Security, privacy & compliance

Sendsteps Trust Center

Sendsteps handles your data and tries to do that in the most secure way possible. We believe in transparency in how we handle security and data privacy.

In brief

Trust at a glance

Encryption

Traffic in transit is encrypted with SHA-256 with RSA. Data on our servers is encrypted with AWS RDS Encryption (AES-256). Infrastructure is accessible only by the development team and through VPN. All activity is logged and audited.

Infrastructure

Sendsteps is hosted on AWS (Amazon Web Services). Currently, our infrastructure is located in the EU (Germany). Data is stored redundantly at multiple locations in our hosting provider’s data centres.

ISO 27001

Sendsteps is ISO 27001 certified (Information Security Management System). View certificate.

Staff practices

Background checks include an official statement of good behaviour granted by the Dutch government. Staff take security and data privacy training. Strong passwords that expire, disk encryption, and multi-factor authentication (MFA) wherever possible.

Monitoring and logging

We monitor performance and security with infrastructure and application monitoring tools. Production has a centralized logging environment covering security, monitoring, availability, access and other metrics.

Availability and recovery

Approximate availability of Sendsteps services is at 99.95%, as stated in Security Standards v2.0. Disaster recovery is tested annually. Data and source code are automatically backed up on a regular basis.

Explore

Privacy, terms and cookies

The Security Standards sit alongside these documents. Nothing below is a summary of a document we have not published.

Privacy statement

What personal data we process, on what legal basis, for how long, with which sub-processors, and how you can exercise your rights. Version 2.1, 4 August 2026.

Terms of Service(s)

The conditions that apply to Free Services and Paid Services, including data processing (clause 10). Version 15, effective 30 October 2024.

Cookie statement

The categories of cookies Sendsteps uses (Essential, Functional, Analytical, Tracking) and the Cookiebot declaration of cookies in use.

Security Standards

How we put security and privacy policy in practice

The full Sendsteps Security Standards. Version 2.0, 3 April 2026. Internal links in this document point to the privacy statement and terms of service on this site.

Read

Our documents

Published documents only. Data processing is set out in clause 10 of the Terms of Service(s). Sub-processors are listed in the privacy statement. External security audit reports are available on request via legal@sendsteps.com.

Need additional information?

Questions about how we process personal data go to our Data Protection Officer. Legal matters, including a request for the most recent external security audit report, go to legal@sendsteps.com.

Choose language

English Nederlands Deutsch Español