Your email infrastructure, fully accountable
PostMTA Hosted is SOC 2 aligned, HIPAA-ready, and GDPR-compliant — with custom DPAs and BAAs on every plan. Our controls are mapped to NIST CSF and CIS Controls v8 so your auditors get real artifacts, not a checkbox exercise.
SOC 2 Type II
Aligned · Report available
HIPAA
BAA on all plans
NIST CSF
All 5 functions mapped
CIS Controls v8
All 18 categories mapped
How PostMTA differs from other MTA providers
Real artifacts, not a checkbox
Most MTA vendors hand you a SOC 2 report PDF and call it a day. PostMTA goes further: our controls are explicitly mapped to NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover) and CIS Controls v8. Your auditor receives a working artifact — the PMH-SEC matrix, audit log schema, and architecture diagrams — not just a certificate.
We also run a formal multi-tenant isolation test (PMH-SEC-036) before every production deployment. This isn't a penetration test snapshot — it's an automated gate that rejects any code change that could allow one workspace's data to leak into another.
- PMH-SEC matrix with 38 controls — status, evidence references, and owner for each
- SOC 2 Type II aligned — report available under NDA
- HIPAA BAA available on Professional and Enterprise plans
- GDPR DPA with EU Standard Contractual Clauses
- CIS Controls v8 all-18-category mapping
- Battle-test PASS run as part of every release gate
Important note on certifications
PostMTA is "aligned" — not "certified." We do not hold a SOC 2 Type II certificate, ISO 27001 certificate, or C5 attestation. What we offer is better for enterprise procurement: real evidence artifacts that your team can actually use in your own compliance narrative.
Customers receive the PMH-SEC control matrix, audit log schema, architecture diagram, and penetration test summary on request. These are the same artifacts our own internal reviews are based on.
Four pillars of our trust posture
Security
38 PMH-SEC controls covering authentication, authorization, transport encryption, credential handling, and multi-tenant isolation. Every control has a status, an owner, and an evidence reference. View the full matrix →
Compliance
SOC 2 TSC (CC1–CC9, A1), HIPAA safeguards (administrative, physical, technical), NIST CSF (Identify, Protect, Detect, Respond, Recover), and CIS Controls v8 all mapped with specific PMH-SEC control references. View the crosswalk →
Privacy
GDPR DPA with EU SCCs, UK Addendum, CCPA service provider terms, and data residency in 16 global regions (US, EU, APAC). Customer data is never used for model training. Append-only audit logs with configurable retention.
Resilience
99.99% uptime SLA on Enterprise. GPG-signed backups, air-gap signed bundles, chaos failure injection testing (PMH-SEC-038), and a formal incident response plan with 15-minute acknowledgment SLA for critical security events.
16 global regions — your data stays where you need it
Americas
- US East (N. Virginia)
- US West (Oregon)
- Canada (Central)
- Brazil (São Paulo)
EMEA
- Ireland
- Frankfurt
- London
- Amsterdam
- Paris
APAC
- Singapore
- Tokyo
- Sydney
- Mumbai
Security and compliance resources
PMH-SEC Control Matrix
All 38 controls with IDs, titles, descriptions, and Live / Shipping / Roadmap status.
View matrix →Compliance Crosswalk
SOC 2 TSC, HIPAA, NIST CSF, CIS Controls v8 — each requirement mapped to what PostMTA does.
View crosswalk →DPA / BAA Templates
GDPR DPA with SCCs, HIPAA BAA, CCPA terms. Download from /contact or request a custom execution.
Request DPA →Request evidence or sign a DPA
Tell us what you need — a security questionnaire, signed DPA/BAA, SOC 2 report, or the full PMH-SEC matrix. We'll respond within one business day.