EU transactional email infrastructure

Your auditor flagged the mail vendor. This is the answer.

Postvow delivers your transactional mail from infrastructure we run inside the EU, under a DPA whose email-content subprocessor list is empty. You are not comparing us to a bulk sender on price per thousand — you are comparing us to keeping the US vendor, paying a law firm €5,000–15,000 for transfer paperwork, carrying the Schrems II risk and hoping the auditor accepts it.

Evaluations are founder-led: a short call, then a live send from your own domain. There is no sign-up form on this page — see “Why there is no form” below.

When people call us

Nobody shops for a mail vendor. They arrive with a problem.

Five moments account for almost every conversation we have. If none of them describe your week, this is probably not urgent for you yet — and we will say so on the call.

An audit named your mail vendor

A GDPR, ISO 27001 or SOC 2 exercise lists a US processor in your email path, and the finding lands on the DPO’s desk with a remediation date attached.

An incident started the NIS2 clock

You are inside the 24-hour early warning and the 72-hour notification window, and someone has to answer whether the notification mail actually left your infrastructure and reached the recipient’s server.

A regulated customer set the terms

A hospital, clinic or bank now requires an EU-only supply chain for anything touching patient or account data — including the notification emails you send on their behalf.

Your own deal stalled on mail due diligence

Your enterprise prospect’s security review stopped at your email provider. You are not the one with the compliance problem — you inherited your vendor’s.

A renewal arrived with fresh CLOUD Act awareness

The SendGrid or Brevo invoice went up, and this time somebody in the room asked what happens to message metadata when a US authority issues an order.

What you actually get

A mail path you can put in front of an auditor.

Not a badge and not a promise about the future — four things that exist today and that a reviewer can check against our DPA, our DNS and our API.

Zero email-content subprocessors

Live in production

No third party processes the content of your messages. Delivery runs on our own mail infrastructure in Germany, operated by us on dedicated capacity from Hetzner Online GmbH; DNS for this website is served by Cloudflare, a US company subject to the CLOUD Act. Both appear on the public subprocessor list — that list is the claim we make, and it is deliberately narrower than a blanket statement about having no processors at all, which would not be true of us or of anyone running on the internet.

A DPA with an empty content-processor annex

Live in production

The DPA is generated per customer, and every optional module you switch on declares its own annex entry. Exactly one module on the price list adds a subprocessor, and the pricing page names it and says so there — before you buy it, not after.

Migration is a credential swap

Live in production

Postvow speaks the same two interfaces you already use: an HTTP send API and an SMTP relay. Point your existing client at our endpoint, publish two DNS records, send. No rewrite of your notification code.

DKIM, SPF and DMARC set up with you

Live, with a stated caveat

We sign with DKIM from your own sending domain and walk you through the SPF and DMARC records, including a policy that actually rejects. One caveat we state rather than hide: for a subdomain sending name, receivers resolve policy through the RFC 9989 tree walk, and our own checker does not yet perform that walk — so treat our DMARC reporting on subdomains as advisory.

Proof of delivery

Three answers to “did it arrive?”, and an honest line about the fourth.

Every message carries a status you can read from the API and show to whoever is asking. What that status is worth depends on which stage it reached, so we label the stages instead of collapsing them into one green tick.

The three stages we report today

  1. accepted-by-MTA

    Live in production

    The receiving mail server accepted the message over an authenticated, TLS-protected connection. Recorded from our own SMTP transcript, with the timestamp and the remote server’s response.

  2. delivered

    Live in production

    The receiving side completed the transaction without a bounce or a deferral inside the retry window. This is the strongest signal any sender can obtain without the recipient’s cooperation.

  3. read

    Live in production

    The recipient opened the message. Useful as a signal, weak as evidence — image blocking, privacy proxies and preview panes all distort it, and we would rather tell you that than sell it as proof.

