
How are secrets and keys handled?
API keys are stored hashed; only a prefix is kept in clear. Connector tokens are sealed at rest. Webhook signing secrets are shown once at creation.
How long is data kept?
Contacts and lists for as long as the workspace exists, and an admin can export or delete them at any time. Per-message send history is kept for 400 days; campaign headline statistics are kept with the campaign.
Can a customer delete their data?
Yes: an admin can export or delete a whole workspace under Settings without contacting us. Deletion removes the workspace’s data; suppression records survive as a masked hash so unsubscribes stay honoured.

05 · Resilience

Resilience

Are there backups, and are they tested?
Nightly encrypted backups to object storage, restore-verified into a scratch database on every run. A written disaster-recovery procedure exists with a key held by the company’s owner.
Is availability monitored?
Independently, with public status at status.sendbeam.io and internal heartbeats on the scheduled jobs.
Is there an SLA?
Not as a standard term today. Business customers can ask for one as part of their agreement.

06 · Security practice

Security practice

Has the service been penetration tested?
Yes, in September 2026; the findings were closed before this page was published.
Is there a vulnerability disclosure route?
Yes: security.txt and a published disclosure policy with a safe harbour for good-faith research.
Are there SOC 2 or ISO 27001 certifications?
No. We say so plainly on the security page rather than present a supplier’s certificate as ours.
How are incidents handled?
A written incident response plan; affected customers are told without undue delay, and the ICO is informed where the law requires.

07 · Email compliance

Email compliance

How is consent handled?
Double opt-in per list (mandatory on the Free plan), with the source, time and IP of each confirmation kept against the contact and exported with it.
How is unsubscribe handled?
Every marketing message carries List-Unsubscribe and List-Unsubscribe-Post headers and a visible link; one click takes effect immediately and a suppressed address cannot be re-added.
How is abuse prevented?
Per-workspace sending health measured against complaint and bounce limits stricter than the mailbox providers’; a workspace that crosses the line pauses automatically. Imports are checked for undeliverable domains.

Start

Start with the site you run today.

Free to start, no card, no trial clock. Each site keeps its own domain, list and rules; you add the next one as a workspace whenever you launch it.

Checking system status