EU transactional email infrastructure

Your auditor flagged the mail vendor. This is the answer.

Postvow delivers your transactional mail from infrastructure we run inside the EU, under a DPA whose email-content subprocessor list is empty. You are not comparing us to a bulk sender on price per thousand — you are comparing us to keeping the US vendor, paying a law firm €5,000–15,000 for transfer paperwork, carrying the Schrems II risk and hoping the auditor accepts it.

Evaluations are founder-led: a short call, then a live send from your own domain. There is no sign-up form on this page — see “Why there is no form” below.

When people call us

Nobody shops for a mail vendor. They arrive with a problem.

Five moments account for almost every conversation we have. If none of them describe your week, this is probably not urgent for you yet — and we will say so on the call.

An audit named your mail vendor

A GDPR, ISO 27001 or SOC 2 exercise lists a US processor in your email path, and the finding lands on the DPO’s desk with a remediation date attached.

An incident started the NIS2 clock

You are inside the 24-hour early warning and the 72-hour notification window, and someone has to answer whether the notification mail actually left your infrastructure and reached the recipient’s server.

A regulated customer set the terms

A hospital, clinic or bank now requires an EU-only supply chain for anything touching patient or account data — including the notification emails you send on their behalf.

Your own deal stalled on mail due diligence

Your enterprise prospect’s security review stopped at your email provider. You are not the one with the compliance problem — you inherited your vendor’s.

A renewal arrived with fresh CLOUD Act awareness

The SendGrid or Brevo invoice went up, and this time somebody in the room asked what happens to message metadata when a US authority issues an order.

What you actually get

A mail path you can put in front of an auditor.

Not a badge and not a promise about the future — four things that exist today and that a reviewer can check against our DPA, our DNS and our API.

Zero email-content subprocessors

Live in production

No third party processes the content of your messages. Delivery runs on our own mail infrastructure in Germany, operated by us on dedicated capacity from Hetzner Online GmbH; DNS for this website is served by Cloudflare, a US company subject to the CLOUD Act. Both appear on the public subprocessor list — that list is the claim we make, and it is deliberately narrower than a blanket statement about having no processors at all, which would not be true of us or of anyone running on the internet.

A DPA with an empty content-processor annex

Live in production

The DPA is generated per customer, and every optional module you switch on declares its own annex entry. Exactly one module on the price list adds a subprocessor, and the pricing page names it and says so there — before you buy it, not after.

Migration is a credential swap

Live in production

Postvow speaks the same two interfaces you already use: an HTTP send API and an SMTP relay. Point your existing client at our endpoint, publish two DNS records, send. No rewrite of your notification code.

DKIM, SPF and DMARC set up with you

Live in production

We sign with DKIM from your own sending domain and walk you through the SPF and DMARC records, including a policy that actually rejects. Two caveats we state rather than hide. First: we sign every message twice, RSA-2048 and Ed25519 (RFC 8463), because support for the newer algorithm is not universal — Gmail does not implement it and treats that signature as an unknown algorithm, which is precisely why the RSA one is there. Which signature a given receiver actually accepted is something we read from that receiver’s own Authentication-Results header and from nowhere else; a key published in DNS is not evidence that anyone verified anything, and we will not report it to you as though it were. Second: for a subdomain sending name, receivers resolve policy through the RFC 9989 tree walk, and the checker on our domain-verification path does not yet perform that walk — so treat our DMARC reporting on subdomains as advisory.

The rest of the surface

There is more here than send and status.

Everything here you can call today with the key we issue you, and every path below is in the OpenAPI document generated from the running code — so you can check the contract before you talk to us.

A sandbox that sends nowhere

Live in production

A test key captures messages instead of delivering them, and you read them back through the API and clear them when you are done — /v1/sandbox/messages. Integration tests that exercise your real notification code, against the real API, without a single message reaching a real person — and without spending your sending reputation to find out that a template was broken.

A deliverability score, before and after

Live in production

Score a message before you send it and get back what would hurt it, or read the current score for your domain and its history over time: /v1/score and /v1/score/history. This is the check that catches an authentication or content problem while it is still a staging problem.

Reputation weather and forecast

Live in production

A current read on how your sending domain is doing, and a forward-looking one — /v1/weather/{domain} and /v1/forecast/{domain}. Useful when volume is about to change — a campaign, a migration, a new sending IP coming out of warm-up — and you would rather know before the bounce rate tells you.

A migration diff for your existing code

Live in production

Post the code that calls your current provider and get back the specific differences against the Postvow call, from /v1/tools/migration-diff. It is the same answer we would give on the call, except your engineers can get it without one.

The full contract, generated from the running code rather than written by hand: https://api.postvow.eu/v1/openapi.json

Proof of delivery

Three answers to “did it arrive?”, and an honest line about the fourth.

Every message carries a status you can read from the API and show to whoever is asking. What that status is worth depends on which stage it reached, so we label the stages instead of collapsing them into one green tick.

