Security & responsible disclosure
Effective date: July 25, 2026
Last updated: July 26, 2026
Document version: 2026-07-26
This page describes practices we actually implement. SendFable is a service operated by iScream Studio INC. We do not claim SOC 2, ISO 27001, HIPAA, PCI certification beyond Stripe's role as payment processor, penetration-test scores, or other formal certifications unless we link to a current report.
General approach
- Encryption in transit via HTTPS/TLS for the public application.
- Access controls on production systems and least-privilege cloud credentials where used.
- Role-based access inside Workspaces (OWNER / ADMIN / MEMBER).
- Tenant isolation controls so Workspace data is scoped by Workspace membership.
- Database backups and, when enabled, encrypted off-host backups.
- Operational health checks and logging for reliability and abuse response.
- Incident response: investigate, contain, remediate, and notify as appropriate and required.
Accounts & authentication
- Passwords stored as one-way bcrypt hashes, not plaintext.
- Magic-link sign-in uses time-limited tokens emailed only to the claimed address.
- Session auth via Auth.js / NextAuth with server-side checks on app routes.
- No requirement for Google or Microsoft OAuth.
Payments and email delivery
- Stripe handles payment-card details; we store billing identifiers and subscription state, not full PANs.
- Amazon SES / AWS handles campaign delivery and related bounce/complaint feedback.
Sending & abuse controls
- Acceptable Use prohibitions on purchased/scraped lists and abusive content.
- Campaign auto-pause on elevated bounce or complaint rates.
- Suppression of hard bounces, complaints, and unsubscribes.
- New-account daily send ramps and plan quotas.
- Manual sending holds for abuse or payment risk.
No absolute guarantee
No internet service can guarantee perfect security or uninterrupted availability. See also the disclaimers in our Terms and Privacy Policy.
Customer security responsibilities
- Protect account credentials and mailbox access used for magic links.
- Invite only trusted Authorized Users and remove access you no longer need.
- Keep Recipient permission and list hygiene lawful.
- Do not share secrets in campaign content or support tickets.
Responsible disclosure
Report suspected vulnerabilities to security@sendfable.com or through our contact form (topic: Security issue). Please include:
- A clear description of the issue and potential impact
- Steps to reproduce or proof-of-concept details (non-destructive)
- Affected URLs, accounts (test only), and approximate timing
- Your contact information for follow-up
Do not publicly disclose the issue before we have had a reasonable chance to remediate. Do not perform destructive testing, data exfiltration beyond what is needed to demonstrate the issue, social engineering of staff or Customers, or attacks on other VPS applications sharing infrastructure. We aim to acknowledge good-faith reports and keep you updated, but we do not guarantee a fixed response deadline or bounty.
Privacy requests
For privacy or data requests, email privacy@sendfable.com or see our Privacy Policy.
Ready to send your story?
Start writing free, import opted-in contacts, and send your first campaign. No credit card required.