Security and privacy
People send you things they wouldn't post publicly.
A headshot, a home phone number, a bio. This page describes what the software actually does with them, and then says plainly what it does not do — including the certifications SendGather does not hold.
Files
Never public, never guessable
Everything a recipient uploads goes to private object storage. There is no public URL and no CDN path to guess. A request for a file is permission-checked first, and only then answered.
Links that expire in sixty seconds
An authorised request is answered with a redirect to a signed URL that stops working after one minute. Even a leaked link is stale almost immediately.
Two ways in, and the narrower one is the recipient's
An admin session reads files in its own organization. A recipient has no account, so they authorise with the same link that let them upload — and it opens their own submission only, nothing else in the organization.
We don't believe the browser about file types
An upload's declared content type is ignored. The bytes are inspected and the file is accepted or refused on what it actually is.
The answers themselves
Fields you mark sensitive are encrypted at rest
AES-256-GCM, with the values masked in the interface until an administrator deliberately reveals one — and that reveal is written to the audit log.
A sensitive answer is never read back to the link holder
A tokenized link arrives by email, and email is not a vault. So a recipient's own link will show that a sensitive file is saved, and will not hand the file back.
You can put a clock on them
An organization can set sensitive answers to be erased on a schedule of its choosing. Nothing else expires on its own — we would rather describe what happens than promise a deletion the software does not yet perform.
Accounts and access
There is no password to steal
Coordinators sign in with a single-use link sent to their address. SendGather stores no passwords because it never asks for one.
Two-factor authentication
Any administrator can turn on TOTP — the standard authenticator-app second factor — with recovery codes.
Administrators see only what they are given
Access is per-administrator, and consequential changes — a new administrator, a change of owner, a deletion — are announced to the people they affect rather than happening quietly.
One organization cannot see another
Every query is scoped to an organization, and membership in that organization is verified before the query runs.
An audit log
Who revealed a sensitive answer, who exported what, who changed access — recorded and readable by the organization.
The people you ask
They have no account, and never will
Request recipients are not users. There is nothing for them to sign up for, no password to forget, and no profile of them being built.
Requests are not marketing, by design
A request asks people for something they are expecting. It is not a mailing list and the product refuses to become one — which is also what keeps delivery working for everyone else sending through it.
Anyone can stop one organization asking
A recipient who wants no more requests from an organization says so from their own link, and that organization stops asking them. It is recorded against that organization alone — it says nothing to any other organization here, and it outlives the request, the list they were imported from, and the address itself. A spam complaint to a mail provider is recorded the same way.
A dead address is retired, not re-sent to
When a provider tells us an address is permanently undeliverable, it stops being written to and the organization is shown that it failed rather than left to assume it arrived. Sending at an address that no longer exists is how a sender's reputation is spent, and everyone here shares one.
Export or erase one person
Everything one person has ever sent your organization can be exported, or erased, on their request — without touching anyone else's.
What we don't claim
Every item above is something the software does. These are the things it doesn't, listed here rather than left for you to discover.
No SOC 2, ISO 27001 or penetration-test report
None has been carried out. If your procurement process requires one, SendGather cannot clear it today and we would rather say so before a trial than during one.
Encryption at rest is not end-to-end encryption
Sensitive fields are encrypted with a key the service holds, which protects them at rest and in backups. It does not mean the operator is technically incapable of reading them.
Not for protected health information
There is no HIPAA business associate agreement and SendGather is not sold into clinical use. The sensitive-field machinery looks like it qualifies and does not.
No uptime guarantee
There is no service level agreement. The product is new and a number invented for a marketing page is not a commitment anyone should rely on.
United States only, for now
Sales are limited to US customers while the tax registrations for selling elsewhere are put in place. Nothing technical prevents it.
Who else touches the data
The full list. Each does one job.
- Neon
- the database
- Cloudflare R2
- uploaded files
- Vercel
- hosting and delivery
- Resend
- outgoing email, and what happens to it
- Stripe
- payments, and it never shows us a card number
Questions, or a security report
Write to legal@ropelabs.io. SendGather is operated by Rope Labs LLC, and the agreement is governed by the law of the State of Delaware, United States. See the privacy policy for the commitments themselves — this page describes mechanism.