Is this your company?Buyers are checking Sendoso here. Claim sendoso.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Founded in 2016, Sender, Inc. dba Sendoso (“Sendoso”) is the world’s first Sending Platform. Our fully-integrated solution solves sourcing, physical warehouse storage, inventory tracking, and ROI attribution problems so that businesses can send anything and personalize at scale. This enables our customers to see increased conversion rates, revenue, retention, and ROI. Sendoso is headquartered in Phoenix, Arizona, and currently services over 700 customer organizations.
Sendoso SOC 2 Type 2 Report for Trust Services Criteria of Security, Availability, and Confidentiality. Issued by Barr Advisory, P.A. on 15-Jun-2026.
Oso and SmartSuite FAQ UpdateApr 2026
Updated the FAQ section with information on the launch of Oso, Sendoso's AI Agent, as well as improvements to the SmartSuite feature set.
Sendoso's 2025 Penetration Test External Assessment SummaryJul 2025
Published results of Sendoso's recent 2025 Penetration Test and External Assessment, executed by our third-party test partner NCC Inc.
2025 SOC2 and SOC3 ReportsJun 2025
Sendoso's 2025 SOC 2 Type 2 and SOC 3 Reports have now been posted to the Trust Center
Policy DocumentsDec 2024
All policy documents are updated and reposted for Year 2025
This listing is partial
6/11 details · 55%
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Sendoso SOC 2 compliant?
Sendoso is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Sendoso GDPR compliant?
According to Sendoso's public trust center, Sendoso is GDPR compliant. On SOC2C this listing is Listed.
Is Sendoso CCPA compliant?
According to Sendoso's public trust center, Sendoso is CCPA compliant. On SOC2C this listing is Listed.
Is Sendoso SOC 2 Type I or Type II?
Sendoso is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Sendoso's SOC 2 for a vendor risk assessment?
Yes. Sendoso's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Sendoso penetration tested?
Sendoso hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Does Sendoso offer a Data Processing Agreement (DPA)?
Sendoso publishes a DPA on its trust center; you can request access through SOC2C.
Is Sendoso secure?
Security isn't a single yes/no, but Sendoso is SOC 2 Type II compliant and holds SOC 2 Type II, GDPR, CCPA. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Sendoso have a bug bounty or vulnerability disclosure program?
Sendoso hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@sendoso.com or via a /security page (Sendoso lists a security contact).
Who are Sendoso's subprocessors?
Sendoso lists 1 subprocessor on its trust center, including (Published Separately). Buyers use this for fourth-party risk review.
Where does Sendoso host or store data?
Sendoso's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Does Sendoso offer a Data Processing Agreement (DPA)?
Sendoso publishes a DPA on its trust center. You can request access through SOC2C.
Where is Sendoso's trust center or security page?
Sendoso's trust center is at https://security.sendoso.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Business Information
Service Description Sendoso provides a comprehensive "sending platform" that enables customers to send direct mail and gifts to their clients, partners, employees, and other chosen recipients. The platform is a fully integrated solution that can be accessed through a customer's existing technology stack or via the Sendoso app/Chrome extension. It addresses challenges such as sourcing, physical warehouse storage, inventory tracking, and return on investment (ROI) attribution. This allows businesses to send personalized items at scale and track conversion rates, revenue, retention, and ROI. Sendoso also offers warehousing and distribution services for customer inventory, manages budgets within the platform, and automates sending campaigns. The platform integrates with various customer technology solutions, such as Salesforce and Marketo, to facilitate seamless operations. Business Location and Incorporation The address for Sendoso corporate headquarters is 655 Montgomery St., Suite 1500, San Francisco, CA 94111, United States. California is the company's primary place of business. Under Sendoso's standard contract terms, California law governs between Sendoso and its customers. Sendoso is legally incorporated in the state of Delaware. Location of the Sending Management solution environment The Sendoso solution environment, including all customer data processing & storage, is located entirely within the United States. Production services are hosted at AWS-West-2 (Oregon) with secondary services at AWS-East-1 (Virginia). Sendoso provides service to all customers globally through this solution environment. Tax ID Sendoso's Tax ID is 81-106-3656 DUNS number Sendoso's DUNS number is 095361229 How to report a security/privacy concern or obtain help with security/privacy questions The following mail addresses are available to any Sendoso customer or supplier: security@sendoso.com: for anyone reporting a security concern, or making a general inquiry on a security topic…
SmartSuite and the Oso AI Agent: Features based on GenAI & LLM
