Security information & certifications
Documentation of the security measures and practices Sendcloud B.V. has in place when handling personal data.
Last updated on 2024-11-28
ISO 27001
Statement

We have been ISO 27001:2013 certified since January 2021. Our platform and our entire organization is in scope of this certification. Furthermore, we leverage other industry best practices, such as OWASP & NIST. As part of our ISO PDCA cycle, we have a Risk Management framework. Sendcloud actively works on finding, limiting and re-assessing our information security risks.

Penetration test report
Statement

Penetration testing:

Sendcloud undergoes annual penetration testing conducted by an independent third-party agency. All testing is done in an isolated clone environment, which means no production systems are affected. No customer or consumer data is exposed in any testing. The outcomes of these tests are fed into our mitigation & remediation process to improve the security maturity of our platform.

We also leverage a HackerOne Bug Bounty Program and encourage other white hat hackers to find and report vulnerabilities to us under our public Bug Bounty Program: https://www.sendcloud.com/bug-bounty-program/

Security information
Statement

Security is a top priority at Sendcloud, because it is fundamental to the service we provide. Our mission is to make shipping as easy as possible. In doing so, security concerns should never be an issue. We are committed to securing your data and the data of your consumers that is processed via our platform. Sendcloud uses a variety of industry best practice technologies and services to ensure the confidentiality, integrity and availability of your data.

The most recent security measures that are in place, can be found at https://www.sendcloud.com/security/.

Security information
Statement

Encryption: Data you provide to Sendcloud is encrypted at rest & in transit at AWS. Sendcloud only allows data to be transmitted over HTTPS transport layer security (TLS) encrypted connections. We use Amazon Key Management Service to regulate keys within our environment. For any connection made to the Sendcloud platform (API, shop integrations, etc.) we use unique and strong key pairs.

Monitoring: AWS offers us various services to monitor and control our cloud environment, such as AWS Guard Duty and Cloudwatch. Several security tools are implemented to identify abnormalities in the platform. We actively monitor the performance of our entire platform and have extensive follow up mechanisms in place to ensure proper follow up during working hours. We also have engineers on duty for extended support outside of normal working hours.

Data hosting and Cloud platform Sendcloud hosts data in Amazon Web Services data centers in EU Central and EU North regions and ensures continual product availability by using native backup tools. An industry-leading infrastructure provider, AWS is certified as compliant with ISO 27001 and has received a SOC 2 (Type 2) report.

All components that process your data operate in Sendcloud’s private network inside our secure cloud platform.

Displaying 4 securities