Skip to content
Start with 100 free verification credits
Qualisend
Trust

Security & trust.

You hand a verification service real people's addresses, so how we handle them matters. Here is our security posture in plain terms — where your data lives, how we protect it, and the controls you keep over it.

Standards we build to

AICPA SOC 2

SOC 2

Our security program is built around the SOC 2 trust principles for security, availability, and confidentiality.

GDPR compliant

GDPR

As an EU-based company, we build to the GDPR — lawful processing, data-subject rights, and EU data residency by default.

HIPAA compliant

HIPAA

Our practices are designed to support HIPAA obligations for teams that handle protected health information.

Need our latest reports, a Data Processing Agreement (DPA), or a Business Associate Agreement (BAA)? Get in touch and we'll share what applies to your use case.

How we protect your data

EU data residency

Qualisend is an EU-based company, and the data you send us is stored and processed in the EU. Nothing has to leave the EEA to be verified, which removes the international-transfer question for European senders.

Encryption & access controls

We apply technical and organizational safeguards — encryption, least-privilege access controls, and regular security assessments — to protect your account and the lists you verify.

Scoped API keys

Verify over the API with scoped, revocable keys so each integration gets only the access it needs, and you can rotate or revoke a key without touching the rest of your setup.

Your data, your control

Verification jobs and results live in your workspace and you can delete them at any time. We never sell, rent, or share the email lists you submit — and we don't use them to train models or enrich anyone else's results.

Data retention

We keep data only as long as there's a reason to. The full schedule is in the privacy policy; in short:

  • Verification jobs and results — kept in your workspace until you delete them or close your account.
  • Account data — retained while your account is open, then removed 30 days after closure.
  • Usage logs — kept 90 days for security and analytics.
  • Billing records — retained to meet tax and accounting law.

Sub-processors & your rights

We rely on a small set of vetted providers — for payments, hosting, and analytics — to run the service, and we don't sell your personal information or the lists you verify. Under the GDPR and CCPA you can access, correct, export, or delete your data and withdraw consent at any time; email hello@qualisend.com to exercise those rights. Qualisend is operated by Longterm studio, MB, registered in Lithuania (EU).

The fine print

Questions about security or compliance?

We're happy to walk through our practices, sign a DPA, or answer a security questionnaire — just reach out.

Start verifying