Skip to content

Security

Security you can verify.

MepMail Cloud runs in Germany on Contabo hardware, the product is open source under AGPL-3.0, and you can self-host the whole thing. Your email content, and every claim on this page, sits somewhere you can check instead of somewhere you have to trust.

  • EU data residency · Germany
  • Open source · AGPL-3.0
  • Self-hostable
  • Encrypted in transit and at rest
  • DKIM · SPF · DMARC

Last reviewed: September 29, 2026. Every statement here is a property of the running product, or labelled as a roadmap item.

Data protection

Sealed at rest, encrypted in transit, restorable by design

Three things decide how safe your email really is: what the database holds, what the network sees, and whether last night's backup actually opens.

At rest

Content is sealed before it is stored

What lands in the database is ciphertext, not a copy of your customers' mail.

  • Every message body (HTML and text) and every attachment is sealed with envelope encryption: a per-message data key encrypts the content and is itself wrapped by the instance key.
  • The wrapping key lives outside the database — the environment master key, or AWS KMS when a KMS key is configured, and both can run side by side while older rows keep opening.
  • A sealed row is bound to its own id, so a ciphertext moved to another row fails to open instead of leaking.
  • Passwords are hashed with scrypt, and API keys are shown once and stored only as a SHA-256 hash plus a short identifying prefix, compared in constant time.

In transit

Every hop is encrypted, including the relay

The panel, the API, the SMTP relay and the hand-off to the inbox all run over encrypted connections.

  • The panel and the API are served over HTTPS, with HSTS (one year, subdomains included), a strict Content-Security-Policy, X-Frame-Options DENY, nosniff and a restricted Permissions-Policy.
  • The SMTP relay requires TLS: STARTTLS is offered with our certificate, and the relay refuses to start without a keypair unless the operator explicitly opts in for a trusted private network.
  • Mail leaves through Amazon SES over TLS, authenticated on your domain by DKIM and SPF.

Recovery

Backups that are verified, not assumed

A daily dump is not a backup until the file has been read back and trusted.

  • The nightly dump (pg_dump, custom format) is validated with pg_restore --list and a checksum before it is trusted.
  • A copy is pushed to off-site object storage, and the uploaded object is re-read and required to match byte for byte.
  • Dumps older than 14 days are pruned, and a dump can be encrypted with an age key before it leaves the host.

Why teams pick MepMail

The security decisions a hosted-only platform cannot make for you

The controls that matter most are the ones you still hold. MepMail is built so that control is real — auditable, portable and, if you want it, entirely inside your own infrastructure.

Data residency

Your data stays in the EU

Germany is where MepMail Cloud runs, not a region you have to request in a sales call.

  • The application and its database run on Contabo infrastructure in Germany — one hosting provider, named on this page.
  • GDPR is the frame the product was built in: EU hosting is the default, not a data-transfer footnote.
  • Delivery runs through Amazon SES (us-east-1) and payments through Stripe, both listed as subprocessors, and the Privacy Policy states what is stored, why and for how long.

Verifiability

Open source under AGPL-3.0

Trust through verifiability: the security claims here are claims about code anyone can read.

  • The encryption, retention, isolation and API surface are all in the public repository — no trust center required to check them.
  • A claim that would not survive an audit of the source is not a claim we make; the trust-center language stays out.
  • Found a gap between this page and the code? That is a security report, and it goes straight to the people who fix it.

Sovereignty

Self-host the whole product

The option a hosted-only vendor cannot offer: run MepMail on your own infrastructure and your data never leaves it.

  • The same panel, API and SDK compatibility, deployed with your own database, keys, object storage and SES account.
  • The subprocessor list on this page stops applying to you: you are the only processor of your data.
  • Useful when a client, a regulator or your own security team requires data to stay inside a boundary you control.

Isolation

Per-team isolation, without a migration project

Multi-tenant by design, and cheap to adopt if you are coming from another provider.

  • Contacts, domains, templates, suppressions, keys, audit entries and API requests all carry the team that owns them, and membership is re-checked as tokens are issued.
  • Reputation is isolated too: per-team bounces and complaints, abuse limits on every plan, and an instance health signal that can pause one team's sending.
  • MepMail speaks the Resend sending API, so adopting it is a base URL and a key change rather than a rewrite.

