Agencies manage sensitive client data through Senly. That's why security isn't a feature we add later — it's built into the foundation of the platform.
All data is stored encrypted (AES-256-GCM) and transmitted over TLS 1.3. Social-media cookies get per-tenant scoped keys.
Every agency has its own tenant scope at the database level. Cross-tenant reads are architecturally impossible, not just by access rules.
Fully GDPR-compliant: a data processing agreement per agency, sub-processors within the EU, data-rights workflows in-product (export, delete, access).
Granular roles per team member, an audit log of every critical action (SyncLog), JWT sessions with a 30-day lifetime and automatic rotation.
Login attempts, API routes and public endpoints are rate-limited. Brute-force, scraping and DoS attempts are stopped automatically.
Security researchers can report vulnerabilities directly via security@senly.io. We confirm within 24 hours and patch critical issues within 72 hours.
EU regulation 2016/679
Modern transport security
At-rest encryption
Password hashing
2-year HTTP Strict Transport
Content Security Policy headers
The optional Chrome extension has access to social-media session cookies. That is sensitive stuff. How we keep it watertight:
In the event of a data breach that poses a risk to the individuals involved, we notify the agency in question within 24 hours of discovery. The agency is responsible for reporting to the Dutch Data Protection Authority within 72 hours, and we support with technical forensics and logs.
Found something? We appreciate responsible disclosure. Send details to security@senly.io — preferably PGP-encrypted with our key (available on request). We confirm within 24 hours and keep you posted on the fix.
Compliance questions, DPIA input, a security audit for enterprise clients? Book a call with our security team.