Encryption
Traffic in transit is encrypted with SHA-256 with RSA. Data on our servers is encrypted with AWS RDS Encryption (AES-256). Infrastructure is accessible only by the development team and through VPN. All activity is logged and audited.
Sendsteps handles your data and tries to do that in the most secure way possible. We believe in transparency in how we handle security and data privacy.
Traffic in transit is encrypted with SHA-256 with RSA. Data on our servers is encrypted with AWS RDS Encryption (AES-256). Infrastructure is accessible only by the development team and through VPN. All activity is logged and audited.
Sendsteps is hosted on AWS (Amazon Web Services). Currently, our infrastructure is located in the EU (Germany). Data is stored redundantly at multiple locations in our hosting provider’s data centres.
Sendsteps is ISO 27001 certified (Information Security Management System). View certificate.
Background checks include an official statement of good behaviour granted by the Dutch government. Staff take security and data privacy training. Strong passwords that expire, disk encryption, and multi-factor authentication (MFA) wherever possible.
We monitor performance and security with infrastructure and application monitoring tools. Production has a centralized logging environment covering security, monitoring, availability, access and other metrics.
Approximate availability of Sendsteps services is at 99.95%, as stated in Security Standards v2.0. Disaster recovery is tested annually. Data and source code are automatically backed up on a regular basis.
The Security Standards sit alongside these documents. Nothing below is a summary of a document we have not published.
What personal data we process, on what legal basis, for how long, with which sub-processors, and how you can exercise your rights. Version 2.1, 4 August 2026.
The conditions that apply to Free Services and Paid Services, including data processing (clause 10). Version 15, effective 30 October 2024.
The categories of cookies Sendsteps uses (Essential, Functional, Analytical, Tracking) and the Cookiebot declaration of cookies in use.
Sendsteps is ISO 27001 certified. The certificate covers our Information Security Management System (ISMS).
View ISO 27001 certificate (PDF) →
We process personal data as Controller or Processor within the meaning of the EU General Data Protection Regulation. Privacy is built into the platform, not added later. Questions go to our Data Protection Officer.
Read the privacy statement →
The full Sendsteps Security Standards. Version 2.0, 3 April 2026. Internal links in this document point to the privacy statement and terms of service on this site.
Sendsteps handles your data and tries to do that in the most secure way possible. When speaking about data we discern the categories as described in our privacy statement.
As a company Sendsteps firmly believes in transparency both in a business as well as in a security context. We always try to be as open and clear as possible in the way we handle both security and (data) privacy. If you are looking for more information on how we treat your personal information or information about the third-parties we work with please have a look at our privacy statement.
In this document we give you a look into our organization and the way we put our security and privacy policy in practice.
In our Terms and Conditions we guarantee to keep your account and personal data confidential. However, as also described in our Terms, if you use our "Free" version, all data we gather can be used for promotion purposes, on our website and can be shared with third parties. If you want your data to be handled in a more secure way we highly recommend using our of our paid plans.
Our staff and third parties, anyone of whom needs to work with your data is contractually obligated to keep that confidential.
As a company we place the greatest amount of importance on making sure the highest possible level of security is in place. Our staff plays an important role in this, therefore we have placed strict controls over our staff and all our processes.
When hiring a new staff member we perform background checks during the hiring process. Including an official statement of good behaviour granted by the Dutch government. When hired each staff member is required to take a security and data privacy training with our Security Officer. During said training the focus is on how to work securely using both our own tools as well as the tools we use from third parties, handling sensitive information (including your personal data). Physical security as well as general security best practices are also covered.
Working at Sendsteps means for some employees that they need to have access to systems that store and process sensitive data. For example, if something went wrong with your payment we may need to access your personal data in order to diagnose the problem. Sendsteps and her employees are committed to making sure that sensitive data is never seen by anyone who doesn't need access to it. We use restrictions on the application layer to make sure that each member of staff only has access to the data that is needed to perform their jobs. These employees are prohibited from using these permissions to view sensitive our personal data unless it is necessary to do so.
Sendsteps performs regular internal audits to make sure we adhere to our own high security standards. Additional checks are made when an employee leaves the company. Also we force every employee to use strong passwords that expire and disk encryption. Multi-factor authentication (MFA) is used wherever possible.
When using Sendsteps, it is possible to export your data through our dashboards.
Upon request of our customers it is possible to delete the data of a specific event. We will process this request when it comes it, usually within 24 hours. Our customer support will happily provide you any sort of assistance necessary.
Sendsteps is hosted on AWS (Amazon Web Services) infrastructure. Currently, our infrastructure is located in the EU (Germany).
Amazon Web Services maintains multiple certifications for its data centres, including ISO 27001 compliance, PCI Certification, and SOC reports. For more information about their certification and compliance, please visit the AWS security website and the AWS compliance website.
When it comes to our server architecture we use a tiered model that keeps services and functions as much as possible within the specific tier.
Sendsteps uses the latest available suites and protocols to encrypt (SHA-256 with RSA Encryption) all traffic in transit. Your data on our servers is encrypted (AWS RDS Encryption - AES-256) as well, our infrastructure is accessible only by the development team and through VPN. All activity is logged and audited.
We closely monitor any changes in the cryptographic landscape work promptly to upgrade our products to respond to new cryptographic weaknesses as they are discovered and implement best practices as they evolve. For encryption in transit, we do this while also balancing the need for compatibility for older versions of commonly used browsers.
Approximate availability of Sendsteps services is at 99.95%. Our infrastructure runs on systems that are fault tolerant of failures of individual servers. Sendsteps' quality assurance team tests disaster recovery measures on an annual basis.
Your data is stored redundantly at multiple locations in our hosting provider's data centres to ensure availability. We have well-tested backup and restoration procedures, which allow recovery from a major disaster. Both your data and our source code are automatically backed up on a regular basis.
We closely monitor both performance as well as security of our products and services. We use infrastructure as well as application monitoring tools. In combination with specialized tools for analysis and data visualization, it gives us strong insights about the condition our services are in. Sendsteps has an extensive, centralized logging environment in its production environment which contains information pertaining to security, monitoring, availability, access, and other metrics about our whole range of products.
In development we follow our own implementation of Agile/Scrum methodology. We frequently release new versions of our products and continuously change our workflow based on evolving needs and the lessons drawn from the past.
All our software is tested extensively by our quality assurance team. These checks are performed both manually as well as automated. Newly created code is peer reviewed and only put live it meets a set of pre-defined requirements.
New code is deployed to our staging environment first. There a set of automated tests as well as manual test are run to ensure the best quality possible. If everything works as expected, the new feature is put live. In case of emergencies, serious bugs or if anything else goes wrong, we are able to release a fix for the problem within the hour.
In the unlikely event of a security breach, Sendsteps will promptly notify you personally of any unauthorized access to your data. We have incident management policies and procedures in place to handle such an event.
On a regular basis Sendsteps' systems are audited by respected external security firms to ensure that our practices stay on par with current security standards. On request we can provide you with the most recent report of these audits.
Published documents only. Data processing is set out in clause 10 of the Terms of Service(s). Sub-processors are listed in the privacy statement. External security audit reports are available on request via legal@sendsteps.com.
Questions about how we process personal data go to our Data Protection Officer. Legal matters, including a request for the most recent external security audit report, go to legal@sendsteps.com.