Trust Center

Security controls you can quote.
No invented certificates.

MailerZ publishes the controls it actually runs. SOC 2, ISO 27001, and HIPAA are not certified. Do not treat this page as an audit report.

Domain verification required Not an open relay Not SOC 2 / ISO / HIPAA

What MailerZ is

MailerZ is a custom-domain email delivery layer operated by Secuno LLC. It accepts inbound mail for verified domains, forwards it to an inbox the customer already uses, and can send through authenticated SMTP. It is not a mailbox host, IMAP store, webmail suite, campaign sender, or certified compliance platform.

Controls that exist

ControlWhat it does
Domain verificationReceiving and sending stay off until the domain owner publishes the required records.
No open relayUnauthenticated users cannot send through MailerZ. Unhosted or unauthorized recipients receive SMTP 550.
Store before acceptanceRequired message content and metadata are stored before MailerZ returns SMTP 250.
Authenticated SMTPOutbound connections require credentials scoped to approved domain identities.
Transport encryptionTLS is used where the communicating server or client supports current mechanisms.
Leftover MX detectionCompeting Google, Microsoft, or host MX records are surfaced before they silently split inbound mail.
Delivery evidenceAcceptance, routing attempts, holds, and destination SMTP responses remain visible in delivery history.
Restricted accessMessage-body access and important account actions are limited and logged.

Certifications we do not claim

FrameworkStatusNote
SOC 2 Type I / Type IINoA control description is published. No auditor report is claimed.
ISO/IEC 27001NoNo ISO certificate is issued or displayed.
HIPAA / BAANoMailerZ is not offered as a HIPAA covered-entity or business-associate product.
Penetration-test badgeNo public badgeResponsible disclosure is accepted at support@mailerz.net.

SOC 2-style questionnaire

These answers match the published Privacy Policy, DPA, Subprocessors, and Digital Security Policy. Recheck those documents if you need contract language.

QuestionCurrent answer
Legal entitySecuno LLC operates MailerZ. Company information is at secuno.net.
Data rolesMailerZ is controller for account, billing, website, support, and service-security data. For message content processed on customer instructions, the customer is generally controller and MailerZ is processor. See the DPA.
Data processedAccount identifiers, domain and route configuration, envelope and header metadata, message content when needed to forward or recover, delivery responses, authentication events, and support correspondence.
RetentionMessage recovery follows the plan window: 14 days on Free, 90 days on paid plans, unless deleted earlier or preserved for security or legal reasons.
SubprocessorsInfrastructure, payment, transactional email, support, and security providers. Cloudflare may deliver the marketing site. The current category list is on /subprocessors.
Encryption in transitTLS is used for supported SMTP, HTTPS, and dashboard sessions. Older peers may negotiate weaker or no encryption.
Encryption at restOperational stores use provider and application controls appropriate to the service. Exact key-management details that would weaken security are not published.
Access controlLeast-privilege operational access, authentication on SMTP and the dashboard, and recorded privileged actions.
Logging and monitoringAuthentication, configuration, delivery, and security events are recorded for operations, abuse, and support.
Incident noticeConfirmed personal-data breaches affecting customer data are notified without undue delay as required by the DPA and applicable law.
Customer dutiesProtect registrar, DNS, inbox, SMTP, and team credentials. Remove leftover MX. Honor anti-spam and acceptable-use rules.
Right to auditThe DPA allows reasonably necessary information, reports, questionnaires, or a scoped confidential audit. A public SOC 2 report is not available.

Is MailerZ SOC 2 certified?

No. MailerZ is not SOC 2 Type I or Type II certified. It is also not ISO 27001 or HIPAA certified. Do not treat marketing language as a certification.

What security controls does MailerZ actually run?

Receiving and sending activate only after domain verification. SMTP credentials send only through approved identities. Incoming mail is stored before SMTP 250. The service is not an open relay. Operational access to message content is restricted and recorded.

Where are privacy and processor terms?

Privacy Policy, Data Processing Addendum, Subprocessors, GDPR, and Digital Security Policy are published on mailerz.net. Security reports go to support@mailerz.net with the subject Security Report.

Related documents: Privacy, DPA, Subprocessors, Digital Security Policy, GDPR, Contact.

Ask for the current control set, not a badge.

Security reports: support@mailerz.net, subject “Security Report.” Sales diligence uses this page plus the DPA.

Start free