惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
The Last Watchdog
The Last Watchdog
TaoSecurity Blog
TaoSecurity Blog
PCI Perspectives
PCI Perspectives
L
LINUX DO - 最新话题
H
Heimdal Security Blog
S
Security Archives - TechRepublic
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
Troy Hunt's Blog
SecWiki News
SecWiki News
S
Secure Thoughts
The Cloudflare Blog
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
Attack and Defense Labs
Attack and Defense Labs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
量子位
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
V
Visual Studio Blog
N
News and Events Feed by Topic
E
Exploit-DB.com RSS Feed
博客园 - Franky
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
Know Your Adversary
Know Your Adversary
M
MIT News - Artificial intelligence
V
V2EX
Webroot Blog
Webroot Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
Cyberwarzone
Cyberwarzone
博客园 - 【当耐特】
月光博客
月光博客
Y
Y Combinator Blog
B
Blog RSS Feed
Recent Announcements
Recent Announcements
S
Schneier on Security
H
Hacker News: Front Page
Stack Overflow Blog
Stack Overflow Blog
NISL@THU
NISL@THU
小众软件
小众软件
雷峰网
雷峰网
P
Privacy International News Feed
腾讯CDC
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
C
Cyber Attacks, Cyber Crime and Cyber Security
V
Vulnerabilities – Threatpost
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
News and Events Feed by Topic

Resend RSS Feed

6 Tips for Accessible Emails Welcoming Manoel do Amaral, our new Brand Designer Welcoming Michael Vaz, our new Customer Success Engineer Six Steps to Improve Your Sender Reputation Welcoming Tatira Andrade, our new Executive Assistant Welcoming Pedro Ivo Hudson, our new Design Engineer Welcoming Diel Duarte, our new Open source Engineer Welcoming Areia Spinner, our new Recruiter Resend Forward: A Conference about Craft React Email 6.0 Custom Tracking Domains AI Email Editor Introducing Automations Welcoming Ahmed Tolba, our new SRE Engineer Welcoming Aneil Singh, our new Founding Account Executive Welcoming Lucas Motta, our new Software Engineer Welcoming Trey Knowles, our new Founding Account Executive Welcoming Anxhela Carciu, our new SRE Engineer Introducing DMARC Analyzer Welcoming Evan Thibodeau, our new Customer Success Engineer Welcoming Derich Pacheco, our new Software Engineer Welcoming Alec Ventura, our new Data Engineer Welcoming Felipe Freitag, our new Software Engineer Welcoming Mateusz Wos, our new Software Engineer Incident report for February 15, 2026 Email automation for OpenClaw How to Create a DevTools Agent Skill Introducing Email Skills Why You Should Embrace the Promotions Tab Slater Smith, our new Customer Success Engineer Do You Need a Warmup Service? Welcoming Zá Scalon, our new Brand Designer How Replit Built Effortless Email Sending Features 1,000,000 users Top 10 new features in 2025 Welcoming Danilo Campos, our new Design Engineer How Dub Uses Webhooks to Power Features Incident report for November 18, 2025 Resend Forward 5: Wrap Up One More (AI) Thing React Email 5.0 Unsubscribe Topics New Contacts Experience Introducing Templates Inbound Emails $3M to Make Email Safer Hacktoberfest 2025 Four Ways to Hurt Your Sender Reputation Resend MCP Hackathon Welcoming Christina Martinez, our new Developer Experience Engineer How to read a DMARC report Welcoming Erin Levine, our new Chief of Staff How to Validate Form Inputs Engineering an AI App Welcoming Lucas da Costa, our new Software Engineer Welcoming Lucas Vieira, our new Software Engineer Resend acquires Briefer How Raycast Modernized their Email Sending How to Get Email Consent DMARC Policy Modes Welcoming Gabriel Miranda, our new Software Engineer Rebranding Resend The 7 Best Email Verification APIs for Developers How DMARC Applies to Subdomains Welcoming Pedro Gomes, our new Software Engineer Do You Need a Dedicated IP? The 6 best notification infrastructure services The Fixer Why Your Emails are Going to Spam Engineering Idempotency Keys Microsoft’s bulk sending requirements for 2025 Welcoming Rehan van der Merwe, our new Devops Engineer 400,000 users and beyond Welcoming Cassio Zen, our new Software Engineer Resend acquires Mergent How to warm up a new domain Welcoming Carolina Josephik, our new Software Engineer Launch Week: Behind the Scenes Welcoming Isabella Aquino, our new Software Engineer Resend Forward 4: Wrap Up React Email 4.0 Multiplayer Editor Broadcast API Multiple Teams new.email Public Launch Welcoming Anna Ward, our new Postmaster How Gumroad Migrated 100M Emails to Resend Welcoming João Melo, our new Software Engineer Welcoming Jp Valery, our new Customer Success Engineer What is AX (Agent Experience) and how to improve it Welcoming Pauline Chin, our new Customer Success Engineer Introducing new.email How we use Friction Logs to improve the product Top 10 Email Deliverability Tips Welcoming Giovana Yahiro, our new Designer Engineer What BIMI's Changes Mean for Email Top 10 new features in 2024 Design Engineering an X Component Welcoming Alexandre Cisneiros, our new Software Engineer Resend raises $18M Series A
Resend is SOC 2 Type II compliant
Jonni Lundy · 2024-03-26 · via Resend RSS Feed

