Secure Email for Regulated SaaS
Email Delivery for a Security Review
Regulated SaaS teams need more than a sending API. They need clear ownership, auditable configuration, data-processing documentation, and a security-review process that describes the product as it is today.
ApexMail provides security and privacy workflows around email delivery, including access controls, audit-capable plans, data-subject request tooling, and current documentation for procurement review.
Audit and Access Controls
Scale and Enterprise include runtime identity and audit features. Configuration and operational ownership remain the customer’s responsibility.
Current Compliance Position
GDPR-oriented processing documentation and a DPA are available. HIPAA availability and SOC 2 certification are not currently offered.
Security Review
Qualified prospects can request current documentation and discuss the scope of any contractual security or deployment commitment.
What We Can Confirm
| Area | Current position |
|---|---|
| Data-processing documentation | DPA and subprocessor information are available for review |
| Identity and audit capabilities | Plan-gated runtime features; SAML SSO starts on Scale |
| Enterprise review | Contractual security, deployment, and operational review |
| HIPAA / BAA | Not currently offered |
| SOC 2 certification | Not currently offered; planned, not an entitlement |
Make Decisions From the Current Contract
ApexMail does not represent a planned certification, an internal workflow, or a sales conversation as a compliance entitlement. A customer should rely on the current service terms, approved DPA, and signed order form when deciding whether the service fits a regulated use case.
Talk to Us
Request a security review if the buying process requires current product, security, or data-processing information.