Trust Center

Your email infrastructure, fully accountable

PostMTA Hosted is SOC 2 aligned, HIPAA-ready, and GDPR-compliant — with custom DPAs and BAAs on every plan. Our controls are mapped to NIST CSF and CIS Controls v8 so your auditors get real artifacts, not a checkbox exercise.

SOC 2 Type II

Aligned · Report available

HIPAA

BAA on all plans

NIST CSF

All 5 functions mapped

CIS Controls v8

All 18 categories mapped

Executive Summary

How PostMTA differs from other MTA providers

Real artifacts, not a checkbox

Most MTA vendors hand you a SOC 2 report PDF and call it a day. PostMTA goes further: our controls are explicitly mapped to NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover) and CIS Controls v8. Your auditor receives a working artifact — the PMH-SEC matrix, audit log schema, and architecture diagrams — not just a certificate.

We also run a formal multi-tenant isolation test (PMH-SEC-036) before every production deployment. This isn't a penetration test snapshot — it's an automated gate that rejects any code change that could allow one workspace's data to leak into another.

  • PMH-SEC matrix with 38 controls — status, evidence references, and owner for each
  • SOC 2 Type II aligned — report available under NDA
  • HIPAA BAA available on Professional and Enterprise plans
  • GDPR DPA with EU Standard Contractual Clauses
  • CIS Controls v8 all-18-category mapping
  • Battle-test PASS run as part of every release gate

Important note on certifications

PostMTA is "aligned" — not "certified." We do not hold a SOC 2 Type II certificate, ISO 27001 certificate, or C5 attestation. What we offer is better for enterprise procurement: real evidence artifacts that your team can actually use in your own compliance narrative.

Customers receive the PMH-SEC control matrix, audit log schema, architecture diagram, and penetration test summary on request. These are the same artifacts our own internal reviews are based on.

Trust Pillars

Four pillars of our trust posture

Security

38 PMH-SEC controls covering authentication, authorization, transport encryption, credential handling, and multi-tenant isolation. Every control has a status, an owner, and an evidence reference. View the full matrix →

Compliance

SOC 2 TSC (CC1–CC9, A1), HIPAA safeguards (administrative, physical, technical), NIST CSF (Identify, Protect, Detect, Respond, Recover), and CIS Controls v8 all mapped with specific PMH-SEC control references. View the crosswalk →

Privacy

GDPR DPA with EU SCCs, UK Addendum, CCPA service provider terms, and data residency in 16 global regions (US, EU, APAC). Customer data is never used for model training. Append-only audit logs with configurable retention.

Resilience

99.99% uptime SLA on Enterprise. GPG-signed backups, air-gap signed bundles, chaos failure injection testing (PMH-SEC-038), and a formal incident response plan with 15-minute acknowledgment SLA for critical security events.

Data Residency

16 global regions — your data stays where you need it

Americas

  • US East (N. Virginia)
  • US West (Oregon)
  • Canada (Central)
  • Brazil (São Paulo)

EMEA

  • Ireland
  • Frankfurt
  • London
  • Amsterdam
  • Paris

APAC

  • Singapore
  • Tokyo
  • Sydney
  • Mumbai
Documentation

Security and compliance resources

PMH-SEC Control Matrix

All 38 controls with IDs, titles, descriptions, and Live / Shipping / Roadmap status.

View matrix →

Compliance Crosswalk

SOC 2 TSC, HIPAA, NIST CSF, CIS Controls v8 — each requirement mapped to what PostMTA does.

View crosswalk →

DPA / BAA Templates

GDPR DPA with SCCs, HIPAA BAA, CCPA terms. Download from /contact or request a custom execution.

Request DPA →

Request evidence or sign a DPA

Tell us what you need — a security questionnaire, signed DPA/BAA, SOC 2 report, or the full PMH-SEC matrix. We'll respond within one business day.