Skip to content
Menu

Security and privacy

People send you things they wouldn't post publicly.

A headshot, a home phone number, a bio. This page describes what the software actually does with them, and then says plainly what it does not do — including the certifications SendGather does not hold.

Files

Never public, never guessable

Everything a recipient uploads goes to private object storage. There is no public URL and no CDN path to guess. A request for a file is permission-checked first, and only then answered.

Links that expire in sixty seconds

An authorised request is answered with a redirect to a signed URL that stops working after one minute. Even a leaked link is stale almost immediately.

Two ways in, and the narrower one is the recipient's

An admin session reads files in its own organization. A recipient has no account, so they authorise with the same link that let them upload — and it opens their own submission only, nothing else in the organization.

We don't believe the browser about file types

An upload's declared content type is ignored. The bytes are inspected and the file is accepted or refused on what it actually is.

The answers themselves

Fields you mark sensitive are encrypted at rest

AES-256-GCM, with the values masked in the interface until an administrator deliberately reveals one — and that reveal is written to the audit log.

A sensitive answer is never read back to the link holder

A tokenized link arrives by email, and email is not a vault. So a recipient's own link will show that a sensitive file is saved, and will not hand the file back.

You can put a clock on them

An organization can set sensitive answers to be erased on a schedule of its choosing. Nothing else expires on its own — we would rather describe what happens than promise a deletion the software does not yet perform.

Accounts and access

There is no password to steal

Coordinators sign in with a single-use link sent to their address. SendGather stores no passwords because it never asks for one.

Two-factor authentication

Any administrator can turn on TOTP — the standard authenticator-app second factor — with recovery codes.

Administrators see only what they are given

Access is per-administrator, and consequential changes — a new administrator, a change of owner, a deletion — are announced to the people they affect rather than happening quietly.

One organization cannot see another

Every query is scoped to an organization, and membership in that organization is verified before the query runs.

An audit log

Who revealed a sensitive answer, who exported what, who changed access — recorded and readable by the organization.

The people you ask

They have no account, and never will

Request recipients are not users. There is nothing for them to sign up for, no password to forget, and no profile of them being built.

Requests are not marketing, by design

A request asks people for something they are expecting. It is not a mailing list and the product refuses to become one — which is also what keeps delivery working for everyone else sending through it.

Anyone can stop one organization asking

A recipient who wants no more requests from an organization says so from their own link, and that organization stops asking them. It is recorded against that organization alone — it says nothing to any other organization here, and it outlives the request, the list they were imported from, and the address itself. A spam complaint to a mail provider is recorded the same way.

A dead address is retired, not re-sent to

When a provider tells us an address is permanently undeliverable, it stops being written to and the organization is shown that it failed rather than left to assume it arrived. Sending at an address that no longer exists is how a sender's reputation is spent, and everyone here shares one.

Export or erase one person

Everything one person has ever sent your organization can be exported, or erased, on their request — without touching anyone else's.

What we don't claim

Every item above is something the software does. These are the things it doesn't, listed here rather than left for you to discover.

No SOC 2, ISO 27001 or penetration-test report

None has been carried out. If your procurement process requires one, SendGather cannot clear it today and we would rather say so before a trial than during one.

Encryption at rest is not end-to-end encryption

Sensitive fields are encrypted with a key the service holds, which protects them at rest and in backups. It does not mean the operator is technically incapable of reading them.

Not for protected health information

There is no HIPAA business associate agreement and SendGather is not sold into clinical use. The sensitive-field machinery looks like it qualifies and does not.

No uptime guarantee

There is no service level agreement. The product is new and a number invented for a marketing page is not a commitment anyone should rely on.

United States only, for now

Sales are limited to US customers while the tax registrations for selling elsewhere are put in place. Nothing technical prevents it.

Who else touches the data

The full list. Each does one job.

Neon
the database
Cloudflare R2
uploaded files
Vercel
hosting and delivery
Resend
outgoing email, and what happens to it
Stripe
payments, and it never shows us a card number

Questions, or a security report

Write to legal@ropelabs.io. SendGather is operated by Rope Labs LLC, and the agreement is governed by the law of the State of Delaware, United States. See the privacy policy for the commitments themselves — this page describes mechanism.