Trust center

Security,
where it belongs.

Hosted in the EU, with an EU-only supplier chain. Keys you can hold. Open architecture, and a compliance roadmap you can hold us to.

At rest
Drive files encrypted, isolated per tenant
TLS 1.3
In-transit, PFS, HSTS preload
PGP
Mail at rest, keys you hold · Business
EU-only
Hosted in Paris, France · OVHcloud
Compliance roadmap

Built to the standards we're certifying against.

We don't claim certifications we don't yet hold. The architecture is designed to these frameworks from day one, here's where each one stands.

EUGDPRProcessor obligationsCompliant by design
ISO27001Information security managementTargeted 2026
ISO27701Privacy information managementTargeted 2026
AICPASOC 2Operational controlsOn roadmap
EUNIS2Critical-entity obligationsOn roadmap
FRSecNumCloudANSSI qualificationOn roadmap
Architecture

Tenant isolation
all the way down.

Every customer gets a dedicated directory, dedicated storage paths, and, on Enterprise, dedicated compute. Compromise of one tenant must never reach another. It's a design invariant we build against, not a slogan.

  • Dedicated per-tenant directories and accounts, no shared namespace
  • Per-account search indexes, no shared corpus
  • Per-tenant rate limits & quota enforcement
  • Encryption at rest with keys you hold, on Business and above
  • Append-only audit trail, enforced at the database, on Business and above
trust.email.eu/architecture
Tenant isolation map · illustrative example
tenant/remails · dedicated directoryisolated
tenant/nordhavn · dedicated storage pathisolated
tenant/caldera · scoped credentialsisolated
tenant/helveta · per-tenant quotasisolated
tenant/ministere-nl · at-rest keys held by tenantencrypted
Every tenant: own directory, scoped credentials, quota wallsexample
Transparency

We publish
what others don't.

Our standing commitments: a quarterly transparency report including every government request we receive, a public subprocessor list with 30-day change notice in the DPA, a public incident log, and a coordinated-disclosure program with a public write-up for every qualifying report.

  • Transparency report · quarterly, first edition published
  • Subprocessor list with 30-day change notice · in the DPA
  • Post-incident writeups within 7 days · public status page
  • Coordinated disclosure · acknowledged within 24h
email.eu/transparency
Transparency report · first edition
Everything through Q2 2026 · published 2026-08-04
0
Requests received
0
From outside the EU/EEA
0
Accounts affected
0
Security incidents
Read the full report, and how we count, at email.eu/transparency.
Answers

Security questions, answered straight.

Where is our data stored, and who operates the infrastructure?
On OVHcloud infrastructure in Paris, France. The servers are rented; everything running on them (mail, files, identity, meetings) is operated by us, not by a third party. Customer Data stays within the EU/EEA at all times, and no sub-processor is established outside it.
Is Email.eu ISO 27001 or SOC 2 certified?
No. ISO 27001 and ISO 27701 are targeted for 2026; SOC 2, NIS2 and SecNumCloud are on the roadmap. GDPR processor obligations are met today and set out in our DPA. The architecture is built to those frameworks from the start, but the certificates are not yet held, and the status on this page is the live one.
Who are your sub-processors?
Three, all EU entities: OVHcloud (OVH SAS, France) for infrastructure, Mollie B.V. (Netherlands) for payments, and Moneybird B.V. (Netherlands) for invoicing. The complete list, including what each one processes, is published at email.eu/subprocessors, and the DPA commits us to 30 days advance notice before any addition or replacement.
Is Email.eu subject to the US CLOUD Act?
No. Remails B.V. is a Dutch company with no US parent, subsidiary or affiliate, and no US provider sits anywhere in the supplier chain, payments included. A US authority therefore has no domestic entity to serve. Lawful requests for Customer Data go through a European court and through us; we report the totals in our quarterly transparency report.
Is mail end-to-end encrypted?
Not between correspondents, and we do not market it that way. On Business plans, mail is encrypted at rest with PGP or S/MIME keys that you hold, which means we cannot read what is stored. In transit, connections use TLS 1.3 with forward secrecy. Customer-managed keys via KMIP or HSM are on the Enterprise roadmap.
Do you train AI models on our data?
No. The service has no AI features, and Customer Data is never used to train models, ours or anyone else's. That is a contractual commitment in the DPA rather than a policy that can quietly change. If we ever ship AI features they will be opt-in, EU-hosted and tenant-isolated.
How do we report a vulnerability?
Mail security@email.eu. We run a coordinated-disclosure program: we confirm receipt within 24 hours, keep you updated through the fix, credit you if you want the credit, and publish post-incident write-ups within seven days where appropriate.

Security, done
properly.

Per-tenant isolation, keys you can hold, EU-only by design, and a DPA and compliance roadmap you can read line by line.

Read the DPATalk to our security team