SOC2C

Is this your company? Buyers are checking Sendoso here. Claim sendoso.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Sendoso logo

Sendoso

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Sendoso is SOC 2 Type II compliant. Sendoso also holds GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Founded in 2016, Sender, Inc. dba Sendoso (“Sendoso”) is the world’s first Sending Platform. Our fully-integrated solution solves sourcing, physical warehouse storage, inventory tracking, and ROI attribution problems so that businesses can send anything and personalize at scale. This enables our customers to see increased conversion rates, revenue, retention, and ROI. Sendoso is headquartered in Phoenix, Arizona, and currently services over 700 customer organizations.

Compliance & infrastructure

Data handled
Customer personally identifiable informationEmployee personally identifiable information

Documents

9

Subprocessors

1
  • (
    (Published Separately)

Compliance leadership

The person who leads Sendoso's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Sendoso's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Sendoso 2026 SOC 2 Type 2 ReportJun 2026

Sendoso SOC 2 Type 2 Report for Trust Services Criteria of Security, Availability, and Confidentiality. Issued by Barr Advisory, P.A. on 15-Jun-2026.

Oso and SmartSuite FAQ UpdateApr 2026

Updated the FAQ section with information on the launch of Oso, Sendoso's AI Agent, as well as improvements to the SmartSuite feature set.

Sendoso's 2025 Penetration Test External Assessment SummaryJul 2025

Published results of Sendoso's recent 2025 Penetration Test and External Assessment, executed by our third-party test partner NCC Inc.

2025 SOC2 and SOC3 ReportsJun 2025

Sendoso's 2025 SOC 2 Type 2 and SOC 3 Reports have now been posted to the Trust Center

Policy DocumentsDec 2024

All policy documents are updated and reposted for Year 2025

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Sendoso SOC 2 compliant?
Sendoso is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Sendoso GDPR compliant?
According to Sendoso's public trust center, Sendoso is GDPR compliant. On SOC2C this listing is Listed.
Is Sendoso CCPA compliant?
According to Sendoso's public trust center, Sendoso is CCPA compliant. On SOC2C this listing is Listed.
Is Sendoso SOC 2 Type I or Type II?
Sendoso is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Sendoso's SOC 2 for a vendor risk assessment?
Yes. Sendoso's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Sendoso

