Trust center

Security,
where it belongs.

Hosted in the EU, with an EU-only supplier chain. Keys you can hold. Open architecture, and a compliance roadmap you can hold us to.

At rest
Drive files encrypted, isolated per tenant
TLS 1.3
In-transit, PFS, HSTS preload
PGP
Mail at rest, keys you hold · Business
EU-only
Hosted in Paris, France · OVHcloud
Compliance roadmap

Built to the standards we're certifying against.

We don't claim certifications we don't yet hold. The architecture is designed to these frameworks from day one, here's where each one stands.

EUGDPRProcessor obligationsCompliant by design
ISO27001Information security managementTargeted 2026
ISO27701Privacy information managementTargeted 2026
AICPASOC 2Operational controlsOn roadmap
EUNIS2Critical-entity obligationsOn roadmap
FRSecNumCloudANSSI qualificationOn roadmap
Architecture

Tenant isolation
all the way down.

Every customer gets a dedicated directory, dedicated storage paths, and, on Enterprise, dedicated compute. Compromise of one tenant must never reach another. It's a design invariant we build against, not a slogan.

  • Dedicated per-tenant directories and accounts, no shared namespace
  • Per-account search indexes, no shared corpus
  • Per-tenant rate limits & quota enforcement
  • Encryption at rest with keys you hold, on Business and above
  • Append-only audit trail, enforced at the database, on Business and above
trust.email.eu/architecture
Tenant isolation map · illustrative example
tenant/remails · dedicated directoryisolated
tenant/nordhavn · dedicated storage pathisolated
tenant/caldera · scoped credentialsisolated
tenant/helveta · per-tenant quotasisolated
tenant/ministere-nl · at-rest keys held by tenantencrypted
Every tenant: own directory, scoped credentials, quota wallsexample
Transparency

We publish
what others don't.

Our standing commitments: a quarterly transparency report including every government request we receive, a public subprocessor list with 30-day change notice in the DPA, a public incident log, and a coordinated-disclosure program that rewards researchers.

  • Transparency report · quarterly, first edition Q3 2026
  • Subprocessor list with 30-day change notice · in the DPA
  • Post-incident writeups within 7 days · public status page
  • Coordinated disclosure · rewards for qualifying reports
trust.email.eu/reports
Transparency report · illustrative
Example layout · first edition publishes Q3 2026
Third-country requests
EU court orders
Security incidents
Bounties paid
Illustrative layout, the first real report publishes Q3 2026.

Security, done
properly.

Per-tenant isolation, keys you can hold, EU-only by design, and a DPA and compliance roadmap you can read line by line.

Read the DPATalk to our security team