Trust · security & compliance

Built to be boring on risk

International outbound only works if legal and security can live with it. Here is how we handle personal information, deliverability, and control.

POPIA-ready infrastructure

Processing and hosting choices aligned with South Africa’s Protection of Personal Information Act, with clear operator/responsible-party roles in our agreements.

GDPR & CCPA handling

Lawful basis, suppression, access, and deletion are first-class. EU and California prospects are handled with the same operational discipline as the rest of the list.

Data processing agreement

DPA available on Growth and Enterprise. Subprocessors listed on request. We do not sell prospect data.

Deliverability & consent craft

Warmed domains, hard bounce budgets, and suppression against your CRM. Volume is capped before reputation is risked.

Security practices

Access limited to delivery systems, encrypted transit, and least-privilege CRM tokens. Enterprise can scope SSO and SOC2-path controls.

Kill-switch

Pause any segment or the whole fleet in one click. Human oversight is optional operationally, available instantly when you want it.

Enterprise

Need a DPA, subprocessors list, or security questionnaire? We respond on Growth and Enterprise timelines.

Contact security

Next step

Compliance should not slow the hunt.

Twenty minutes. We map your ICP, show a sample list, and tell you if we can fill the diary. No deck. No theatre.