Trust & Security

Built to protect sensitive founder materials.

This page is maintained by SendRoom to answer common security, privacy, and deliverability questions. It describes controls and practices built into the product — not an independent certification or audit of SendRoom itself.

Platform certifications

Enterprise-grade infrastructure under the hood

SendRoom is built on a platform that maintains SOC 2 Type II and ISO 27001:2022 certifications. Storage, authentication, and hosting sit on infrastructure operated to those standards. SendRoom itself is not separately certified.

Encryption & access controls

Every document is behind an access gate and served by short-lived signed URLs

  • All traffic and files are sent over TLS. Documents live in private cloud storage and are served through signed, time-limited URLs — never raw public links.
  • Investors identify themselves with name and email before viewing anything — there is no anonymous access. Row-level security policies enforce that admins only see rooms and documents they own. Per-link passcodes are available and can be required per share link.
  • Share links can be scoped to specific documents or folders, so an investor only sees the exact materials you chose for that link.
  • Documents render in an in-browser viewer with a viewer-identity watermark on Founder Plus and higher plans. Downloads are off by default — you enable them per document or per share link.
  • NDA acceptance can be required per share link on Founder Plus and higher; the investor must accept the NDA text you provide before the room opens.
  • Every view is logged with viewer identity, timestamp, and dwell time, so you can see exactly who saw what and for how long.
Deliverability

Invitations that actually reach investors

Room invitations and notifications send from SendRoom's verified sending domain (notify.sendroom.io), so messages look professional and land in the right inbox.

  • Authenticated email with SPF, DKIM, and DMARC records configured for notify.sendroom.io
  • Sent through SendRoom's verified email domain with built-in queueing and delivery logging
  • Built-in send-test button and full email log inside the admin, so you can confirm delivery and diagnose bounces before you ever email investors

Every send attempt is logged — status code, provider response, sender address — so you are never guessing why an invite did not arrive.

Retention & data handling

You own your room. You can delete it.

  • When you cancel your SendRoom account, your uploaded documents, share links, and viewer records are removed from active systems.
  • Access logs may be retained briefly to support billing and abuse investigations, then deleted.
  • SendRoom does not sell viewer data and does not use your documents to train any model.
Reporting an issue

Security contact

If you believe you've found a security issue with SendRoom, please email security@sendroom.io. We aim to acknowledge reports within two business days.

Third-party verification

Independent trust seals

SendRoom is preparing to display verified trust seals from recognized security providers. Once activated, those badges will appear here and in the footer.

Norton Secured

Badge pending provider script

McAfee Secure

Badge pending provider script

TrustedSite

Badge pending provider script