Reproduced from Sendoso's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Business Information
Service Description Sendoso provides a comprehensive "sending platform" that enables customers to send direct mail and gifts to their clients, partners, employees, and other chosen recipients. The platform is a fully integrated solution that can be accessed through a customer's existing technology stack or via the Sendoso app/Chrome extension. It addresses challenges such as sourcing, physical warehouse storage, inventory tracking, and return on investment (ROI) attribution. This allows businesses to send personalized items at scale and track conversion rates, revenue, retention, and ROI. Sendoso also offers warehousing and distribution services for customer inventory, manages budgets within the platform, and automates sending campaigns. The platform integrates with various customer technology solutions, such as Salesforce and Marketo, to facilitate seamless operations. Business Location and Incorporation The address for Sendoso corporate headquarters is 655 Montgomery St., Suite 1500, San Francisco, CA 94111, United States. California is the company's primary place of business. Under Sendoso's standard contract terms, California law governs between Sendoso and its customers. Sendoso is legally incorporated in the state of Delaware. Location of the Sending Management solution environment The Sendoso solution environment, including all customer data processing & storage, is located entirely within the United States. Production services are hosted at AWS-West-2 (Oregon) with secondary services at AWS-East-1 (Virginia). Sendoso provides service to all customers globally through this solution environment. Tax ID Sendoso's Tax ID is 81-106-3656 DUNS number Sendoso's DUNS number is 095361229 How to report a security/privacy concern or obtain help with security/privacy questions The following mail addresses are available to any Sendoso customer or supplier: security@sendoso.com: for anyone reporting a security concern, or making a general inquiry on a security topic…
SmartSuite and the Oso AI Agent: Features based on GenAI & LLM
Sendoso's Current Use of Generative AI & LLM We provide GenAI/LLM-based capabilities to our customers, branded as Oso, Sendoso’s AI Agent, and the SmartSuite feature set. Oso and SmartSuite are a part of our ongoing commitment to improve the business value of the Sendoso platform for our customers, as well as the Sending experience of our platform users. These features are based on the OpenAI platform and also apply natural language processing. Oso and SmartSuite features currently include: *Oso:* Sendoso's AI Agent. Oso converts natural language requests into: - Real-time data and analytic reports using Sendoso's data through authorized integrations - Intelligent gift recommendations and human-in-the-loop gift sending. *SmartSend:* Provides personalized gift recommendations based on information you supply and other publicly-sourced information. - Combined with Gong Integration: Provides personalized gift recommendations based on data sourced from Gong call transcripts *SmartMessage:* Generates personalized notes to accompany gifts. *SmartDelivery:* Enables sending gifts using externally-sourced address information. The SmartSend Data Flow SmartSend offers gift suggestions based on information that you provide through the SmartSend chat window. SmartSend will supplement this information with externally-sourced and public information to better personalize the gift suggestions it makes. For customers with CRM (e.g., Salesforce) integration to Sendoso, SmartSend also performs a real-time lookup when a SmartSend request is made; if relevant information (specifically related to gift personalization) is identified, it may be used to further inform the gift recommendation. Gift recommendations are returned directly to the user and not retained by Sendoso. Meeting & Transcript Processing Data Flow Sendoso stores reference IDs to meetings (e.g., Gong calls) along with participant information. When a SmartSend request is triggered (such as an email match to a meeting…
Security & Privacy Certifications
SOC2 Type II Report Sendoso generates an annual SOC 2 Type II Report covering the AICPA domains of Security, Availability, and Confidentiality, which can be found on the Sendoso Trust Center. PCI Report on Compliance Sendoso files a Self-Attestation Questionnaire reflecting our use of Stripe Inc. as processor of all payment card activity. Our current filing is for PCI DSS v4.0 using form SAQ-A. Stripe Inc. generates a PCI ROC as a Service Provider, also using PCI DSS v4.0. The Attestation of Compliance (AOC) for both filings can be found on the Sendoso Trust Center. ISO 27001 Certification Sendoso is not ISO-27001 certified at this time. GDPR & CCPA Compliance Sendoso is fully compliant with all aspects of GDPR and CCPA data privacy legislation for the geographies in which they are applicable. Note that no formal external certification is currently required for these privacy regulations.
Sendoso Organization and Training
Security & Privacy awareness training All personnel are required to complete annual security awareness training, which includes topics covering customer data privacy and confidentiality. Training is provided upon hire, and at least once per year thereafter. A summary of the topics covered in training is found in the Resources section of the Trust Center. Employees receive continuing education through online industry-related training and periodic industry conferences on an as-needed basis. Training certification is registered automatically by the company training platform upon successful completion of the training. Training records are audited annually as part of SOC 2 compliance review." Compliance training All employees receive compliance training annually and annually thereafter. This includes training in anti-harassment and anti-bribery as defined in the Sendoso Code of Conduct. Personnel background checks Background verification checks are coordinate by Sendoso HR and executed by an external service partner. Background checks include following components, to the extent allowed by regulations in the hiring jurisdiction: Federal criminal search (10 yrs), county criminal search (7 yrs), national criminal search, employment verification, sex offender registry search, and identity/SSN trace. In all cases, all findings resolved to the satisfaction of Sendoso HR before new personnel are provided access to systems or locations containing customer information. All third parties with technical privileged or administrative access to sendoso.com production systems or networks are subject to a background check or requirement to provide evidence of an acceptable background check. Onboard & offboard processes Onboard and offboard processes are coordinated by the HR department through the Jira work management system. New personnel are required to sign a confidentiality agreement, and are provided access to customer data only after fully clearing the third-party background…
Solution Architecture
Sending Management Platform solution architecture A general overview of the solution architecture is provided in the Sendoso Trust Center. If you have specific architecture questions we are happy to respond to these directly; please contact your Account Manager or send your question directly to security@sendoso.com.

Business & Industrial peers that completed SOC 2