Security & privacy

Built to be trusted by both sides of the message.

Your records need to be secure, and your recipients deserve honesty. Here's how SentLedger handles both.

Tenant isolation

Every record belongs to one workspace. Row-level security in the database blocks cross-workspace reads even if application code were wrong.

Encryption

TLS in transit, encryption at rest, and AES-256-GCM for OAuth tokens and webhook secrets, with keys held only in the server environment.

Hashed secrets

API keys are shown once and stored only as SHA-256 hashes. Webhooks are signed with HMAC-SHA256 and a timestamp.

Append-only ledger

Events can't be edited or deleted by the application; each is chained to the previous event's hash.

Least privilege

Five roles, scoped API keys, send-only inbox permissions, and a full audit log of sensitive actions.

Private files

Files live in private storage and are served only through short-lived signed links after an access check.

Tracking limitations

What tracking can't tell you.

We'd rather you understand these limits than overstate what a record shows.

Image blocking

Many mail apps don't load images until the reader allows it. Real opens can go unrecorded.

Privacy proxies

Apple Mail Privacy Protection and Gmail's image proxy can load images automatically. We flag these as uncertain.

Security scanners

Corporate email security can click links to check them. Very fast clicks and known scanners are flagged.

Forwarding

If a message is forwarded, opens and clicks may come from someone other than the original recipient.

Location

We store a truncated network prefix only. SentLedger does not identify people or precise locations from IP addresses.

Connected inboxes

Gmail and Microsoft 365 don't report delivery or bounces to us; those arrive in your own mailbox instead.

Recipient privacy

  • Workspaces can require a visible tracking notice on every message
  • Unsubscribe links and one-click List-Unsubscribe for multi-recipient sends
  • Bounces, complaints and unsubscribes are suppressed automatically
  • Full IP addresses are never stored with tracking events
  • Retention limits remove old records automatically

Found a vulnerability? Email security@sentledger.com. Received a message you believe is abusive? Report it here.

Keep a record you can stand behind.

Start with the web app today and bring in the API when you're ready. No card required for the trial.

Start free trialTalk to sales