Security overview
Last updated November 10, 2025Sagency International LLCabout 2 min readSee also: Trust centre, Data processing agreement, Subprocessors, Anti-Spam Policy, Delete or export your data
The technical controls protecting customer data, written for the person signing off.
What this covers
Principles, infrastructure, encryption, access controls, authentication, monitoring, backups, privacy, opt-outs, incident response and compliance posture, written for the person signing off.
1. Overview
Blue Reacher is a B2B iMessage platform operated by Sagency International LLC. It processes contact records, message content, reply history and delivery states on behalf of its customers.
Blue Reacher acts as processor, customers act as controller. This document describes the technical and organisational controls protecting customer data.
2. Security principles
- Least privilege
- Every person and system holds only required access, with no standing access to production data.
- Defence in depth
- Layered controls prevent single-point failures.
- Encryption everywhere
- Data encrypted in transit and at rest by default.
- Auditability
- All production access logged and retained.
- Transparency
- Posture published, including gaps.
3. Infrastructure and hosting
Blue Reacher runs on managed US cloud infrastructure. Every hosting provider is named on the published subprocessor list with purpose and region.
- Environment isolation
- Production, staging and development separated. Internal tooling not publicly exposed.
- Deployment
- Zero-downtime rollouts with automated rollback.
- Dependency hygiene
- Automated auditing for vulnerable packages. Code reviewed before production.
- Data residency
- US storage and processing. Standard Contractual Clauses cover EEA, UK and Switzerland transfers.
4. Encryption
TLS 1.3 in transit (fallback TLS 1.2), AES-256 at rest. Keys managed by cloud provider, never in application code.
API access uses per-customer bearer keys, rotatable anytime without contacting us.
5. Access controls
Role-based least-privilege access, limited to platform operators. No standing access. Privileges reviewed on a recurring schedule.
Workspaces logically isolated by account. Every data access logged.
6. Authentication
MFA required on all production accounts, no exemptions. Credentials never reused across environments.
Customer accounts use per-user credentials with MFA available. Single sign-on not offered today (genuine gap, not roadmap promise).
7. Monitoring and alerting
Continuous monitoring of infrastructure health, error rates and latency. Security events trigger automated alerts 24/7.
Logs retained 90+ days, reviewed on security events.
8. Data protection and backups
- Backups
- Automated regular backups with verified restore integrity.
- Tenant isolation
- Data logically isolated by account at the data layer.
- Deletion
- Completed within 30 days. Written certification available on request.
- Suppression records
- Do-not-contact entries survive record deletion by design.
9. Privacy commitments
Data processed solely to provide service. Never sold, shared between customers or used for public AI training.
Aggregated anonymized metrics used to improve reliability. Cannot identify a customer, contact or message.
10. Opt-out and sending safeguards
Automatic detection, immediate enforcement, permanent account-wide. Suppression cannot be overridden via API, all events logged.
Line health monitored continuously. Sending paced conversationally. Full rules in Anti-Spam Policy.
11. Incident response
Documented plan defining escalation, on-call responsibilities, containment, investigation and post-incident review.
Breach notification within 48 hours of discovery (GDPR Article 33 aligned). Notification includes nature, data categories, estimated records and remediation.
12. Compliance posture
Controls mapped to SOC 2 Trust Services Criteria for security, availability and confidentiality. Full control mapping and security questionnaire available on request.
Signed DPA published and in every contract. BAA available on Enterprise plans for HIPAA obligations. Card data never reaches Blue Reacher (Stripe SAQ-A category).
Monitoring obligations under GDPR, CCPA/CPRA and TCPA. Documents published, not badges.
13. Responsible disclosure
Email security@bluereacher.com or use /.well-known/security.txt. Coordinated disclosure welcome. Good-faith reporters credited.
Questions, questionnaire, control mapping or countersigned DPA: email security@bluereacher.com for same-week response. Summary at /trust.