Security at a glance
Cendaro uses role-aware access control, protected infrastructure, audit logging, privacy-operation safeguards, consent-aware messaging rules, restore-review workflows, and incident-response practices to help customers operate safely.
1. Access control and account security
Cendaro separates access by workspace, user role, and admin surface. Protected routes enforce role-aware access, admin surfaces are scoped separately from business workspaces, and privileged operations are designed to require explicit authorization rather than relying on hidden UI alone.
2. Hosting, secrets, and infrastructure
Cendaro runs on managed infrastructure that uses environment-scoped secrets, provider-backed authentication and storage, and deployment separation between public routes, app routes, and internal operations. Production secrets should remain protected and never be shipped into public client bundles.
3. Messaging, consent, and customer safeguards
Cendaro applies customer-communication guardrails such as consent-aware message checks, STOP and unsubscribe handling, blocked-send evidence, and audit trails for operator actions. The product is designed to reduce accidental marketing misuse and unsafe outbound communications.
4. Privacy and destructive-action controls
Privacy workflows include request intake, status lookup, secure export delivery, delete preview, destructive approval, destructive execution, legal retention signoff, and restore-readiness review. Sensitive destructive actions are gated so operators cannot silently bypass review or evidence requirements.
5. Auditability and operational evidence
Cendaro records operational events for core workflows such as legal acceptance, messaging, consent changes, privacy actions, and admin review steps. Auditability is treated as part of the product safety model because customer communications, approval flows, and destructive actions require clear evidence trails.
6. Backup, restore, and retention review
Launch-readiness work includes documented restore and retention checks, privacy retention signoff records, and operational readiness review before sensitive cleanup or redaction actions proceed. This helps reduce the risk of unsafe deletion behavior or undocumented production maintenance changes.
7. Incident response
Cendaro maintains an incident-response process that includes triage, evidence preservation, provider review, customer or regulator notification where required, and follow-up through internal compliance or admin workflows. Incident readiness is also reflected in Admin HQ registers and launch review gates.
Contact
For security questions, incident coordination, or customer trust reviews, contact Cendaro's privacy contact.