Sendoso's Current Use of Generative AI & LLM We provide GenAI/LLM-based capabilities to our customers, branded as Oso, Sendoso’s AI Agent, and the SmartSuite feature set. Oso and SmartSuite are a part of our ongoing commitment to improve the business value of the Sendoso platform for our customers, as well as the Sending experience of our platform users. These features are based on the OpenAI platform and also apply natural language processing. Oso and SmartSuite features currently include: *Oso:* Sendoso's AI Agent. Oso converts natural language requests into: - Real-time data and analytic reports using Sendoso's data through authorized integrations - Intelligent gift recommendations and human-in-the-loop gift sending. *SmartSend:* Provides personalized gift recommendations based on information you supply and other publicly-sourced information. - Combined with Gong Integration: Provides personalized gift recommendations based on data sourced from Gong call transcripts *SmartMessage:* Generates personalized notes to accompany gifts. *SmartDelivery:* Enables sending gifts using externally-sourced address information. The SmartSend Data Flow SmartSend offers gift suggestions based on information that you provide through the SmartSend chat window. SmartSend will supplement this information with externally-sourced and public information to better personalize the gift suggestions it makes. For customers with CRM (e.g., Salesforce) integration to Sendoso, SmartSend also performs a real-time lookup when a SmartSend request is made; if relevant information (specifically related to gift personalization) is identified, it may be used to further inform the gift recommendation. Gift recommendations are returned directly to the user and not retained by Sendoso. Meeting & Transcript Processing Data Flow Sendoso stores reference IDs to meetings (e.g., Gong calls) along with participant information. When a SmartSend request is triggered (such as an email match to a meeting…
Security & Privacy Certifications
SOC2 Type II Report Sendoso generates an annual SOC 2 Type II Report covering the AICPA domains of Security, Availability, and Confidentiality, which can be found on the Sendoso Trust Center. PCI Report on Compliance Sendoso files a Self-Attestation Questionnaire reflecting our use of Stripe Inc. as processor of all payment card activity. Our current filing is for PCI DSS v4.0 using form SAQ-A. Stripe Inc. generates a PCI ROC as a Service Provider, also using PCI DSS v4.0. The Attestation of Compliance (AOC) for both filings can be found on the Sendoso Trust Center. ISO 27001 Certification Sendoso is not ISO-27001 certified at this time. GDPR & CCPA Compliance Sendoso is fully compliant with all aspects of GDPR and CCPA data privacy legislation for the geographies in which they are applicable. Note that no formal external certification is currently required for these privacy regulations.
Sendoso Organization and Training
Security & Privacy awareness training All personnel are required to complete annual security awareness training, which includes topics covering customer data privacy and confidentiality. Training is provided upon hire, and at least once per year thereafter. A summary of the topics covered in training is found in the Resources section of the Trust Center. Employees receive continuing education through online industry-related training and periodic industry conferences on an as-needed basis. Training certification is registered automatically by the company training platform upon successful completion of the training. Training records are audited annually as part of SOC 2 compliance review." Compliance training All employees receive compliance training annually and annually thereafter. This includes training in anti-harassment and anti-bribery as defined in the Sendoso Code of Conduct. Personnel background checks Background verification checks are coordinate by Sendoso HR and executed by an external service partner. Background checks include following components, to the extent allowed by regulations in the hiring jurisdiction: Federal criminal search (10 yrs), county criminal search (7 yrs), national criminal search, employment verification, sex offender registry search, and identity/SSN trace. In all cases, all findings resolved to the satisfaction of Sendoso HR before new personnel are provided access to systems or locations containing customer information. All third parties with technical privileged or administrative access to sendoso.com production systems or networks are subject to a background check or requirement to provide evidence of an acceptable background check. Onboard & offboard processes Onboard and offboard processes are coordinated by the HR department through the Jira work management system. New personnel are required to sign a confidentiality agreement, and are provided access to customer data only after fully clearing the third-party background…
Solution Architecture
Sending Management Platform solution architecture A general overview of the solution architecture is provided in the Sendoso Trust Center. If you have specific architecture questions we are happy to respond to these directly; please contact your Account Manager or send your question directly to security@sendoso.com.
