Security is part of the workflow.
Sendlander separates organisations, protects authenticated application routes, uses protected session cookies, stores password hashes rather than passwords, and limits connected-service access to the feature a customer chooses. OAuth credentials used by the inbox-placement service are encrypted at rest. Stripe handles raw card details; Sendlander stores billing references and state.
Access
Organisation roles, session controls, email verification, and provider-scoped authorisation reduce accidental access.
Detection
Operational logs, error monitoring, audit records, abuse limits, and provider events support investigation.
Recovery
Infrastructure and data-store recovery controls are operated with our hosting providers. No system can eliminate every risk.
Data control
Disconnect providers, export account data, and request account closure from Account settings.
Your part
Use unique credentials, protect administrator and provider accounts, give only necessary team access, review connections, and report suspicious activity promptly. Never send secrets through the support form.
Report a vulnerability
Email security@sendlander.com with a reproducible description and minimum necessary evidence. Do not access other users’ data, disrupt service, send spam, use automated destructive testing, or publicly disclose an unresolved issue. We will acknowledge good-faith reports and work toward a proportionate response.