Trust Center

Security and compliance, without compromise

HIPAA, GDPR, SOC 2 Type II — custom DPAs and BAAs available on every plan. We handle the paperwork so you can focus on sending.

Certifications

Compliance certifications

SOC 2 Type II

Annual audit by an independent third party. Security, availability, and confidentiality controls verified.

Report available →

HIPAA

Business Associate Agreement available on Professional and Enterprise plans. PHI handled with strict controls.

Request BAA →

GDPR

Data processing agreement available. EU data residency in Frankfurt and Dublin.

Request DPA →

PCI DSS

Level 1 service provider. Cardholder data environment isolated and audited annually.

View certification →
Security

Four pillars of our security posture

Encryption

TLS 1.2/1.3 in transit. AES-256 at rest. Per-customer encryption keys available on Enterprise.

Network Security

Private backbone, no public internet routing for SMTP traffic. WAF, DDoS protection, and rate limiting at the edge.

Access Control

Role-based access control, MFA enforced on all accounts, SSO via SAML 2.0 on Enterprise.

Incident Response

24/7 security operations team. Breach notification within 72 hours per GDPR Article 33.

Data Residency

16 global regions — your data stays where you need it

Americas

  • US East (N. Virginia)
  • US West (Oregon)
  • Canada (Central)
  • Brazil (São Paulo)

EMEA

  • Ireland
  • Frankfurt
  • London
  • Amsterdam
  • Paris

APAC

  • Singapore
  • Tokyo
  • Sydney
  • Mumbai
Documentation

Security and compliance resources

DPA Template

Download our standard Data Processing Agreement.

Download PDF →

Security Whitepaper

Deep-dive into our infrastructure, encryption, and controls.

Request access →

Subprocessor List

Full list of third-party subprocessors and their compliance certifications.

View list →

Ready to send with confidence?

Start your 30-day free trial. No credit card required.

Start Free Trial