Is MailerZ SOC 2 certified?
No. MailerZ is not SOC 2 Type I or Type II certified. It is also not ISO 27001 or HIPAA certified. Do not treat marketing language as a certification.
Trust Center
MailerZ publishes the controls it actually runs. SOC 2, ISO 27001, and HIPAA are not certified. Do not treat this page as an audit report.
MailerZ is a custom-domain email delivery layer operated by Secuno LLC. It accepts inbound mail for verified domains, forwards it to an inbox the customer already uses, and can send through authenticated SMTP. It is not a mailbox host, IMAP store, webmail suite, campaign sender, or certified compliance platform.
| Control | What it does |
|---|---|
| Domain verification | Receiving and sending stay off until the domain owner publishes the required records. |
| No open relay | Unauthenticated users cannot send through MailerZ. Unhosted or unauthorized recipients receive SMTP 550. |
| Store before acceptance | Required message content and metadata are stored before MailerZ returns SMTP 250. |
| Authenticated SMTP | Outbound connections require credentials scoped to approved domain identities. |
| Transport encryption | TLS is used where the communicating server or client supports current mechanisms. |
| Leftover MX detection | Competing Google, Microsoft, or host MX records are surfaced before they silently split inbound mail. |
| Delivery evidence | Acceptance, routing attempts, holds, and destination SMTP responses remain visible in delivery history. |
| Restricted access | Message-body access and important account actions are limited and logged. |
| Framework | Status | Note |
|---|---|---|
| SOC 2 Type I / Type II | No | A control description is published. No auditor report is claimed. |
| ISO/IEC 27001 | No | No ISO certificate is issued or displayed. |
| HIPAA / BAA | No | MailerZ is not offered as a HIPAA covered-entity or business-associate product. |
| Penetration-test badge | No public badge | Responsible disclosure is accepted at support@mailerz.net. |
These answers match the published Privacy Policy, DPA, Subprocessors, and Digital Security Policy. Recheck those documents if you need contract language.
| Question | Current answer |
|---|---|
| Legal entity | Secuno LLC operates MailerZ. Company information is at secuno.net. |
| Data roles | MailerZ is controller for account, billing, website, support, and service-security data. For message content processed on customer instructions, the customer is generally controller and MailerZ is processor. See the DPA. |
| Data processed | Account identifiers, domain and route configuration, envelope and header metadata, message content when needed to forward or recover, delivery responses, authentication events, and support correspondence. |
| Retention | Message recovery follows the plan window: 14 days on Free, 90 days on paid plans, unless deleted earlier or preserved for security or legal reasons. |
| Subprocessors | Infrastructure, payment, transactional email, support, and security providers. Cloudflare may deliver the marketing site. The current category list is on /subprocessors. |
| Encryption in transit | TLS is used for supported SMTP, HTTPS, and dashboard sessions. Older peers may negotiate weaker or no encryption. |
| Encryption at rest | Operational stores use provider and application controls appropriate to the service. Exact key-management details that would weaken security are not published. |
| Access control | Least-privilege operational access, authentication on SMTP and the dashboard, and recorded privileged actions. |
| Logging and monitoring | Authentication, configuration, delivery, and security events are recorded for operations, abuse, and support. |
| Incident notice | Confirmed personal-data breaches affecting customer data are notified without undue delay as required by the DPA and applicable law. |
| Customer duties | Protect registrar, DNS, inbox, SMTP, and team credentials. Remove leftover MX. Honor anti-spam and acceptable-use rules. |
| Right to audit | The DPA allows reasonably necessary information, reports, questionnaires, or a scoped confidential audit. A public SOC 2 report is not available. |
No. MailerZ is not SOC 2 Type I or Type II certified. It is also not ISO 27001 or HIPAA certified. Do not treat marketing language as a certification.
Receiving and sending activate only after domain verification. SMTP credentials send only through approved identities. Incoming mail is stored before SMTP 250. The service is not an open relay. Operational access to message content is restricted and recorded.
Privacy Policy, Data Processing Addendum, Subprocessors, GDPR, and Digital Security Policy are published on mailerz.net. Security reports go to support@mailerz.net with the subject Security Report.
Related documents: Privacy, DPA, Subprocessors, Digital Security Policy, GDPR, Contact.
Security reports: support@mailerz.net, subject “Security Report.” Sales diligence uses this page plus the DPA.