Security controls

The controls running in production today

Every item below is a property of the running product, not an aspiration. Where a control only covers part of the surface, the card says so — and the source is public, so you can check the ones that matter to you.

Encryption in transit

Everything between you and MepMail travels over an encrypted connection.

  • The panel and the API are served over HTTPS, with HSTS (one year, subdomains included), a strict Content-Security-Policy, X-Frame-Options DENY, nosniff and a restricted Permissions-Policy.
  • The SMTP relay requires TLS: STARTTLS is offered with our certificate, and the relay refuses to start without a keypair unless the operator explicitly opts in for a trusted private network.
  • Mail leaves through Amazon SES over TLS, authenticated for your domain by DKIM and SPF.

Passwords and API keys

Credentials are stored in forms that cannot be replayed.

  • Account passwords are hashed with scrypt (Node's crypto.scrypt); no plain-text password is stored or sent to the browser.
  • API keys are shown once and stored only as a SHA-256 hash plus a short prefix for identification, and a presented key is compared in constant time.
  • A team can hold at most 25 active keys, so a leaked key cannot fan out into an unbounded set of credentials.
  • Sign-in, sign-up, password reset and verification resend are rate-limited per window and IP.

Team isolation

The team is the boundary: a credential only ever reaches the team it is bound to.

  • Contacts, broadcasts, sending domains, templates, suppressions, API keys, audit entries and API requests all carry the team that owns them.
  • An API grant is bound to a team, and membership is re-checked as tokens are issued or refreshed — removing a member stops new tokens.
  • Deleting an account is refused while it is the only owner of a team, so a team is never left with nobody able to administer it.

Abuse limits

Limits keep one compromised key or one runaway script from burning a domain's reputation.

  • Every plan carries an included volume and a daily send ceiling; sends past the daily ceiling are held instead of running all day.
  • Bounces and complaints are recorded per team, and the instance's deliverability health can pause a team's sending.
  • Sign-up is closed by default on a reachable instance — only the first account may register — and a beta can be capped by seat count.
  • A Cloudflare Turnstile challenge can be turned on for sign-in, sign-up, password reset and the verification resend.

Suppressions

A do-not-contact record beats any future send, on every surface.

  • Hard bounces, spam complaints, manual blocks and one-click unsubscribes are stored per team against a hash of the recipient address.
  • The list is checked on every send path — API, SMTP relay and scheduled broadcasts alike — while transactional mail still reaches a recipient who only unsubscribed from marketing.
  • Suppressions outlive erasure: account data is removed, the hash stays as the do-not-contact record.

Monitoring

The service and the deploy path are watched, not just the happy path.

  • The API exposes a health endpoint that reports the service status and the deployed revision.
  • Containers run health checks that gate startup and restarts.
  • A boot check verifies the application containers and the SMTP relay port and alerts the operator, and each deploy verifies the public site and its security headers before it is called done.

Backups

The database is dumped on a daily schedule and the copy is verified.

  • The nightly dump (pg_dump, custom format) is validated with pg_restore --list and a checksum before it is trusted.
  • A copy is pushed to off-site object storage, and the uploaded object is re-read and required to match byte for byte.
  • Dumps older than 14 days are pruned, and a dump can be encrypted with an age key before it leaves the host.

DKIM, SPF and DMARC

Authentication is configured per sending domain, not globally.

  • Connecting a domain returns the exact DNS records to publish: the DKIM record and the MAIL FROM record (SPF).
  • Those two gate sending — a domain whose records stop resolving has its sends refused until they are back — and a background worker re-checks each domain's DNS on a schedule.
  • DMARC is recommended rather than required, and MepMail reads the policy, including one inherited from the parent domain.

Infrastructure

Subprocessors

The short list of providers that process data for MepMail Cloud. It mirrors the Privacy Policy and adds the hosting provider.

ProviderRoleLocation
Contabo GmbHServers hosting the application and its databaseGermany
Amazon Web Services (Amazon SES)Email delivery and delivery eventsus-east-1, United States
CloudflareDNS, CDN and network protection in front of our serversGlobal edge network
StripePayment processing, invoices and receiptsUnited States

A self-hosted instance runs on infrastructure you choose, so this list does not apply to it.

