Third Party Index

Snapshot 48813

Document
Security page
URL
https://supersend.io/legal/security-measures
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
54084 bytes
SHA-256 (raw)
0be74774ed96d725038b4b9a762c279efa3ddbba2c1d195881786846a274561e
SHA-256 (normalized text)
2c227f63c2990c56fb8203d98cc45a11a88336290c94fafa7f2dc63b89591d5c

Normalized text

Scripts and page chrome removed; this is what change detection compares.

1. Encryption & Data Protection
•Data in transit: TLS encryption for HTTPS, API, and database connections.
•Data at rest: Google Cloud Platform default encryption for databases and object storage.
•Application secrets stored in GCP Secret Manager.
•Redis (GCP Memorystore) operates within private VPC networking.
2. Access Control
•Role-based access control (RBAC) across systems and Kubernetes workloads.
•Administrative access to production infrastructure and source control uses Google Workspace single sign-on with mandatory two-factor authentication (2-Step Verification).
•Unique individual user accounts; shared administrative accounts are not used for production systems.
•Service accounts limited to least-privilege permissions.
3. Application Security
•Pull-request code review and dependency updates as part of the development process.
•Security headers (e.g. HSTS, XSS protection) on the API via Helmet.
•Application error monitoring via Sentry; centralized logging via Grafana/Loki.
•Third-party penetration testing is not performed on a fixed schedule; it may be conducted for enterprise engagements upon request.
4. Business Continuity & Disaster Recovery
•Daily automated backups of critical databases (GCP Cloud SQL) with 30-day retention.
•Recovery Time Objective (RTO): < 4 hours (internal target).
•Recovery Point Objective (RPO): < 24 hours (internal target).
•Business continuity and disaster recovery measures are documented in this policy.
5. Vendor & Sub-processor Management
•Sub-processors vetted for ISO 27001/SOC 2 and GDPR compliance where applicable.
•Sub-processor register reviewed and updated when vendors change; customers notified at least 30 days before new sub-processors process their data, per applicable DPAs.
•Public list available at supersend.io/legal/subprocessors.
6. Incident Response
•Automated monitoring and alerting via Sentry, Grafana/Loki, and Prometheus metrics.
•Escalation channels for high-severity incidents.
•Customer notification within 72 hours of a confirmed data breach affecting their data, where legally required.
Last Updated July 6, 2026 | GDPR Compliance v2026-07
Run cold email and LinkedIn from one sequence.
Set up free, no card. 7-day free trial when you launch. Plans from $59/month.
Get startedSee pricing
Start your first sequence today.
Connect an inbox, add your LinkedIn, and build your sequence. Set up free, no card. 7-day free trial when you launch. Plans from $59/month.
Get startedSee pricing