Encrypted by default
AES-256 at rest and TLS 1.3 in transit, with keys managed and rotated in a dedicated KMS.
Celentra runs outbound at scale on infrastructure built for teams under real controls: encryption everywhere, least-privilege access, independent audits, and the documentation your reviewers ask for on day one.
Every workspace runs against the same hardened baseline. Controls are monitored continuously and evidence is collected automatically, so audits reflect how the platform actually runs.
142 of 145 monitored controls are passing. The remaining three are scheduled access reviews, not open findings.
AES-256 at rest and TLS 1.3 in transit, with keys managed and rotated in a dedicated KMS.
Internal access is role-scoped, time-bound, approved in advance, and logged for review.
Every workspace is logically isolated, with authorisation checks enforced at the data layer.
Centralised logging, anomaly detection, and paged on-call coverage around the clock.
From identity to incident response, the pieces your security questionnaire asks about are already in place — and we will walk your reviewers through every one of them.
The package includes our SOC 2 report under NDA, penetration test summary, architecture overview, sub-processor list, and a completed CAIQ.
SAML single sign-on with your identity provider, plus automated provisioning and deprovisioning.
Immutable records of access, exports, and configuration changes, exportable to your SIEM.
Multi-zone hosting, encrypted backups tested by restore drills, and a documented recovery plan.
A practised runbook with 24-hour customer notification for confirmed incidents affecting your data.
Every sub-processor is risk-assessed before onboarding and reviewed at least once a year.
Choose where campaign data lives and keep regional sending policies enforced.
We complete questionnaires, sign DPAs, and join architecture calls with your security team — before you commit to anything.