{
  "slug": "sendgrid",
  "category": "email-sending",
  "name": "SendGrid",
  "description": "Email API and SMTP relay from Twilio for transactional and marketing email, with open and click tracking, event webhooks and an activity feed.",
  "website": "https://www.twilio.com/en-us/sendgrid",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 52,
  "coverage": 100,
  "summary": "SendGrid scores 52 out of 100 (grade D) on the email sending services criteria. It meets 4 of 12 criteria: transparency report, tells users about requests, message content deleted after delivery and encrypted delivery can be enforced. It partly meets no ads or data sales, independent audit, TLS configuration, open and click tracking off by default and EU data location. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade D-.",
  "url": "https://privacyratings.com/email-sending/sendgrid/",
  "markdown": "https://privacyratings.com/email-sending/sendgrid/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "The website loads Google Tag Manager, Segment, Adobe Launch and VWO."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.twilio.com/en-us/legal/privacy",
      "note": "Funded by paid plans and states data is not sold, but website tracking for targeted advertising counts as sharing under some US state laws."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://security.twilio.com/",
      "note": "SOC 2 and ISO 27001 audits and a SendGrid penetration test report are listed, but reports are only available on request through the Twilio Trust Center."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.twilio.com/en-us/legal/transparency",
      "note": "Twilio publishes annual transparency reports with government request counts, responses and how often users were notified."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://www.twilio.com/en-us/legal/law-enforcement-guidelines",
      "note": "Twilio uses reasonable efforts to notify customers of requests for their information unless prohibited by law."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=sendgrid.com&hideResults=on",
      "note": "Grade A-"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=sendgrid.com",
      "note": "Grade D- (25/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "content_retention": {
      "title": "Message content deleted after delivery",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://support.sendgrid.com/hc/en-us/articles/18961023703963-How-to-Find-the-Body-or-Contents-of-Emails",
      "note": "Message content is not stored. Delivery data such as addresses, timestamps and engagement events is kept."
    },
    "tracking_off_by_default": {
      "title": "Open and click tracking off by default",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.twilio.com/docs/sendgrid/ui/account-and-settings/tracking",
      "note": "Open tracking is turned on by default for Marketing Campaigns. Open and click tracking can be turned off in the account's tracking settings."
    },
    "enforced_tls": {
      "title": "Encrypted delivery can be enforced",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.twilio.com/docs/sendgrid/for-developers/sending-email/enforced-tls",
      "note": "Enforced TLS settings can require TLS and a valid certificate. Mail to servers that do not meet them is dropped."
    },
    "eu_data_location": {
      "title": "EU data location",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://www.twilio.com/docs/sendgrid/data-residency/faq.md",
      "note": "EU data residency is available only on Pro, Premier and Custom plans."
    }
  },
  "tests": {
    "ssllabs": "A-",
    "observatory": "D-",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      },
      {
        "name": "Segment",
        "host": "cdn.segment.com",
        "effect": "no"
      },
      {
        "name": "TrustArc",
        "host": "consent.trustarc.com",
        "effect": "none"
      },
      {
        "name": "VWO",
        "host": "dev.visualwebsiteoptimizer.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T07:28:24.921Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}