Security overview

Last updated November 10, 2025Sagency International LLCabout 2 min readSee also: Trust centre, Data processing agreement, Subprocessors, Anti-Spam Policy, Delete or export your data

The technical controls protecting customer data, written for the person signing off.

What this covers

Principles, infrastructure, encryption, access controls, authentication, monitoring, backups, privacy, opt-outs, incident response and compliance posture, written for the person signing off.

1. Overview

Blue Reacher is a B2B iMessage platform operated by Sagency International LLC. It processes contact records, message content, reply history and delivery states on behalf of its customers.

Blue Reacher acts as processor, customers act as controller. This document describes the technical and organisational controls protecting customer data.

2. Security principles

Least privilege
Every person and system holds only required access, with no standing access to production data.
Defence in depth
Layered controls prevent single-point failures.
Encryption everywhere
Data encrypted in transit and at rest by default.
Auditability
All production access logged and retained.
Transparency
Posture published, including gaps.

3. Infrastructure and hosting

Blue Reacher runs on managed US cloud infrastructure. Every hosting provider is named on the published subprocessor list with purpose and region.

Environment isolation
Production, staging and development separated. Internal tooling not publicly exposed.
Deployment
Zero-downtime rollouts with automated rollback.
Dependency hygiene
Automated auditing for vulnerable packages. Code reviewed before production.
Data residency
US storage and processing. Standard Contractual Clauses cover EEA, UK and Switzerland transfers.

4. Encryption

TLS 1.3 in transit (fallback TLS 1.2), AES-256 at rest. Keys managed by cloud provider, never in application code.

API access uses per-customer bearer keys, rotatable anytime without contacting us.

5. Access controls

Role-based least-privilege access, limited to platform operators. No standing access. Privileges reviewed on a recurring schedule.

Workspaces logically isolated by account. Every data access logged.

6. Authentication

MFA required on all production accounts, no exemptions. Credentials never reused across environments.

Customer accounts use per-user credentials with MFA available. Single sign-on not offered today (genuine gap, not roadmap promise).

7. Monitoring and alerting

Continuous monitoring of infrastructure health, error rates and latency. Security events trigger automated alerts 24/7.

Logs retained 90+ days, reviewed on security events.

8. Data protection and backups

Backups
Automated regular backups with verified restore integrity.
Tenant isolation
Data logically isolated by account at the data layer.
Deletion
Completed within 30 days. Written certification available on request.
Suppression records
Do-not-contact entries survive record deletion by design.

9. Privacy commitments

Data processed solely to provide service. Never sold, shared between customers or used for public AI training.

Aggregated anonymized metrics used to improve reliability. Cannot identify a customer, contact or message.

10. Opt-out and sending safeguards

Automatic detection, immediate enforcement, permanent account-wide. Suppression cannot be overridden via API, all events logged.

Line health monitored continuously. Sending paced conversationally. Full rules in Anti-Spam Policy.

11. Incident response

Documented plan defining escalation, on-call responsibilities, containment, investigation and post-incident review.

Breach notification within 48 hours of discovery (GDPR Article 33 aligned). Notification includes nature, data categories, estimated records and remediation.

12. Compliance posture

Controls mapped to SOC 2 Trust Services Criteria for security, availability and confidentiality. Full control mapping and security questionnaire available on request.

Signed DPA published and in every contract. BAA available on Enterprise plans for HIPAA obligations. Card data never reaches Blue Reacher (Stripe SAQ-A category).

Monitoring obligations under GDPR, CCPA/CPRA and TCPA. Documents published, not badges.

13. Responsible disclosure

Email security@bluereacher.com or use /.well-known/security.txt. Coordinated disclosure welcome. Good-faith reporters credited.

Questions, questionnaire, control mapping or countersigned DPA: email security@bluereacher.com for same-week response. Summary at /trust.