01Start with the Evidence.
SOC 2 Type II
Independent examination against the Security trust services criteria. Audit period August 4 to November 3, 2025. Report issued May 7, 2026 by Johanson Group. Clean opinion, no exceptions noted.
- Penetration TestingA 2026 penetration test is listed on the trust center. Results are available for your evaluation on request.Available
- GDPRProcessor Data Processing Addendum incorporating the 2021 EU Standard Contractual Clauses, an Article 30 processing register and annual risk assessments.In Place
- Cyber InsuranceCybersecurity insurance maintained.In Place
- Trust CenterThe live control list, subprocessor list and documents sit at trust.sellence.com. Reviewers request access there.Public
02Clear Facts. Defined Controls.
Breach notification within 48 hours under the Data Processing Addendum.
03The Model and Its Providers.
Identifiers Never Reach a Model
Direct identifiers, meaning names, phone numbers and contact details, are replaced by tokens before anything reaches a reasoning model. A residue guard blocks any outgoing message that still carries a masking token. This is pseudonymization. We do not describe it as anonymization.
Model-Provider Controls
We review model-provider security attestations as part of vendor management. Ask for the security pack to review provider terms and data use for your deployment. Inference can be pinned to a single region and the cross-vendor fallback disabled if you require one provider.
Subprocessors
| Provider | Role | Region |
|---|---|---|
| Amazon Web Services | Hosting and storage | Frankfurt, Germany |
| OpenAI | Model inference | USA |
| Google Gemini | Model inference | USA |
| Anthropic | Model inference | USA |
| Twilio | SMS delivery | Your account |
| Meta Cloud API | WhatsApp delivery | Your account |
| Cloudflare | Edge and network | Global |
The current list is published on the trust center. You may object to a new subprocessor within the notice period set in the Data Processing Addendum.
04TCPA, Consent and Opt-Outs.
US texting is governed by the TCPA, state law and the carriers. The program below is how Sellence keeps every message inside those rules.
- Consent Stays with YouSellence messages only the contacts you supply, with their consent status. No purchased or generated lists. During onboarding we help you build the opt-in form with the required disclosure language, at no cost.Standard
- Opt-Out Is Instant, and It SticksSTOP, QUIT, UNSUBSCRIBE, CANCEL, END and other clear requests are honored on the spot and suppressed across every campaign and channel. They are written back to your system of record and never reversed without a new explicit opt-in. You receive a daily opt-out digest.Standard
- Quiet HoursSend windows are enforced in the recipient's local time, measured by area code.Standard
- Registered TrafficBrand and campaign are registered with The Campaign Registry under the A2P 10DLC standard. Your brand name appears in every message.Standard
- Audit TrailEvery opt-out is timestamped and logged. Consent status is on file for each contact.Standard
- Outside CounselSellence works with outside counsel on the SMS compliance program. Compliance questions go to compliance@sellence.com.Retained
This page describes how Sellence approaches messaging compliance. It is informational and is not legal advice. Each brand remains responsible for obtaining and maintaining valid consent, and should consult its own counsel before launching a messaging program.
05Privacy and Data Rights.
| Retention | Conversation history is kept for the life of the contract. The model's per-turn history window is a configurable setting. Retention and deletion follow the Data Processing Addendum. |
| Erasure | Per-contact erasure is supported during the term. At termination, all personal data processed on your behalf is deleted or returned, unless the law requires retention. |
| Data Subject Requests | Sellence assists you and forwards any request it receives directly. It never answers a data subject on its own. |
| CCPA | Under the Data Processing Addendum, Sellence acts as a service provider: no sale or sharing of personal data, no retention, use or disclosure outside the services, and no combining with data from other sources. |
| Website Visitors | Covered by the Privacy Policy. Service data is governed by the Data Processing Addendum, available on request. |
06What We Hold. What We Do Not.
Certifications we hold, and the ones we do not yet hold, in one place.
- SOC 2 Type IISecurity criteria. Report issued May 7, 2026, no exceptions.Held
- Penetration Test 2026Listed on the trust center.Done
- GDPR Processor DPA2021 EU Standard Contractual Clauses, Article 30 register, annual risk assessments.In Place
- HIPAAPolicies signed in July 2026 and a HIPAA program is underway. We do not claim HIPAA compliance until it is complete.In Progress
- ISO 27001Sellence does not hold ISO 27001. The cloud and model providers we rely on hold their own SOC 2 or ISO 27001 attestations, reviewed in vendor management.Not Held
07Questions Reviewers Ask.
Does Sellence have a SOC 2 report?
Yes. Sellence holds a SOC 2 Type II report against the Security trust services criteria. The audit period ran from August 4 to November 3, 2025. The report was issued on May 7, 2026 by Johanson Group, with no exceptions noted. The full report is available under NDA through trust.sellence.com. A SOC 3 summary is public.
Can our compliance team export the audit trail for a regulator or a sponsor bank?
Yes. Every message, consent record and opt-out is timestamped and logged. The audit trail exports for a market conduct exam, an FCA review or a sponsor bank audit.
Where is our data stored?
All data at rest sits in AWS eu-central-1 (Frankfurt, Germany), encrypted in transit and at rest. Model inference can be pinned to a single region and the cross-vendor fallback disabled if you require one provider.
How is customer data handled by the model?
Direct identifiers such as names, phone numbers and contact details are replaced by tokens before they reach a reasoning model. A residue guard blocks outgoing messages that still carry a masking token. This is pseudonymization. Request the security pack to review model-provider terms and data use for your deployment.
Who owns SMS consent, and what happens when someone texts STOP?
Consent stays with you. Sellence messages only the contacts you supply, with their consent status, and never purchased or generated lists. STOP, QUIT, UNSUBSCRIBE, CANCEL, END and other clear requests are honored on the spot and suppressed across every campaign. They are written back to your system of record and never reversed without a new explicit opt-in. Every opt-out is timestamped and logged.
What happens to our data when the contract ends?
At termination, all personal data processed on your behalf is deleted or returned, unless the law requires retention. During the term, per-contact erasure is supported and data subject requests are forwarded to you and assisted; Sellence never answers a data subject on its own.
Is Sellence HIPAA or ISO 27001 certified?
Not yet. HIPAA policies were signed in July 2026 and a HIPAA program is in progress; Sellence does not claim HIPAA compliance until it is complete. Sellence does not hold ISO 27001. The cloud and model providers it relies on hold their own SOC 2 or ISO 27001 attestations, which are reviewed in vendor management.

