Security at Sendlander

Practical controls for a product that touches sensitive sending infrastructure.

Security is part of the workflow.

Sendlander separates organisations, protects authenticated application routes, uses protected session cookies, stores password hashes rather than passwords, and limits connected-service access to the feature a customer chooses. OAuth credentials used by the inbox-placement service are encrypted at rest. Stripe handles raw card details; Sendlander stores billing references and state.

Your part

Use unique credentials, protect administrator and provider accounts, give only necessary team access, review connections, and report suspicious activity promptly. Never send secrets through the support form.

Report a vulnerability

Email security@sendlander.com with a reproducible description and minimum necessary evidence. Do not access other users’ data, disrupt service, send spam, use automated destructive testing, or publicly disclose an unresolved issue. We will acknowledge good-faith reports and work toward a proportionate response.