Security

Security that survives review.

The controls your security team asks about — documented, audited, and enforced in architecture.

Architecture

SendFlit runs fully managed in isolated cloud infrastructure. Your data — contacts, templates, message content — is stored encrypted and scoped per account.

API traffic is stateless and horizontally scaled; no single component is a failure domain for delivery.

Encryption

TLS 1.2+ for all traffic in transit. AES-256 at rest for stored data, including message archives and audit logs.

Per-domain DKIM keys are generated in isolated workers and never leave the signing pipeline.

Access control

Scoped API keys: send-only keys for agents, with no PII export, domain management, or billing access.

Human accounts support SSO/SAML on Enterprise. Every key creation, revocation, and admin action is audit-logged.

Agent governance

Approval gates route policy-triggered sends (broadcast size, new domains, external recipients) to a human before delivery.

Agent keys cannot bypass gates, export contact lists, or alter policy — enforced at the API layer, not in prompts.

Incident response

Documented IR plan with severity tiers, containment, and customer notification within 24 hours for confirmed incidents.

Postmortems published to affected Enterprise customers within 5 business days.

SOC 2 Type IIGDPR99.9% SLAAES-256TLS 1.2+

Need our security docs?

SOC 2 report, DPA, and completed questionnaire available under NDA.