Security
Your audience is the asset. We secure it like one.
The list you upload to Retensive took real money and years to build. Everything below — isolation, encryption, access control, send-time safeguards — exists to make sure it stays yours, stays private, and is never put at risk by a send.
01Platform security
Locked down by design.
The controls that protect your workspace and the data inside it.
Tenant isolation
Each workspace's data is logically isolated. Contact data is never pooled across customers, never shared between tenants, and never used to benefit anyone but its owner.
Encryption everywhere
Data is encrypted in transit (TLS) and at rest. Credentials and API keys are stored hashed or encrypted, never in plain text.
Role-based access control
Granular roles separate editing, reviewing, and sending. Launching a campaign is a permission, not a default — and so is exporting contacts.
Audit logs
Sends, suppressions, exports, permission changes, and configuration changes are recorded with actor and timestamp, so there's always an answer to "who did what, when".
Permission-gated exports
Bulk contact exports require an explicit permission grant and always appear in the audit log. Your list can't quietly walk out the door.
Sender authentication
SPF, DKIM, and DMARC verification are built into sender setup and monitored continuously, so no one can send as you without proving they're you.
02Send-time safety
Security doesn't stop at the database. It rides every send.
A million-recipient send is the moment your reputation, your consent obligations, and your recipients' trust are all on the line. These safeguards are on by default.
Suppression integrity
Unsubscribes and complaints are enforced platform-wide, immediately, on every send path. There is no way to email a suppressed contact.
Consent as data
Opt-in state lives on the contact profile and is checked at send time — not reconstructed from a spreadsheet afterwards.
Blast-radius controls
Canary batches, pacing, and the mid-send brake mean a mistake reaches hundreds, not millions, before it's caught.
Complaint monitoring
Provider feedback loops and complaint signals are watched live, and sends that trip them are paused automatically.
03Data handling
Your data. Your rules. Your exit.
The commitments behind the checkboxes, spelled out in full in our privacy policy.
You can always leave
Contacts, consent records, suppression lists, and templates are exportable at any time. No lock-in by hostage-taking.
Deletion that means it
Delete contacts or close a workspace and the data is removed from live systems within 30 days and from backups within 90.
No secondary use
Customer contact data is never sold, never used for our own marketing, and never used to train models or build shared profiles.
Minimal collection
We collect what the product needs to work. No advertising trackers, no cross-site cookies, no data brokers.
Where we are on certifications
We're an early-stage platform, and we won't put badges on this page that we haven't earned. Formal certifications are on our roadmap; the practices above are how we operate today. If your procurement process needs specifics — data flow diagrams, subprocessor lists, security questionnaires — ask, and we'll answer directly.
Found a vulnerability?
We want to hear about it before anyone else does. Report it to security@retensive.com with enough detail to reproduce it. We'll acknowledge within 2 business days, keep you posted while we fix it, and credit you if you'd like. Good-faith research done responsibly will never get you in trouble with us.
Get started
The list is already paid for.
Tell us about your audience and volume, and we'll show you what it can do.