Security & Data Compliance

Enterprise-grade security protocols, privacy-first architecture, and SOC 2 preparedness.

1. Data Compliance & Privacy Protocols

At Solidrix Send, we recognize that email delivery involves handling sensitive Personally Identifiable Information (PII). Our architecture is built on the principle of least privilege and strict data isolation.

  • GDPR & CCPA Ready: We provide full support for Data Subject Access Requests (DSARs), including the Right to Erasure (Right to be Forgotten). When a contact is deleted, their data is scrubbed from all our active databases.
  • Zero Data Selling: We operate strictly as a data processor. We do not sell, rent, or scan subscriber lists for advertising purposes.
  • Data Residency: All core databases are hosted in isolated virtual private clouds (VPCs) with strict firewall rules, preventing public internet access to data stores.

2. SOC 2 Preparedness & Access Control

We are actively aligning our internal operations with the AICPA's Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy) in preparation for an official SOC 2 Type II audit.

  • Role-Based Access Control (RBAC): Internal access to production environments is strictly limited to authorized senior engineers requiring VPNs and multi-factor authentication (MFA).
  • Audit Logging: All critical system changes, deployments, and access events are logged and monitored.
  • Incident Response: Dedicated incident response plans are in place to mitigate potential breaches within SLAs.

3. Cryptography & Encryption Protocols

We employ modern cryptographic standards to ensure data remains secure both while moving across networks and when stored on disk.

  • Data in Transit: All API requests, dashboard access, and webhook deliveries are enforced over HTTPS using TLS 1.2 or TLS 1.3.
  • Data at Rest: Sensitive credentials (like third-party SMTP passwords and API keys) are encrypted in the database using AES-256-CBC.
  • End-to-End Encryption (E2EE) - Upcoming: We are pioneering an open-source library that will allow clients to encrypt email payloads using Public/Private Key pairs before they leave their server. Solidrix Send will route the cipher-text without ever being able to read the underlying message.

4. Infrastructure Resilience

Reliability is a core security principle. If a system goes down, it becomes a security risk.

  • Smart Airbag™ Defense: Automated circuit breakers quarantine massive traffic spikes into Redis holding tanks, preventing database exhaustion and protecting sender reputation.
  • DDoS Protection: Traffic is proxied through enterprise-grade edge networks that automatically mitigate volumetric distributed denial-of-service (DDoS) attacks.
  • Multi-Gateway Redundancy: Complete architectural decoupling ensures that if one upstream provider (e.g., AWS SES) experiences an outage, traffic fails over seamlessly to backup gateways.

Need more details? For customized DPA (Data Processing Agreements) or specific compliance questionnaires, please contact our security team at [email protected].