SECURITY

Security your reviewers can sign off

Celentra runs outbound at scale on infrastructure built for teams under real controls: encryption everywhere, least-privilege access, independent audits, and the documentation your reviewers ask for on day one.

  • HubSpot
  • Salesforce
  • Pipedrive
  • Google Workspace
  • Microsoft 365
  • LinkedIn
  • Instantly
  • Zapier
  • Make
  • Slack
SOC 2 Type II audited
GDPR and UK GDPR ready
ISO 27001 aligned
AES-256 at rest, TLS 1.3 in transit
SECURITY POSTURE

Continuous control monitoring, not an annual snapshot

Every workspace runs against the same hardened baseline. Controls are monitored continuously and evidence is collected automatically, so audits reflect how the platform actually runs.

142 of 145 monitored controls are passing. The remaining three are scheduled access reviews, not open findings.

Control monitorsLive
  • Encryption at rest and in transitEnforced
  • MFA on all internal accountsEnforced
  • Dependency and image scanningClean
  • Access reviewsDue in 9 days
Automated scansLast 7 days

Encrypted by default

AES-256 at rest and TLS 1.3 in transit, with keys managed and rotated in a dedicated KMS.

Least privilege

Internal access is role-scoped, time-bound, approved in advance, and logged for review.

Tenant isolation

Every workspace is logically isolated, with authorisation checks enforced at the data layer.

Always watching

Centralised logging, anomaly detection, and paged on-call coverage around the clock.

SOC 2 Type IIIndependently audited annually
GDPR and CCPADPA and SCCs available
Penetration testedThird-party tests twice a year
Vetted teamBackground checks and annual training
SECURITY FAQ

What reviewers
ask us most

Yes. We share the full SOC 2 Type II report, along with our latest penetration test summary, under a mutual NDA. Ask your account team or use the contact form and we will send it over the same day.

THE PROGRAMME

Controls that hold up to enterprise review

From identity to incident response, the pieces your security questionnaire asks about are already in place — and we will walk your reviewers through every one of them.

The package includes our SOC 2 report under NDA, penetration test summary, architecture overview, sub-processor list, and a completed CAIQ.

SSO and SCIM

SAML single sign-on with your identity provider, plus automated provisioning and deprovisioning.

Audit log and retention

Immutable records of access, exports, and configuration changes, exportable to your SIEM.

Resilient infrastructure

Multi-zone hosting, encrypted backups tested by restore drills, and a documented recovery plan.

Incident response

A practised runbook with 24-hour customer notification for confirmed incidents affecting your data.

Vendor management

Every sub-processor is risk-assessed before onboarding and reviewed at least once a year.

Regional data residency

Choose where campaign data lives and keep regional sending policies enforced.

READY FOR REVIEW

Send us your security questionnaire

We complete questionnaires, sign DPAs, and join architecture calls with your security team — before you commit to anything.