An audit named your mail vendor
A GDPR, ISO 27001 or SOC 2 exercise lists a US processor in your email path, and the finding lands on the DPO’s desk with a remediation date attached.
EU transactional email infrastructure
Postvow delivers your transactional mail from infrastructure we run inside the EU, under a DPA whose email-content subprocessor list is empty. You are not comparing us to a bulk sender on price per thousand — you are comparing us to keeping the US vendor, paying a law firm €5,000–15,000 for transfer paperwork, carrying the Schrems II risk and hoping the auditor accepts it.
Evaluations are founder-led: a short call, then a live send from your own domain. There is no sign-up form on this page — see “Why there is no form” below.
When people call us
Five moments account for almost every conversation we have. If none of them describe your week, this is probably not urgent for you yet — and we will say so on the call.
A GDPR, ISO 27001 or SOC 2 exercise lists a US processor in your email path, and the finding lands on the DPO’s desk with a remediation date attached.
You are inside the 24-hour early warning and the 72-hour notification window, and someone has to answer whether the notification mail actually left your infrastructure and reached the recipient’s server.
A hospital, clinic or bank now requires an EU-only supply chain for anything touching patient or account data — including the notification emails you send on their behalf.
Your enterprise prospect’s security review stopped at your email provider. You are not the one with the compliance problem — you inherited your vendor’s.
The SendGrid or Brevo invoice went up, and this time somebody in the room asked what happens to message metadata when a US authority issues an order.
What you actually get
Not a badge and not a promise about the future — four things that exist today and that a reviewer can check against our DPA, our DNS and our API.
Live in production
No third party processes the content of your messages. Delivery runs on our own mail infrastructure in Germany, operated by us on dedicated capacity from Hetzner Online GmbH; DNS for this website is served by Cloudflare, a US company subject to the CLOUD Act. Both appear on the public subprocessor list — that list is the claim we make, and it is deliberately narrower than a blanket statement about having no processors at all, which would not be true of us or of anyone running on the internet.
Live in production
The DPA is generated per customer, and every optional module you switch on declares its own annex entry. Exactly one module on the price list adds a subprocessor, and the pricing page names it and says so there — before you buy it, not after.
Live in production
Postvow speaks the same two interfaces you already use: an HTTP send API and an SMTP relay. Point your existing client at our endpoint, publish two DNS records, send. No rewrite of your notification code.
Live, with a stated caveat
We sign with DKIM from your own sending domain and walk you through the SPF and DMARC records, including a policy that actually rejects. One caveat we state rather than hide: for a subdomain sending name, receivers resolve policy through the RFC 9989 tree walk, and our own checker does not yet perform that walk — so treat our DMARC reporting on subdomains as advisory.
Proof of delivery
Every message carries a status you can read from the API and show to whoever is asking. What that status is worth depends on which stage it reached, so we label the stages instead of collapsing them into one green tick.
accepted-by-MTA Live in production
The receiving mail server accepted the message over an authenticated, TLS-protected connection. Recorded from our own SMTP transcript, with the timestamp and the remote server’s response.
delivered Live in production
The receiving side completed the transaction without a bounce or a deferral inside the retry window. This is the strongest signal any sender can obtain without the recipient’s cooperation.
read Live in production
The recipient opened the message. Useful as a signal, weak as evidence — image blocking, privacy proxies and preview panes all distort it, and we would rather tell you that than sell it as proof.
This is operational proof: it answers an operations question and it holds up in an audit conversation. It is not the cryptographic article. The signed, independently verifiable audit trail — per-message hashes anchored in a daily signed root — is a separate paid module that is specified and priced but not built yet, and it is labelled as such in the price list. We do not describe it as available, and we make no claim about how any of this would be treated in litigation — that judgement belongs to a lawyer looking at a specific case, not to a vendor’s website.
Migration
The technical gatekeeper on the call usually asks one question: how much of my code changes? The answer is normally none.
The API surface is published as a live OpenAPI document rather than a PDF, so your engineers can read the real contract before any call with us: https://api.postvow.eu/v1/openapi.json
Pricing
The price is for compliance posture and proof, not for volume of mail — so it is a flat monthly figure, and you will not find a per-thousand rate anywhere on this page. Sovereign is the tier most regulated customers land on.
€0
1,000–3,000 messages / month
Evaluation, development and deliverability hygiene.
No audit package.
Request an evaluation€149 — per month, or €1,490 per year
50,000 messages / month
A single EU SaaS getting its first clean DPA in place.
Operational proof — three-tier delivery status.
Talk to us€349 — per month, or €3,490 per year
250,000 messages / month
Regulated B2B2B — health-tech, patient communications, fintech.
Operational proof plus the audit package.
Talk to us€749 — per month
1,000,000 messages / month
Higher-volume health-tech and fintech senders.
Operational proof; eligible for the audit-grade module when it ships.
Talk to usCustom — typically from €1,500 per month
Committed volume
Your paper, your terms, your retention schedule.
Negotiated.
Talk to usCritical mail always arrives — even over the limit. You pay for the excess, not for a dropped OTP.
Annual billing costs two months less than paying monthly — about 16.7%. Invoicing is by bank transfer in euro against a Polish VAT invoice; there is no US payment intermediary in the chain.
On Sovereign Pro, 99.95% is an availability target we operate to and report against. There is no service-credit mechanism behind it yet — that machinery is on the backlog, and until it exists we are not going to imply a contractual remedy that we could not honour. Enterprise terms are negotiated individually.
Contact
Did an auditor, a customer or a security review flag a non-EU subprocessor in your email path? If yes, write to us and say which one — we will tell you within a day whether we can remove it and what it costs. If no, we would rather say so plainly than take the meeting: without that trigger there is usually nothing here for you yet, and a polite “not now” costs us both less than a demo.
Useful things to put in the first message: who raised the finding, which provider is in the path today, roughly how many messages you send a month, and your deadline.
Why there is no form: a contact form on a public page means processing personal data, a lawful basis, a retention rule, a register entry and an endpoint open to anonymous traffic. We sell data minimisation, so we start by applying it here. Plain email is enough for a founder-led evaluation.