Ready for your security review.
Letterhead runs newsletter portfolios inside large media and enterprise companies, so we've been through the enterprise vendor review more than once. The controls below are already in place. Send us the questionnaire, or ask for the security pack.
What's covered
The questions your security team will ask.
SSO & SAML
Single sign-on over SAML, with role-based access scoped to workspaces. The controls procurement asks for.
SOC 2
Security, availability, and confidentiality controls, documented and audited. Procurement-ready security pack on request.
GDPR & privacy compliance
GDPR and CCPA built in: access, deletion, and export requests handled on time. Audience data stays yours — never sold, never used to train models.
Enterprise-ready API
A documented, versioned API across the whole platform — newsletters, audience, sends, and reporting — built for production integrations.
S3 & data sync
Scheduled exports of audience and engagement data to your S3 bucket or warehouse. Your data, in your stack, on your cadence.
Audit logs
An exportable trail of who changed what, when — across every newsletter and workspace.
Bring your security questions.
Fifteen minutes with the team that runs the platform. Ask about data handling, access control, or whatever procurement flagged.