Two deployment models. One standard of trust.
PostMTA Enterprise is available as a fully managed service (We Operate) or as a self-hosted appliance (You Operate). Both include the same security controls, PMH-SEC matrix, and compliance artifacts.
WE OPERATE (Managed)
┌─────────────────────────────────┐
│ Your Application │
└──────────┬────────────────────┘
│ HTTPS
┌──────────▼────────────────────┐
│ PostMTA Cloud (Shared VPC) │
│ · JWT Auth · Rate Limits │
│ · Multi-tenant isolation │
│ · PMH-SEC-036 gated │
└──────────┬────────────────────┘
│ SMTP/TLS
┌──────────▼────────────────────┐
│ Downstream MX (Internet) │
└────────────────────────────────┘
YOU OPERATE (Self-Hosted)
┌─────────────────────────────────┐
│ Your Application │
└──────────┬────────────────────┘
│ HTTPS
┌──────────▼────────────────────┐
│ PostMTA Appliance (Your VPC) │
│ · Air-gapped install │
│ · Your KMS for DKIM keys │
│ · PMH-SEC-036 tested │
└──────────┬────────────────────┘
│ SMTP/TLS
┌──────────▼────────────────────┐
│ Downstream MX (Internet) │
└────────────────────────────────┘
PMH-SEC-036
Multi-tenant isolation test, every deployment
99.99%
Uptime SLA on Enterprise
SOC 2
Aligned — artifacts available
HIPAA
BAA on all plans
Model: base + credits. No per-email surprises.
What's included in base
- Dedicated sending infrastructure (isolated VPC)
- Named solutions engineer (quarterly reviews)
- HIPAA BAA or GDPR DPA (custom execution)
- SOC 2 artifact package under NDA
- PMH-SEC matrix with 38 controls
- 99.99% uptime SLA with financial credits
- 24/7 emergency support (15-min response)
- Kumo path onboarding support
- OmniFBL (aggregate feedback loop)
- Custom DKIM (dedicated signing key)
- Dedicated IP pool (up to /24)
- Observability: structured JSON logs + metrics
Add-ons
Credit pricing is volume-based and negotiated annually. Contact us for a custom quote based on your projected send volume.
What Enterprise includes vs. typical MTA providers
| Feature | PostMTA Enterprise | Typical MTA Provider |
|---|---|---|
| PMH-SEC control matrix (38 controls) | ✅ Full matrix, status + evidence refs | ❌ Vendor SOC 2 PDF only |
| Multi-tenant isolation test (automated) | ✅ PMH-SEC-036 gates every deploy | ❌ Not disclosed |
| HIPAA BAA | ✅ Custom execution, all plans | ❌ Limited or not available |
| SOC 2 artifact package | ✅ Full evidence package under NDA | ❌ Report PDF only |
| Custom DPA | ✅ Counter-signed, SCCs included | ❌ Standard template only |
| SLA | ✅ 99.99% with financial credits | ❌ 99.9% or lower, no credits |
| Named solutions engineer | ✅ Quarterly reviews, direct access | ❌ Ticket queue only |
| Custom IP pool | ✅ Up to /24 included | ❌ Shared pool only |
| Observability (structured JSON logs) | ✅ Per-workspace, 90-day hot retention | ❌ Aggregated only, limited retention |
| Incident response SLA | ✅ 15-minute acknowledgment, 24/7 | ❌ Business hours only |
| Migration assistance | ✅ PMH-SEC-037 tested, Kumo path included | ❌ Self-service only |
| Battle-test PASS on every release | ✅ PMH-SEC-036 automated gate | ❌ Not disclosed |
Everything included
Named Solutions Engineer
A dedicated contact who knows your account. Quarterly health reviews, proactive warmup monitoring, and direct Slack access — not a ticket queue.
Custom DPA / BAA
Available on all plans. Healthcare organizations, financial services, and regulated industries — we handle the paperwork. Counter-signed DPA returned within 2 business days.
99.99% Uptime SLA
Financial credits for any qualifying downtime. Measured via synthetic monitoring from 3 regions. 15-minute incident acknowledgment SLA, 24/7.
Custom IP Pools + OmniFBL
Dedicated IP pool up to /24. OmniFBL aggregates complaint and bounce feedback from all major ISPs into a single dashboard view. Full reputation transparency.
How Meridian Health cut deliverability issues by 94%
"We went from 68% to 97.3% inbox placement in three weeks. PostMTA's team actually understands email infrastructure."
Sarah Roth, VP Engineering, Meridian Health
Request case study access →Talk to our enterprise team
Schedule a 30-minute technical call with a solutions engineer. We'll discuss your sending volume, compliance requirements, and migration path.