Security and compliance, without compromise
HIPAA, GDPR, SOC 2 Type II — custom DPAs and BAAs available on every plan. We handle the paperwork so you can focus on sending.
Compliance certifications
SOC 2 Type II
Annual audit by an independent third party. Security, availability, and confidentiality controls verified.
Report available →HIPAA
Business Associate Agreement available on Professional and Enterprise plans. PHI handled with strict controls.
Request BAA →PCI DSS
Level 1 service provider. Cardholder data environment isolated and audited annually.
View certification →Four pillars of our security posture
Encryption
TLS 1.2/1.3 in transit. AES-256 at rest. Per-customer encryption keys available on Enterprise.
Network Security
Private backbone, no public internet routing for SMTP traffic. WAF, DDoS protection, and rate limiting at the edge.
Access Control
Role-based access control, MFA enforced on all accounts, SSO via SAML 2.0 on Enterprise.
Incident Response
24/7 security operations team. Breach notification within 72 hours per GDPR Article 33.
16 global regions — your data stays where you need it
Americas
- US East (N. Virginia)
- US West (Oregon)
- Canada (Central)
- Brazil (São Paulo)
EMEA
- Ireland
- Frankfurt
- London
- Amsterdam
- Paris
APAC
- Singapore
- Tokyo
- Sydney
- Mumbai
Security and compliance resources
Subprocessor List
Full list of third-party subprocessors and their compliance certifications.
View list →Ready to send with confidence?
Start your 30-day free trial. No credit card required.
Start Free Trial