Built to protect sensitive founder materials.
This page is maintained by SendRoom to answer common security, privacy, and deliverability questions. It describes controls and practices built into the product — not an independent certification or audit of SendRoom itself.
Enterprise-grade infrastructure under the hood
SendRoom is built on a platform that maintains SOC 2 Type II and ISO 27001:2022 certifications. Storage, authentication, and hosting sit on infrastructure operated to those standards. SendRoom itself is not separately certified.
Every document is behind an access gate and served by short-lived signed URLs
- All traffic and files are sent over TLS. Documents live in private cloud storage and are served through signed, time-limited URLs — never raw public links.
- Investors identify themselves with name and email before viewing anything — there is no anonymous access. Row-level security policies enforce that admins only see rooms and documents they own. Per-link passcodes are available and can be required per share link.
- Share links can be scoped to specific documents or folders, so an investor only sees the exact materials you chose for that link.
- Documents render in an in-browser viewer with a viewer-identity watermark on Founder Plus and higher plans. Downloads are off by default — you enable them per document or per share link.
- NDA acceptance can be required per share link on Founder Plus and higher; the investor must accept the NDA text you provide before the room opens.
- Every view is logged with viewer identity, timestamp, and dwell time, so you can see exactly who saw what and for how long.
Invitations that actually reach investors
Room invitations and notifications send from SendRoom's verified sending domain (notify.sendroom.io), so messages look professional and land in the right inbox.
- Authenticated email with SPF, DKIM, and DMARC records configured for notify.sendroom.io
- Sent through SendRoom's verified email domain with built-in queueing and delivery logging
- Built-in send-test button and full email log inside the admin, so you can confirm delivery and diagnose bounces before you ever email investors
Every send attempt is logged — status code, provider response, sender address — so you are never guessing why an invite did not arrive.
You own your room. You can delete it.
- When you cancel your SendRoom account, your uploaded documents, share links, and viewer records are removed from active systems.
- Access logs may be retained briefly to support billing and abuse investigations, then deleted.
- SendRoom does not sell viewer data and does not use your documents to train any model.
Security contact
If you believe you've found a security issue with SendRoom, please email security@sendroom.io. We aim to acknowledge reports within two business days.
Independent trust seals
SendRoom is preparing to display verified trust seals from recognized security providers. Once activated, those badges will appear here and in the footer.
Norton Secured
Badge pending provider script
McAfee Secure
Badge pending provider script
TrustedSite
Badge pending provider script