Built on infrastructure you already trust

No exotic dependencies to vet: the four providers behind every send are the same names most teams already run in production.

  • Contabo GmbHEU hosting · Germany
  • Amazon SESDelivery over TLS
  • CloudflareDNS, CDN, edge protection
  • StripePayments and invoices

Compliance

Where compliance stands — in writing

GDPR applies to MepMail Cloud from the first European team that signs up, and the application runs in the EU. Framework audits are a longer road, and this is exactly where that road is.

  • GDPRIn place

    MepMail Cloud is hosted in Germany and the Privacy Policy states what is stored, why and for how long. A DPA is agreed per customer — ask at [email protected]. Privacy Policy

  • SOC 2 · ISO 27001In progress

    Both are on the roadmap. No auditor is engaged and no date is announced: we will not describe an audit that has not happened, and no certificate is implied by this page.

  • SLA · uptimeNot published

    No uptime percentage and no SLA are published today. When that changes, it is written here first — until then, the control list above is what to hold us to.

The rule behind all of it: every claim on this page is a property of the running product, or labelled as a roadmap item.

FAQ

The questions an enterprise review asks

Short answers, with the detail underneath. Anything missing is a fair question for [email protected].

Is email content encrypted at rest?

Yes. Message bodies (HTML and text) and attachments are sealed with envelope encryption before they are written: a per-message data key encrypts the content and is wrapped by the instance key, so the database holds ciphertext and a wrapped key. The wrapping key lives outside the database — the environment master key, or AWS KMS when configured. Recipients, subject and delivery events are stored as rows rather than secrets, and they age out on the retention window below.

Is MepMail SOC 2 compliant?

Not today. SOC 2 and ISO 27001 are on the roadmap, no auditor is engaged and no date is announced. Until then, hold us to the control list on this page — and because the product is open source, you can verify those controls yourself instead of relying on a report.

Is MepMail GDPR compliant?

MepMail Cloud is built for it: the application and its database run in Germany, inside the EU. Two subprocessors sit in the United States — Amazon SES (us-east-1) for delivery and Stripe for payments — and the Privacy Policy states those transfers. We do not claim a certification we do not hold.

How do I get a signed DPA?

There is no pre-signed DPA published today: write to [email protected] with your legal entity and it is agreed per customer. Self-hosting removes the question entirely — the processing agreement is then between you and your own infrastructure.

Where is my data stored, and does it stay in the EU?

MepMail Cloud: the application and its database in Germany; delivery events with Amazon SES in us-east-1; DNS and network protection through Cloudflare's global edge. The table above lists every provider and its role. A self-hosted instance stores everything wherever you deploy it.

How long is email data retained?

Message bodies and attachments leave on the team's retention window — 30 days by default — and the row is stamped when it is purged. Recipients, subject, status and events age out on the same window, as do webhook delivery records. Nightly backups are pruned after 14 days.

How do I delete a contact's data?

Delete the contact with erase=true on the API: the address is then erased from email history, event payloads and API logs — the GDPR/LGPD path. Without it, the send log ages out with the retention window. Suppressions keep only a hash of the address, as the do-not-contact record. API reference

Do AI or model subprocessors receive my email content?

No. No AI provider processes your email content on MepMail Cloud. The open-source code ships an optional abuse monitor (ABUSE_JUDGE, off by default), which a self-hoster can turn on: an already-accepted send may then be sampled and sent to TypeSafe System One for an abuse verdict. MepMail Cloud runs with it off, and a self-hoster decides for themselves.

Where can I find the current subprocessor list?

On this page — the table above, which mirrors the Privacy Policy. A self-hosted instance has no such list, because it runs on infrastructure you choose.

Report

Responsible disclosure

Found a vulnerability? Tell us and we will fix it — that is the same standard the code is held to.

  • Email [email protected] with the details and, if you have one, a reproduction.
  • We acknowledge the report and give a first answer within 72 hours.
  • There is no bug bounty today — we will credit you publicly if you want the credit.
  • Please give us a reasonable window to fix the issue before publishing it; we will tell you what we are doing along the way.

Email [email protected]

Connect a domain and send in minutes

Create an account, add your sending domain and publish the DKIM and MAIL FROM records the panel returns. If you would rather audit first, the source and the docs are open — both are one click away.