Security and control
Controls you can check for yourself.
Nothing reaches your customers without a person’s approval, your provider keys stay sealed, and Sendalto’s own team sees your records only when you allow it. Here is how each control works — and what we don’t claim.
Access
Access that fits each person’s job.
Seven roles, two-factor sign-in, and a fresh confirmation before anything sensitive.
Two-factor sign-in and a fresh confirmation
Every account starts with a verified email. Two-factor authentication works with any authenticator app. Owners and admins can’t change settings, the team, keys or billing, or launch sends, without it — and if they signed in more than 15 minutes ago, Sendalto asks for the password and code again, right where they are.
- Authenticator app with one-time recovery codes
- Changing your password signs out your other sessions
- See and end active sessions in Settings → Security
Seven fixed roles
Owner, admin, marketer, approver, sales, analyst and technical. A marketer drafts, an approver approves, sales handles replies, and a technical member only sets up DNS for the sending domain.
Decisions only the owner makes
The sending policy and autonomy level, the monthly spend cap, privacy requests and Sendalto support access are decided by the owner alone.
Invitations tied to one address
An invitation works only for the invited email, once that address is verified. Links expire after 7 days and can be revoked; only the owner can invite an admin.
Credentials
Your provider keys, sealed.
Sendalto connects to Amazon, HubSpot and your other tools with your own credentials. They are encrypted when saved and never shown again.
Encrypted and bound to your workspace
Provider secrets and access tokens are encrypted with AES-256-GCM. Each sealed value is bound to its workspace and can’t be opened for another one.
Never sent back to the browser
After saving, the cabinet only shows that a key exists. Entering a new one resets the connection check and cancels queued sends through that connection.
API keys you see once
Sendalto keeps only a hash of each key. Keys carry 1–5 scopes, can be revoked, stop working if their creator loses access, and can’t approve or send campaigns. Every request is recorded.
Signed webhooks
Each webhook has its own secret, and every delivery carries an HMAC-SHA256 signature with a timestamp, so your endpoint can verify it. Secrets can be rotated.
Public addresses only
Webhook calls go only to public HTTPS addresses. Sendalto checks every resolved address, refuses private networks and doesn’t follow redirects.
Hardened sessions
Session cookies are HTTP-only and secure, every change is checked against the site’s origin, and sign-in attempts are rate-limited.
Sending safeguards
Nothing goes out without passing the rules.
The system checks these at every send. The AI can propose; it can’t switch them off.
Approval tied to a version
An approval covers one exact version of the audience and content. Any edit withdraws it and cancels queued sends until someone approves again.
A hard monthly spend cap
Sends and AI work reserve budget before they run. At the cap they stop; nothing is bought automatically. Only the owner can change the cap.
Checked again at send time
Consent for this kind of email, unsubscribes, the do-not-contact list and bounces are checked again for every recipient as the email goes out.
Complaints stop sending
A hard bounce or spam complaint reported by Amazon SES puts the address on the do-not-contact list. A complaint also pauses the workspace’s sending until it is reviewed.
Two separate lanes
Lifecycle email goes through your verified domain on Amazon SES, B2B outreach only through a mailbox you own. One do-not-contact list covers both.
Business review before real sending
Before a workspace emails real recipients, Sendalto reviews the business and its use case. Real sending also needs a paid plan, and plans aren’t on sale yet. Test emails to your own address need neither.
AI boundaries
The AI proposes. It never decides.
AI features are being switched on. These boundaries are already built into how they work.
Switching on soon
What the AI can do
- Draft a brand profile from one page of your site — used only after you confirm it
- Propose a plan and marketing emails as editable drafts
- Suggest a reply in the inbox for a person to review and send
- Plan from confirmed brand facts, page excerpts, and anonymous audience and event counts
What it can’t do
- Change the sending policy, roles, permissions or the spend cap
- Send a reply or start a campaign by itself
- Read individual contact records or mailbox messages when planning
- Spend past the cap — every AI run reserves budget first
Three levels of autonomy, set by the owner
SupervisedDefault
The AI only proposes. People create, approve and send everything.
Assisted
AI proposals can be imported as drafts. People still approve and send.
Bounded autonomy
The owner can approve and schedule an AI plan in one step — only within set limits on audience, content, sender, volume and budget.
Support access
Sendalto support sees only what you allow.
Without your permission, Sendalto staff see totals for your workspace — not your records.
Time-limited, read-only, logged
When support needs a closer look, it asks with a reason and a duration from 1 to 72 hours. The owner gets an email and decides in Settings → Security. Access is read-only, starts at approval, ends on its own, and can be revoked at any time.
- Every view and action by Sendalto appears in your access log
- Mailbox addresses stay masked without a grant
- Sendalto’s support console requires two-factor authentication
Privacy requests
Export or erase a person — and keep their opt-out.
When someone asks what you hold about them, or asks to be forgotten, the owner can answer from the cabinet.
Export one person’s data
Download everything Sendalto holds about a person as a JSON file: profile, consent and sources, suppressions, events, sends and inbox messages.
Erase without losing the opt-out
Erasure deletes the person’s records and keeps only a do-not-contact entry for the address, so a later import can’t add them back by mistake.
Confirmed on purpose
Only the owner can erase, with two-factor authentication and the address typed again. Erasure waits until in-flight sends have finished.
In the open
What we don’t claim.
Trust is easier to keep when it isn’t overstated.
- No SOC 2 or ISO 27001 certification. We haven’t been audited, so we show no badges.
- No “GDPR compliant” badge. Sendalto gives you consent records, export and erasure; compliance depends on how you use them.
- No guaranteed inbox placement. Mailbox providers and recipients decide; we report what providers actually told us.
- No published uptime or recovery-time promise yet. Backups run daily and a restore has been tested; we’ll publish targets once they’re measured.
Report a problem
Found something wrong? Tell us.
Security reports and abuse complaints go to the same contact page.
A security vulnerability
Describe what you found and how to reproduce it. Please don’t access other people’s data or disrupt the service while testing, and give us reasonable time to fix it before sharing details.
Unwanted email or abuse
If you received unwanted email sent through Sendalto, send us the message with its full headers. Sendalto can pause a workspace, a sending domain or a mailbox while we look into it.
Set it up and check it yourself.
Setup and test sends are free. Nothing goes out without your approval, and you’ll see the price before any charge.