This is operational proof: it answers an operations question and it holds up in an audit conversation. It is not the cryptographic article. The signed, independently verifiable audit trail — per-message hashes anchored in a daily signed root — is a separate paid module that is specified and priced but not built yet, and it is labelled as such in the price list. We do not describe it as available, and we make no claim about how any of this would be treated in litigation — that judgement belongs to a lawyer looking at a specific case, not to a vendor’s website.

Migration

From your current provider in an afternoon.

The technical gatekeeper on the call usually asks one question: how much of my code changes? The answer is normally none.

  1. We create your tenant and a sending stream, and issue machine credentials for your service.
  2. You publish two DKIM records and adjust SPF for your sending domain; we check the DMARC policy with you before the first send.
  3. You point your existing HTTP client or SMTP configuration at Postvow — the same call your code already makes, with a different endpoint and key.
  4. You send a live message from your own domain and read its status back through the API.
  5. We hand over the generated DPA with the module annexes matching exactly what you switched on.

The API surface is published as a live OpenAPI document rather than a PDF, so your engineers can read the real contract before any call with us: https://api.postvow.eu/v1/openapi.json

Pricing

Flat monthly price. Published numbers.

The price is for compliance posture and proof, not for volume of mail — so it is a flat monthly figure, and you will not find a per-thousand rate anywhere on this page. Sovereign is the tier most regulated customers land on.

Free

€0

1,000–3,000 messages / month

Evaluation, development and deliverability hygiene.

  • Full send API and SMTP relay
  • DKIM signing from your own domain
  • Three-tier delivery status
  • No audit package, no per-module DPA annexes

No audit package.

Request an evaluation

Starter

€149 — per month, or €1,490 per year

50,000 messages / month

A single EU SaaS getting its first clean DPA in place.

  • DPA with an empty email-content subprocessor list
  • Three-tier delivery status reporting
  • Dedicated sending domain configuration with us
  • Email support from the people who run the infrastructure

Operational proof — three-tier delivery status.

Talk to us

Sovereign

€349 — per month, or €3,490 per year

250,000 messages / month

Regulated B2B2B — health-tech, patient communications, fintech.

  • Everything in Starter
  • Audit package: the evidence set your reviewer asks for
  • Per-module DPA annexes for every optional module
  • Add-on modules available

Operational proof plus the audit package.

Talk to us

Sovereign Pro

€749 — per month

1,000,000 messages / month

Higher-volume health-tech and fintech senders.

  • Everything in Sovereign
  • 99.95% availability target
  • Eligible for the audit-grade provable delivery module Roadmap — not built
  • Priority incident handling

Operational proof; eligible for the audit-grade module when it ships.

Talk to us

Enterprise

Custom — typically from €1,500 per month

Committed volume

Your paper, your terms, your retention schedule.

  • Your own DPA rather than ours
  • Bespoke retention and data-handling terms
  • Dedicated commercial terms
  • Named contacts on both sides

Negotiated.

Talk to us

Critical mail always arrives — even over the limit. You pay for the excess, not for a dropped OTP.

Annual billing costs two months less than paying monthly — about 16.7%. Invoicing is by bank transfer in euro against a Polish VAT invoice; there is no US payment intermediary in the chain.

On Sovereign Pro, 99.95% is an availability target we operate to and report against. There is no service-credit mechanism behind it yet — that machinery is on the backlog, and until it exists we are not going to imply a contractual remedy that we could not honour. Enterprise terms are negotiated individually.

Contact

One question decides whether this call is worth your time.

Did an auditor, a customer or a security review flag a non-EU subprocessor in your email path? If yes, write to us and say which one — we will tell you within a day whether we can remove it and what it costs. If no, we would rather say so plainly than take the meeting: without that trigger there is usually nothing here for you yet, and a polite “not now” costs us both less than a demo.

Useful things to put in the first message: who raised the finding, which provider is in the path today, roughly how many messages you send a month, and your deadline.

Why there is no form: a contact form on a public page means processing personal data, a lawful basis, a retention rule, a register entry and an endpoint open to anonymous traffic. We sell data minimisation, so we start by applying it here. Plain email is enough for a founder-led evaluation.