The three stages we report today

  1. accepted-by-MTA

    Live in production

    The receiving mail server accepted the message over an authenticated, TLS-protected connection. Recorded from our own SMTP transcript, with the timestamp and the remote server’s response.

  2. delivered

    Live in production

    The receiving side completed the transaction without a bounce or a deferral inside the retry window. This is the strongest signal any sender can obtain without the recipient’s cooperation.

  3. read

    Live in production

    The recipient opened the message. Useful as a signal, weak as evidence — image blocking, privacy proxies and preview panes all distort it, and we would rather tell you that than sell it as proof.

This is operational proof: it answers an operations question and it holds up in an audit conversation. It is not the cryptographic article. The signed, independently verifiable audit trail — per-message hashes anchored in a daily signed root — is a separate paid module that is specified and priced but not built yet, and it is labelled as such in the price list. We do not describe it as available, and we make no claim about how any of this would be treated in litigation — that judgement belongs to a lawyer looking at a specific case, not to a vendor’s website.

Migration

From your current provider in an afternoon.

The technical gatekeeper on the call usually asks one question: how much of my code changes? The answer is normally none.

  1. We create your tenant and a sending stream, and issue machine credentials for your service.
  2. You publish two DKIM records and adjust SPF for your sending domain; before the first send we check that the DKIM delegation chain resolves in DNS, and we walk the DMARC policy with you. The signature itself is a separate control, validated against an independent DKIM implementation in our release pipeline rather than at your DNS.
  3. You point your existing HTTP client or SMTP configuration at Postvow — the same call your code already makes, with a different endpoint and key.
  4. You send a live message from your own domain and read its status back through the API.
  5. We hand over the generated DPA with the module annexes matching exactly what you switched on.

The API surface is published as a live OpenAPI document rather than a PDF, so your engineers can read the real contract before any call with us: https://api.postvow.eu/v1/openapi.json

Pricing

Flat monthly price. Published numbers.

The price is for compliance posture and proof, not for volume of mail — so it is a flat monthly figure, and you will not find a per-thousand rate anywhere on this page. Sovereign is the tier most regulated customers land on.

Free

€0

1,000–3,000 messages / month

Evaluation, development and deliverability hygiene.

  • Full send API and SMTP relay
  • DKIM signing from your own domain
  • Three-tier delivery status
  • No audit package, no per-module DPA annexes

No audit package.

Request an evaluation

Starter

€149 — per month

or €1,490 per year

50,000 messages / month

A single EU SaaS getting its first clean DPA in place.

  • DPA with an empty email-content subprocessor list
  • Three-tier delivery status reporting
  • Dedicated sending domain configuration with us
  • Email support from the people who run the infrastructure

Operational proof — three-tier delivery status.

Talk to us

Sovereign

€349 — per month

or €3,490 per year

250,000 messages / month

Regulated B2B2B — health-tech, patient communications, fintech.

  • Everything in Starter
  • Audit package: the evidence set your reviewer asks for
  • Per-module DPA annexes for every optional module
  • Add-on modules available

Operational proof plus the audit package.

Talk to us

Sovereign Pro

€749 — per month

or €7,490 per year

1,000,000 messages / month

Higher-volume health-tech and fintech senders.

  • Everything in Sovereign
  • 99.95% availability target
  • Eligible for the audit-grade provable delivery module On the roadmap
  • Priority incident handling

Operational proof; eligible for the audit-grade module when it ships.

Talk to us

Enterprise

Custom — typically from €1,500 per month

Committed volume

Your paper, your terms, your retention schedule.

  • Your own DPA rather than ours
  • Bespoke retention and data-handling terms
  • Dedicated commercial terms
  • Named contacts on both sides

Negotiated.

Talk to us

Critical mail always arrives — even over the limit. You pay for the excess, not for a dropped OTP.

Annual billing costs two months less than paying monthly — about 16.7%. Invoicing is by bank transfer in euro against a Polish VAT invoice; there is no US payment intermediary in the chain.

On Sovereign Pro, 99.95% is an availability target we operate to and report against. There is no service-credit mechanism behind it — that mechanism does not exist yet, and until it does we are not going to imply a contractual remedy that we could not honour. Enterprise terms are negotiated individually.

Contact

One question decides whether this call is worth your time.

Did an auditor, a customer or a security review flag a non-EU subprocessor in your email path? If yes, write to us and say which one — we will tell you within a day whether we can remove it and what it costs. If no, we would rather say so plainly than take the meeting: without that trigger there is usually nothing here for you yet, and a polite “not now” costs us both less than a demo.

Useful things to put in the first message: who raised the finding, which provider is in the path today, roughly how many messages you send a month, and your deadline.

Why there is no form: a contact form on a public page means processing personal data, a lawful basis, a retention rule, a register entry and an endpoint open to anonymous traffic. We sell data minimisation, so we start by applying it here. Plain email is enough for a founder-led evaluation.