Security and compliance are foundational to everything we build. This page provides a transparent overview of our security architecture, compliance status, and data handling practices. We believe trust is earned through openness, not claims.
Our security posture spans infrastructure, application, and operational layers. Each layer is designed with defense-in-depth principles.
How we store, process, and manage your data. We are committed to minimizing data retention and maximizing your control over your information.
All data is hosted in the EU. We do not transfer data outside the EU unless explicitly configured by the tenant. All infrastructure services — database, cache, message bus and blob storage — reside in the same region.
Message content is processed only for the purpose of delivery. We do not analyze, mine, or use message content for any purpose other than routing to the configured provider. Message variables are resolved at delivery time and are not stored separately from the rendered message.
The following third-party services process data on behalf of OneSend2U:
Messaging-provider fees (Twilio, Meta, Infobip and others) are invoiced directly to you by the provider, under your own contract with them. OneSend2U charges only its platform fee.
We take security vulnerabilities seriously. If you have discovered a security issue in OneSend2U, we appreciate your help in disclosing it to us responsibly.
Please report security vulnerabilities to:
We will acknowledge your report within 48 hours and aim to provide a resolution timeline within 5 business days. We request that you do not publicly disclose the vulnerability until we have had an opportunity to address it.