Security and data protection
How we protect your mailboxes, your credentials, and your mail. The facts, not adjectives.
Authenticated per-customer encryption
Each customer gets a dedicated Fernet key. We use it to encrypt your sensitive fields at rest, with authentication built in: your mailboxes' OVH SMTP and IMAP passwords, cached message bodies, and outbound message bodies. Mailbox passwords are never returned by any API response and never written to logs. Your agent authenticates with a scoped mailbox API key, not the underlying password.
EU data residency
Your mailboxes live on OVHcloud in the EU, the authoritative store for your mail. Outbound mail is relayed through Amazon SES in eu-west-1 (Dublin). Storage and processing stay in the EU. Mail you send then travels to the recipient's server, which can be anywhere, so delivered mail leaves the EU once it reaches them.
Account and access control
Turn on optional two-factor authentication (TOTP), compatible with the usual authenticator apps. Enabling it gives you 10 single-use recovery codes, shown once. API keys are scoped to a single mailbox with a read, read-write, or management role, can be set to expire, and can be revoked at any time.
Your data, in your control
Request a data export and we assemble a downloadable archive of your account (domains, mailboxes, keys, DNS records, messages and bodies, bounces, suppressions, audit log, and tickets) behind a signed link valid for 24 hours, one export per 24 hours. Account deletion runs on a 7-day grace period. Credentials and keys are revoked immediately, you can cancel during the grace window, and after 7 days your per-customer key is destroyed. With the key gone, every encrypted blob is permanently unrecoverable. Our handling of your data is aligned with the GDPR.
Deliverability guard rails
We publish DKIM automatically, suppress hard bounces and complaints per mailbox, and track each mailbox's bounce-and-complaint rate over a rolling window. Sustained high rates throttle, then disable, a mailbox to protect the shared sending reputation, and you're emailed when it happens. We run the machinery; you own your domain's sending reputation. We don't promise inbox placement, because no one honestly can.
Transparency
A live status page, the full OpenAPI reference published from our live schema, and transparent pricing with domain costs shown at selection. No hidden fees.
Custom security review or DPA?
For a security or legal review, a DPA, or a conversation about negotiated EU-residency assurances, talk to us.