Resend is SOC 2 Type II compliant.
We partner with third-party firms to conduct regular audits.
Get a concise, human-readable summary of this security page.
SOC 2 is an audit report developed by the American Institute of CPAs (AICPA).
The audit evaluates controls related to security, availability, processing integrity, confidentiality, and privacy of a system.
There are two types of SOC 2 reports:
Resend is SOC 2 Type II compliant.
SOC 2 is not mandatory in a legal sense, and certification isn't required by law.
Still, we believe that SOC 2 is crucial because it encourages companies to have solid controls in place to protect customer data.
For us, this isn't a short-term growth play but the beginning of a long-term security investment.
The auditing was done by Advantage Partners which has a track record of partnering with many SaaS companies.
Resend also uses Vanta to monitor, collect, and submit evidence to auditors.
The reporting period is from February 1, 2025 to February 1, 2026.
The SOC 2 Type II report, the annual penetration test Letter of Attestation, and the signed DPA are all on the Documents page (login required).
For GDPR, data transfers, and sub-processors, see the GDPR overview and the DPA.
Most questionnaire items are answered on the Security overview, the DPA, the subprocessors list, and the GDPR overview. If you still need a questionnaire filled, please contact us.