Skip to content

Security

Your audience is the asset. We secure it like one.

The list you upload to Retensive took real money and years to build. Everything below — isolation, encryption, access control, send-time safeguards — exists to make sure it stays yours, stays private, and is never put at risk by a send.

01Platform security

Locked down by design.

The controls that protect your workspace and the data inside it.

Tenant isolation

Each workspace's data is logically isolated. Contact data is never pooled across customers, never shared between tenants, and never used to benefit anyone but its owner.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest. Credentials and API keys are stored hashed or encrypted, never in plain text.

Role-based access control

Granular roles separate editing, reviewing, and sending. Launching a campaign is a permission, not a default — and so is exporting contacts.

Audit logs

Sends, suppressions, exports, permission changes, and configuration changes are recorded with actor and timestamp, so there's always an answer to "who did what, when".

Permission-gated exports

Bulk contact exports require an explicit permission grant and always appear in the audit log. Your list can't quietly walk out the door.

Sender authentication

SPF, DKIM, and DMARC verification are built into sender setup and monitored continuously, so no one can send as you without proving they're you.

02Send-time safety

Security doesn't stop at the database. It rides every send.

A million-recipient send is the moment your reputation, your consent obligations, and your recipients' trust are all on the line. These safeguards are on by default.

Suppression integrity

Unsubscribes and complaints are enforced platform-wide, immediately, on every send path. There is no way to email a suppressed contact.

Consent as data

Opt-in state lives on the contact profile and is checked at send time — not reconstructed from a spreadsheet afterwards.

Blast-radius controls

Canary batches, pacing, and the mid-send brake mean a mistake reaches hundreds, not millions, before it's caught.

Complaint monitoring

Provider feedback loops and complaint signals are watched live, and sends that trip them are paused automatically.

03Data handling

Your data. Your rules. Your exit.

The commitments behind the checkboxes, spelled out in full in our privacy policy.

You can always leave

Contacts, consent records, suppression lists, and templates are exportable at any time. No lock-in by hostage-taking.

Deletion that means it

Delete contacts or close a workspace and the data is removed from live systems within 30 days and from backups within 90.

No secondary use

Customer contact data is never sold, never used for our own marketing, and never used to train models or build shared profiles.

Minimal collection

We collect what the product needs to work. No advertising trackers, no cross-site cookies, no data brokers.

Where we are on certifications

We're an early-stage platform, and we won't put badges on this page that we haven't earned. Formal certifications are on our roadmap; the practices above are how we operate today. If your procurement process needs specifics — data flow diagrams, subprocessor lists, security questionnaires — ask, and we'll answer directly.

Found a vulnerability?

We want to hear about it before anyone else does. Report it to security@retensive.com with enough detail to reproduce it. We'll acknowledge within 2 business days, keep you posted while we fix it, and credit you if you'd like. Good-faith research done responsibly will never get you in trouble with us.

Get started

The list is already paid for.

Tell us about your audience and volume, and we'll show you what it can do.