Sendoso · Trust Center

Sendoso Trust Center

Trust center

Sendoso runs a Vanta-hosted Trust Center at security.sendoso.com. It answers HTTP 200, but it is a client-rendered single-page application: the 5.7 KB HTML the server actually delivers contains the title "Sendoso Trust Center" and nothing else — no certification name, no control, no document list. Certifications are therefore NOT recorded here, because none were readable. That is a measurement of the surface, not a claim about Sendoso's compliance posture.

Sendoso maintains a public trust center covering its security and compliance posture.

Corporate GiftingDirect MailSales EngagementMarketing AutomationCRM IntegrationeGiftsSwag and MerchandiseFulfillmentEmployee RecognitionAccount Based MarketingSCIM ProvisioningWebhook
Trust center:

Certifications & Compliance

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: probed
source: https://security.sendoso.com/
provider: Sendoso
providerId: sendoso
description: >-
  Sendoso runs a Vanta-hosted Trust Center at security.sendoso.com. It answers HTTP 200, but
  it is a client-rendered single-page application: the 5.7 KB HTML the server actually
  delivers contains the title "Sendoso Trust Center" and nothing else — no certification
  name, no control, no document list. Certifications are therefore NOT recorded here, because
  none were readable. That is a measurement of the surface, not a claim about Sendoso's
  compliance posture.
trust_center:
  url: https://security.sendoso.com/
  http_status: 200
  platform: Vanta
  platform_evidence: >-
    Page assets load exclusively from assets.vanta.com (index-trust-report bundle), and the
    page links a Vanta document viewer at https://app.vanta.com/doc?s=wj3tcv6rtc7222p39ikj9.
  discovered_via: https://www.sendoso.com/security (302 to security.sendoso.com)
  machine_readable: false
  machine_readable_note: >-
    Probed for a machine-readable trust report at /api/trust-center, /api/trust-report,
    app.vanta.com/api/trust-report/sendoso and app.vanta.com/api/trust/sendoso — all returned
    the SPA HTML shell rather than data.
certifications: []
certifications_note: >-
  None readable. Do not emit a Compliance pointer from this file; a trust center whose
  contents cannot be read is not published evidence of a named certification.
compliance_signals_found_elsewhere:
  - signal: CCPA
    where: https://www.sendoso.com/ and https://www.sendoso.com/compare-plans (footer link)
    note: A privacy-rights link, not a certification.
  - signal: Anti-Bribery Controls
    where: https://www.sendoso.com/compare-plans
    note: Sold as an Enterprise-tier feature row, not stated as an external attestation.
  - signal: Advanced Audit Services
    where: https://www.sendoso.com/compare-plans
    note: Enterprise-tier feature row.
security_claims_in_docs:
  - claim: Data encrypted at rest with AES-256.
    source: https://developer.sendoso.com/rest-api/overview/security
  - claim: Data in transit over HTTPS TLS 1.2 with RSA 256-bit.
    source: https://developer.sendoso.com/rest-api/overview/security
    observed: TLSv1.3 negotiated on all three hosts (probed 2026-08-13).
  - claim: >-
      All API requests are logged (IP, method, resource, response status) and monitored for
      suspicious activity.
    source: https://developer.sendoso.com/rest-api/overview/security
enterprise_controls_published:
  source: https://www.sendoso.com/compare-plans
  controls:
    - Single Sign-On (SSO) — Core tier and above
    - SCIM user management — Enterprise tier
    - IP allow listing — Enterprise tier
    - Admin audit log — Enterprise tier
    - Policy Center — Enterprise tier
    - Advanced IT controls — Enterprise tier
recommendation_for_provider: >-
  The Vanta trust center is invisible to every automated reader, including the AI agents
  Sendoso is otherwise courting with an MCP server and an agent skill. Serving the
  certification list as static HTML, or exposing Vanta's public trust-report JSON, would make
  a real compliance program legible without changing what is disclosed.