Skip to main content
Compliance-as-Code

The Email API With
Compliance Built In.

Stop treating compliance as an afterthought. ApexMail includes GDPR workflow APIs, HIPAA BAA lifecycle tooling, SOC 2 evidence workflows, and generated SIG, CAIQ, and HECVAT answer packs for Enterprise customers.

  • Consent tracking and management across 6 consent types
  • SIG, CAIQ, and HECVAT answer packs generated from Trust Portal evidence
  • Right-to-be-Forgotten erasure workflow with audit events

Compliance Workflows

GDPR DSR
HIPAA BAA
SIG / CAIQ
HECVAT
Enterprise security-review report generated from live controls
Built-In Compliance

Enterprise Compliance Workflows

Track audit events, manage DSR requests, record consent, and generate security-review answer packs from live evidence.

Questionnaire Automation

FrameworkGenerated OutputEvidence SourcesAudit Artifact
SIGNormalized answer packSOC 2 controls, Trust Portal docs, incidentsSHA-256 hash
CAIQCloud-control mapped answersAccess, encryption, logging, subprocessorsEvidence manifest
HECVATHigher-ed security review packHIPAA BAA state, privacy, consent, continuityMarkdown report

Audit Trail

TimestampActorActionResourceIP Address
2025-01-15 14:23:01 UTCadmin@acme.comapi_key.createkey_prod_****7f2a203.0.113.42
2025-01-15 14:18:33 UTCops@acme.comdomain.verifymail.acme.com198.51.100.8
2025-01-15 13:55:12 UTCdpo@acme.comrtbf.executeuser_****3e9f192.0.2.17
2025-01-15 13:41:07 UTCsystemwebhook.deliverwh_****a1b2

Right to Be Forgotten (RTBF)

1
Request

Data subject submits erasure request via API or dashboard

2
Verify

Identity verification and scope confirmation

3
Execute

Execute scoped erasure across configured data stores

4
Record

Log completion evidence for compliance review

Consent Ledger

SubjectPurposeStatusGrantedExpires
user_****3e9fTransactional emailActive2024-06-012025-06-01
user_****a1b2Marketing emailRevoked2024-03-15
user_****7f2aAnalytics trackingActive2024-09-202025-09-20
Auto-DPA

Data Processing Agreements on Autopilot

Prepare DPA workflows with maintained clauses, jurisdiction context, processing activities, and a signature request path for legal review.

  • Customized to your jurisdiction and processing activities
  • Includes declared processing activities
  • Standard Contractual Clauses (SCCs) included
  • Versioned and timestamped for audit trails
  • Document package available for legal review
Data Processing Agreement
Template maintained for 2026 GDPR workflows
Included Clauses:
GDPR Art. 28SCCsSub-processorsSecurity Measures

Ready to Sleep Better at Night?

ApexMail provides compliance-critical email infrastructure with GDPR workflows, SOC 2 evidence automation, HIPAA BAA lifecycle tooling, and generated SIG, CAIQ, and HECVAT answer packs.

SOC 2 Controls
Enterprise plan
GDPR DSR
Workflow APIs
HIPAA
BAA (Enterprise)
SIG / CAIQ / HECVAT
Generated packs

Security documentation, control evidence, and SIG/CAIQ/HECVAT answer packs are available during Enterprise review.
Contact compliance@apexmail.ee for a hashed security-review report.