Skip to content
WeZend
Trust & security

Security that survives an audit

No trust theatre. This page lists the concrete mechanisms protecting your data and your customers' data — each one a real feature you can verify in the product, not a promise in a slide deck.

Data protection

EU data residency by default

Customer data is processed and stored in the EU. The DPA and the public sub-processor list are published under legal — no NDA required to read them.

Encryption in transit and at rest

All traffic runs over TLS. Vendor credentials and channel secrets are encrypted at rest with a dedicated key, and passwords are stored as bcrypt hashes — never in any recoverable form.

GDPR tooling built in

Full data export as JSON, irreversible anonymisation across every module, automated retention policies and a GDPR audit log — one API call each, documented publicly.

Access control

Scoped roles, one login per human

Admin, Editor and Viewer roles enforce least privilege. Role changes apply on the next request; removing a member revokes their sessions immediately via session-epoch invalidation.

Two-factor authentication (TOTP)

Standards-based TOTP works with any authenticator app. Admins can require MFA account-wide — with it on, no member signs in without a second factor.

API keys that rotate safely

Key rotation issues the new key immediately while the old one keeps working for a 24-hour grace window — rotate on every offboarding without a deployment scramble.

Platform integrity

Signed webhooks

Every webhook carries an HMAC signature (X-WeZend-Signature) computed with your per-account secret, so your systems can prove a callback really came from us. Secrets rotate on demand.

Nothing fails silently

Failed messages land in a dead-letter queue for inspection and retry. Vendor health is monitored per destination with automatic failover. Every delivery has a plain-language timeline in the Delivery Inspector.

Audit trail on account changes

Role edits, key creation, pricing changes and GDPR actions are logged with actor and timestamp. When something changed and nobody remembers changing it, the answer is in the log.

Sending compliance

Consent enforced at send time

Per-channel consent, the suppression list, frequency caps and quiet hours are checked on every single send — campaign, journey or API call alike. No code path can accidentally message someone without a legal basis.

One-click unsubscribe & STOP handling

RFC 8058 one-click unsubscribe on every marketing email, STOP keywords intercepted and processed instantly on SMS — compliance events recorded with full history, not just a flag.

Responsible disclosure

Found a vulnerability? Write to security@wezend.com. We confirm receipt within one business day, keep you informed, and credit researchers who report responsibly.

The paperwork lives under legal: Data Processing Agreement · Sub-processor listGDPR API

One platform. Every customer interaction.

Replace your patchwork of messaging APIs, CDP and automation tools with a single engagement platform built for scale.

No credit card required · EU data residency · 99.99% uptime SLA