Security and trust

SOC 2 Type 2. HIPAA-ready. Built for regulated verticals.

Healthcare networks, financial services brands, and franchise enterprises run on DirectMail.io. The security posture supports that reality: independently audited SOC 2 Type 2 infrastructure, BAA execution as part of standard onboarding for HIPAA-covered customers, CCPA/CPRA right-to-delete propagation across active campaigns, and the kind of audit logging and access scoping that enterprise procurement teams expect.

Certifications and compliance

Independently audited.

SOC 2 Type 2

Independently audited annually.

DirectMail.io maintains SOC 2 Type 2 certification covering security, availability, processing integrity, confidentiality, and privacy. The attestation report is available to enterprise customers and prospects under NDA.

HIPAA-ready with BAA

For covered entities and business associates.

For healthcare customers handling Protected Health Information (PHI), DirectMail.io supports execution of a Business Associate Agreement (BAA) as part of standard onboarding. Platform configuration includes PGP-encrypted ingest, scoped access controls, audit logging, and retention policies that align with HIPAA requirements.

CCPA / CPRA compliant

Right-to-delete propagation across active campaigns.

Consumer privacy requests propagate to active campaigns and underlying recipient lists. Per-record suppression flows through the platform, and identity-resolution audiences respect deletion requests across coordinated channels.

GDPR posture

Standard contractual clauses available.

For European customers, DirectMail.io supports standard contractual clauses (SCCs) and the data subject rights documented in our Privacy Policy. Data is processed in the United States; cross-border transfer mechanisms are in place where applicable.

Engineering practices

How the platform handles your data.

  • Encryption in transit and at rest

    All transfers use TLS 1.2+ in transit. Data at rest is encrypted using AES-256 across the platform infrastructure, including the SFTP layer and the database tier.

  • Per-account access scoping

    Account credentials and SFTP keypairs are scoped per account or per program. No credential is shared across accounts, and access logs are maintained for every authentication event.

  • Audit logging on every operation

    Every API call, dashboard action, and platform configuration change writes to an audit log with timestamp, calling key, and response payload. Audit logs are retained for the platform retention period and available for compliance review.

  • PGP-encrypted SFTP for sensitive ingest

    For healthcare, financial services, and other regulated verticals, the platform supports PGP-encrypted SFTP for list ingest. The platform manages keys per account and supports standard rotation cadence.

  • Subprocessor management

    A current list of subprocessors is maintained and made available to customers under NDA. Material changes to the subprocessor list are notified to customers in advance per the Master Services Agreement.

  • Incident response and breach notification

    In the event of a security incident affecting customer data, DirectMail.io notifies affected customers within 24 hours of becoming aware of the incident, per Section 3.10 of the Terms of Service. Coordinated investigation and remediation follow.

Privacy regulations 2026

CCPA, CPRA, and the January 2026 CPPA rules.

  • Annual cybersecurity audit

    DirectMail.io commissions an annual cybersecurity audit covering technical safeguards, breach response procedures, and vendor due diligence — required by the CPPA regulations effective January 1, 2026 for businesses processing sensitive personal information at scale. Audit reports are available to enterprise customers under NDA on request.

  • Risk assessments before high-risk processing

    Every new use case involving identity resolution, automated decision-making, or other high-risk processing receives a documented risk assessment before launch — naming the risks, the mitigations, and the legal basis for processing. Risk assessments are reviewed annually and on material changes to the use case.

  • Automated Decision-Making Technology (ADMT) disclosures

    Where DirectMail.io's platform automates decisions about consumers (eligibility, pricing, offers shown), pre-use notices and opt-out paths are provided per the CPPA's ADMT rules. The platform supports cross-session opt-out propagation: an opt-out registered anonymously persists when the same identity later authenticates.

  • Global Privacy Control (GPC) signals honored

    Browser-level GPC signals are recognized as a valid opt-out request across all DirectMail.io pixel and tracking products. Visitors sending GPC are excluded from identity resolution, retargeting feeds, and any "sharing" under CCPA's definition.

  • Data processor agreements (DPA) standard

    DirectMail.io operates as a data processor under signed DPA — not a third-party recipient. The legal posture matters for CIPA wiretap exposure, CCPA "sharing" classification, and downstream liability allocation. DPA execution is part of standard onboarding.

  • Right-to-know, right-to-delete, right-to-opt-out workflows

    Consumer rights requests under CCPA, CPRA, VCDPA (Virginia), CPA (Colorado), and similar state laws are processed within the regulatory deadlines — typically 45 days. Resolved identity records have an audit-tracked deletion workflow that propagates upstream and downstream of the platform.

Security FAQ

Questions enterprise security teams ask.

Short answers. For vendor security review packets, contact security@directmail.io.

  • Is DirectMail.io SOC 2 Type 2 certified?

    Yes. DirectMail.io maintains SOC 2 Type 2 certification, audited annually by an independent third-party auditor. The certification covers the security, availability, processing integrity, confidentiality, and privacy trust service criteria. The attestation report is available to enterprise customers and qualified prospects under a mutual non-disclosure agreement.

  • Does DirectMail.io support a Business Associate Agreement (BAA) for HIPAA?

    Yes. For healthcare customers handling Protected Health Information, DirectMail.io supports execution of a Business Associate Agreement as part of standard onboarding. The platform infrastructure, encryption practices, access controls, and audit logging are configured to align with HIPAA requirements. BAA execution typically completes during the contracting phase before production data ingest begins.

  • How can we get the SOC 2 attestation report?

    Contact us at security@directmail.io with your company name, the names and titles of the reviewers, and confirmation that you can execute a mutual NDA. The report is shared securely under NDA. The platform infrastructure team can also schedule a security review call to walk through specific controls relevant to your evaluation.

  • How is customer data segregated?

    Customer data is logically segregated at every layer of the platform. Account credentials, SFTP keypairs, dashboard access, API keys, and database queries all enforce per-account scoping. There is no shared-tenant data store; per-account isolation is the default posture, not an upgrade tier.

  • What happens to customer data on contract termination?

    Per Section 4.1 of the Terms of Service, customer data retains for 90 days after contract termination to support data retrieval requests. After the 90-day window, customer data is deleted from the platform. The retention period and deletion process are auditable through the platform logging layer.

  • How does DirectMail.io handle subprocessors?

    DirectMail.io maintains a current list of subprocessors used to deliver the platform services (cloud infrastructure, postal data partners, identity-resolution providers, payment processors). The list is made available to customers under NDA. Material changes to the subprocessor list are notified to customers in advance per the governing Master Services Agreement, with the option to object before the change takes effect.

  • How are vendor security reviews handled?

    For enterprise security reviews, DirectMail.io provides: (1) the SOC 2 Type 2 attestation report under NDA, (2) responses to standard security questionnaires (SIG, CAIQ, custom), (3) a security review call with the platform infrastructure team, (4) the subprocessors list, and (5) BAA, DPA, and SCC documentation as applicable. Most enterprise reviews complete within 2-3 weeks of intake.

Ready for security review?

Email security@directmail.io with your company, the reviewers, and an NDA-ready posture. We’ll send the SOC 2 report and schedule the security review call.