Data Lifecycle & Deletion
Personal information from customers and gift recipients Sendoso processes the minimal amount of personal information required for us to deliver the contracted service to our customer. \- The types of personal Information we process from our customers who are users of the Sendoso platform may include: full name, employer's name, email address, job title, information about their product account preferences, transactional system information (including billing address), and navigational information relevant to use of the Sendoso application including IP address. \- The types of personal information we process from our customer's targeted gift recipients may include: full name, email address, postal address, phone number, navigational information relevant to use of the Sendoso application including IP address, and any supporting information supplied to facilitate successful delivery of direct mail and goods through the service. Please review the Sendoso Privacy Policy at https://sendoso.com/privacy for more detail about data collected and its use in the Sendoso service. Credit Card information from Customer and Gift Recipients Sendoso does not collect, process, or retain credit card information. Customers who choose to make payments by credit card will be connected direct to our 3rd party credit card partner Stripe Inc. Gift recipients will never be asked to provide credit card information. Use of customer data Customer data (data directly supplied by the customer, or directly derived from customer-supplied data) remains the property of the customer throughout the life of the Sendoso service. We use customer data only in the delivery of service defined in contract. This may include our internal research to improve service or to define new service features. Retention schedule for customer data To support delivery of service and any potential follow-on activity that may be identified after individual sending requests are completed, customer data is held through the life…
Data Protection
Customer data encryption All customer data is encrypted at rest using the AES-256 standard, managed through the Key Management Service (KMS) of our hosting partner Amazon Web Services (AWS). All customer data is encrypted in transit using the TLS 1.2 standard. Cryptographic keys All cryptographic keys, including customer database keys, are managed centrally by the Engineering team using the AWS Key Management Service, 256-bit key length, and rotated annually. Network Data Loss Prevention (DLP) We maintain network-based data loss prevention (DLP) systems with a defined ruleset and automated monitoring to alert (or block, as appropriate) unauthorized traffic leaving the network or endpoints. Email filtering and blocks are in place using native Google Workspace capabilities. Endpoint device security Sendoso uses MalwareBytes ThreatDown EDR package on all company-managed workstations. This drives a daily antivirus/malware scan, based on antivirus signature profile that is updated daily. Full disk encryption is implemented on every company-managed device using ThreatLocker. An IRU security agent is installed on every company-managed device to enforce company security policies, and to enable company actions such as disable or wipe of the device in an emergency situation. Company personnel routinely use company-managed devices to access, inspect, and otherwise process customer information, including personal information of the client's customers for whom the client has initiated send requests, in certain normal business activities including system troubleshooting and root cause analysis of suspected security events. In normal business activities, company personnel are prohibited from storing customer information on company workstations or external to the solution environment without express agreement of the customer (which might arise in a customer-driven testing situation, for instance). Handheld/mobile device security Sendoso does not issue or manage personal mobile…
Data Privacy Compliance
Controller / Processor / Sub-processor roles In customer's use of the Sending Management solution, Sendoso operates as a data processor and Sendoso's customer as the data controller. Sendoso suppliers who receive, store, or otherwise process a customer's personal data (or the personal data of the customers and gift recipients) are recognized as data sub-processors. Gift partners Sendoso gift partners are entities who offer and/or provide goods or services to customers through the Sending Management solution. Gift partners are not Sendoso suppliers or data sub-processors, but rather are third-party entities engaged in a direct relationship with the customer reviewing and/or consuming those goods and services. In this situation, Sendoso acts strictly as an intermediary providing a service platform to facilitate the connection between the customer and gift partner; in no circumstance is Sendoso acting as a reseller or a representative for the gift partner. In terms of privacy regulation, the customer and gift partner are responsible to establish their own agreement regarding controller and processor roles. In certain cases, the gift partner may receive a customer's personal information directly from Sendoso, as authorized by the customer in contract. Types of personal data processed as defined under GDPR Sendoso processes Personal Information for delivery of service. In no case does Sendoso collect or receive special categories of personal data as defined under GDPR. \- The types of personal Information we process from our customers who are users of the Sendoso platform may include: full name, employer's name, email address, job title, information about their product account preferences, transactional system information (including billing address), and navigational information relevant to use of the Sendoso application including IP address. \- The types of personal information we process from our customer's targeted gift recipients may include: full name, email…
Suppliers and Sub-Processors
Supplier approval The Supplier approval process includes review by the security team to evaluate the supplier's security profile and establish necessary security requirements. Suppliers who will require access to customer information are identified as data sub-processors. The current list of Sendoso data sub-processors is published at https://sendoso.com/data-sub-processor/ Customers will be notified by email when Sendoso makes periodic updates to this list. Data sub-processor contracts Security and data protection requirements for data sub-processors are maintained contractually, and consistent with requirements in Sendoso customer contracts. Where appropriate a DPA is included in the contract to detail these requirements. Where appropriate for cross-border transfer of data, GDPR standard contractual clauses as approved by EC on 04-Jun-2021 are included. Supplier Risk Management program Sendoso operates a Supplier Risk Management (SRM) program aligned to AICPA SOC 2 requirements. In this program, we periodically review the performance of suppliers to verify they maintain the relevant certifications \[SOC 1, SOC 2, ISO 27001:2013, PCI-DSS, etc.\] and specific security requirements of their contract with Sendoso. As part of the SRM program, every current data sub-processor is reviewed annually, as well as a selected group of other suppliers. Results of SRM program reviews are reflected in Sendoso's annual SOC2 Type II report.
