<\!DOCTYPE html> Security — Outbound
Security

Your data is
yours. Always.

We process your contact data on your behalf. You own it, you can export or delete it at any time, and we have specific obligations to protect it.

Encryption in transit

All data transmitted between your browser, our servers, and third-party integrations is encrypted using TLS 1.2 or higher. Older protocol versions are disabled.

Encryption at rest

All data stored in our PostgreSQL database is encrypted at rest using AES-256. Backups are encrypted using the same standard.

SOC 2 in progress

We are actively pursuing SOC 2 Type II certification, with a target completion date of Q2 2026. Controls, policies, and procedures are in place and being audited.

GDPR posture

We offer a Data Processing Agreement (DPA) on request for customers operating under GDPR jurisdiction. We support data subject requests: access, deletion, and portability.

Data residency

All customer data is stored in US-based infrastructure. We do not transfer data to jurisdictions outside the United States without customer consent and adequate safeguards.

You own your data

Your contact lists, sequences, and analytics belong to you. We are a data processor, not a data owner. You can export everything and delete it at any time from your dashboard.

Who processes
your data

We use the following third-party services to deliver the Outbound platform. Each has been evaluated for security and compliance.

Subprocessor
Purpose
Location
Neon (PostgreSQL)
Database storage
US
Render
Application hosting
US
OpenAI
AI email generation
US
Postmark / SendGrid
Email delivery
US
Stripe
Payment processing
US

What happens
if something goes wrong

We maintain a documented incident response plan. In the event of a confirmed data breach affecting customer data:

  • You'll be notified within 72 hours of our confirming the incident — in line with GDPR Article 33 timelines.
  • Notification will include: what data was affected, how it was exposed, what we've done to contain it, and what you should do next.
  • We will cooperate fully with any regulatory investigation.

For security questions, vulnerability reports, or DPA requests, email security@outbound-5.polsia.app.

Security questions?

Reach out directly. We'll send you our DPA and answer any compliance questions specific to your industry.

<\!-- Polsia Analytics -->