The journey starts

In early April of 2023, we were finalizing our time inside of Y Combinator.

We had just over 50 paying customers and only 3 people on the team (Bu, Zeno, and myself). We were not thinking about compliance, just trying to build a product people loved and would pay for.

Even though only two prospects had asked us about SOC 2, we knew this journey was best started sooner rather than later. Resend is the second company where I've gone from zero to SOC 2. I remembered the arduous timeline:

  • Start engaging with auditors and consultants (1-2 weeks)
  • Optionally perform a readiness assessment (2 weeks)
  • Begin making all the changes needed across the org (2-5 months)
  • Optionally do a Type I audit first (1-3 months)
  • Complete audit period (6-12 months)
  • Review evidence with auditors and wait for the final report (1-2 months)

In the best-case scenario, we were looking at 9 months before we would have the final report, more likely 12-15 months. This wasn't a short-term growth play but the beginning of a long-term security investment.

The question wasn't "Is this important now?" but rather, "Will this be important a year from now?". We knew it definitely would be.

Choosing the type of audit

Although SOC 2 Type II is a default for most SaaS companies, many strategic standards exist, like GDPR, ISO 27001, HIPAA, FEDRAMP, and more. We chose SOC 2 because it is a well-rounded standard to build on and covers practical security measures like least-privileged access alongside organization controls like incident management.

We decided to skip SOC 2 Type I because it's not a requirement for Type II, and we wanted to save time and money. We had already been through the process, which made us more confident we could pass the Type II audit on the first run.

Many years ago, when I first went through SOC 2 at my previous company, we had to write all policies manually and used tons of spreadsheets to track everything.

The world has changed a lot since then. This time, we decided to use a compliance tool to help collect evidence automatically.

We considered Drata, Secureframe, and Vanta. In the end, we chose Vanta because the product was the clear leader in real-time monitoring with robust automation and because they were a fellow YC company, which made it easier to get started.

Engaging with an auditor

Once we had Vanta up and running, it took us some time to make the needed changes and catalog the evidence. We then engaged with an auditor to review everything and attest to the compliance of every control.

We chose Advantage Partners because they were a Vanta partner and had a track record of collaborating with many SaaS companies.

Around June 2023, we worked with them to complete a readiness check and then began the observation window shortly after.

Keeping the momentum

In November 2023, we had a mid-audit checkpoint since we were halfway through our SOC 2 Type II observation window. We have dozens of projects happening at any given time, and losing focus is easy.

Vanta makes it easy to keep compliance top of mind. They send daily and weekly reminders on Slack and email so we know what is due. This also prevented any surprises during the final audit.

This proactive approach is essential. SOC 2 is not a one-time project. It's an ongoing process that requires continuous improvement and maintenance.

SOC 2 is not a silver bullet

If you've been with us for a while, you'll know we had some incidents in January/February 2024. All of these happening during our audit period were discouraging and even made me question how meaningful SOC 2 is if it can't protect us from these kinds of events.

As the dust settled, I realized that SOC 2 is not a silver bullet for preventing any incident from ever happening. Similar to driving laws, it's there to safely guide most day-to-day operations and help prepare for how to respond if things go wrong. Having SOC 2 already implemented before these incidents gave us a foundation to respond effectively and grow efficiently from each incident.

We're learning that the most secure system is the one that is active, iterative, and improving over the one that has all the boxes checked and stays put. We love that SOC 2 encourages this way of active, engaged working.

SOC 2 is not a checkbox exercise, but rather a mechanism that helps build a security culture.

The final report

Almost 12 months after we started thinking about SOC 2, we passed our first Type II audit with zero exceptions. We couldn't be more proud of the effort of the entire team to make this happen.

This reporting period is from August 1, 2023 to February 1, 2024 and covers all users on all plans.

You can request a copy of the report via the Documents on the dashboard. If you have a questionnaire that needs filling, please contact us.

Make sure to visit the dedicated SOC 2 page and Security Center for more information on our data safety practices.