Monitoring, Logging, & Incident Response
Network protection and monitoring Sendoso applies many tools and process controls to ensure protection of the solution & customer data. These include: \- Configuration & Hardening: All network components are built using 'golden' images, based on configuration & hardening standards defined in the Sendoso Operations Security policy, which includes AWS Compliance Best Practices. \- IDS/IPS: network-based and host-based Intrusion Detection (IDS)/Intrusion Prevention (IPS) systems are used to detect anomalous and/or malicious traffic on our networks and systems. \- Firewall infrastructure: next-generation firewalls and/ or ACLs are utilized to restrict access to systems from external networks and between systems internally. By default, all access is denied and only explicitly allowed ports and protocols are permitted based on business need. Sendoso uses the AWS WAFv2 web application firewall. \- DDoS mitigation: the infrastructure incorporates multiple DDoS mitigation techniques in addition to maintaining multiple backbone connections. We work closely with our providers to quickly respond to events and enable advanced DDoS mitigation controls when needed. Log content & retention Sendoso collects comprehensive system and event records in system logs, and analyzes these logs continuously to ensure solution performance and security. Log data includes but is not limited to access, delete, change, event, and alert logs, as well as security events such as successful and failed authentication events, access control failures, deserialization failures, and input validation failures. Sendoso logs do not include any customer personal information. System logs are held in both Data Dog and AWS GuardDuty environments. All security-related system logs are retained for a minimum of 12 months. Event handling & response All system logs and monitoring data are forwarded to our Managed Security Services Provider (MSSP), who perform live 24x7x365 data correlation, alerting, and event…
Access Management
Access controls for Sendoso company resources Access to corporate resources requires a corporate ID/password plus MFA. Corporate network user accounts are provided on a named-user basis, managed through the corporate Okta IAM platform. Sharing of passwords is prohibited by company policy as enforced by company training and the company disciplinary policy. All employees are provisioned OnePassword password vaults to ensure keys are kept confidential. Password complexity rules include 12-character PW length and special character requirements. User passwords for corporate resources must be reset after 90 days. On password reset, use of past 3 passwords is prohibited. 5 unsuccessful login attempts triggers a 15-minute user lockout period. Approving and implementing access changes Access privileges are controlled centrally by the Corporate IT function, and are assigned based on management-approved role-based access profiles to meet requirements of least privilege and separation of duties. Access change requests must be manager-approved to ensure these requirements are maintained, and then are implemented by the IT function. Privileged access controls Privileged access controls include all the standard access controls noted above, with addition of VPN. Sendoso uses Twingate VPN solution. Privileged access is limited to specific engineering and customer support roles. User Access Reviews (UARs) on company systems UARs are performed semi-annually for all key corporate resources, and annually for supporting resources, using the Vanta compliance platform. Access removal for departing personnel When an employee or contractor exits Sendoso, access removal is driven by HR and fully executed by IT within 24 hours. Customer Single Sign-On (SSO) to the Sending Management solution Sendoso supports SAML 2.0 or OIDC (OpenID Connect). Customers can manage their authentication and single-sign-on (SSO) options via Okta, OneLogin, Auth0, and other widely available service offerings. More…
Application Security
Sendoso's secure SDLC process The Sendoso Sending solution is developed using a secure SDLC encompassing design, code review, testing, change management, and release management activities. \- Design: Specific security-by-design and privacy-by-design principles are defined, implemented and included in review processes. Developers undergo annual training in these secure development principles, and receive ongoing guidance and resources pertaining to coding best practices, such as prevention of common web application attacks and code vulnerabilities. \- Code Review: Manual/peer code review is done before deployment with 100% of the developed code is covered in the review process. \- Testing: We use Aikido Security for development stage vulnerability testing, with code scanned by developers at code repository check-in. Identified vulnerabilities are prioritized and remediated according to risk severity. Applications are reviewed and tested both pre- and post-deployment to ensure that there is no adverse impact on organizational operations or security. \- Change Management: Changes to systems within the development lifecycle are managed with formal change control procedures. Significant code changes are reviewed and approved by management prior to production deployment. \- Release Management: Release Checklist must be completed which includes a checklist of all Test Plans which show the completion of all associated tests and remediation of identified issues. Change control procedures include separation of duties between development and deployment tasks. The Chrome browser extension The Chrome browser extension is developed and maintained by Sendoso. All aspects of the solution follow the Sendoso secure SDLC process, including the browser extension. Development environments & test data Sendoso protects all system environments, ensuring production, test/staging and development efforts are logically or physically separated. Customer data is not used for testing purposes…