Five sites.
One network.
A core ring across Falkenstein, Nuremberg and Helsinki, with Oslo and Sofia uplinked into it.
SECURITY FEATURES
Built to keep your email and your data safe
Every account gets the same security features, on every plan.
Two-factor authentication, enforced
Protect your account with TOTP-based 2FA, and require it for your whole team with account-wide enforcement.
Learn moreSingle sign-on
Log in through your own identity provider with OpenID Connect SSO, including PKCE and multi-domain support.
Learn moreScoped API keys
Restrict every API key to specific domains and granular permissions, so a leaked key for one service cannot touch anything else.
Learn moreIP allow lists
Lock any API key to the IPv4/IPv6 addresses or CIDR ranges you specify. Changing an allow list requires re-authentication and alerts your admins.
Learn moreSigned webhooks
All webhooks follow the Standard Webhooks specification with HMAC signatures and timestamps, so your endpoints can verify every event.
Learn moreSandbox mode
Test your full integration, including bounces and webhooks, without a single real email leaving the platform.
Learn moreYou decide how long we keep your data
Message metadata for 1 to 30 days, full message content anywhere from 30 days down to zero.
Learn moreOur infrastructure is
the security feature
Most email providers build on a hyperscaler and inherit its control plane, its shared tenancy and its legal exposure. We run on bare metal in European datacenters, on our own network, with our own IP space and AS number. Running the full stack ourselves means we control the operating system, patching, hardening and monitoring on every server. The answer to "where is my email data stored?" is one sentence: in Germany and Finland, under our control, with every party that touches it named in our DPA.
Dedicated servers in European datacenters, on our own network with our own ASN and IP ranges. No hyperscaler, no shared control plane.
Our datacenter providers are the only parties with a role in handling your mail. All are EU/EEA companies, all listed in our DPA, none hidden behind a reseller.
We install, patch and harden every server ourselves. Delivery is TLS-secured and our status is always public at status.ahasend.com.
Where your data is stored
All email content, message data, metadata, logs and analytics are stored in the EU, on bare metal servers we operate in our core sites in Falkenstein, Nuremberg and Helsinki. Our Oslo and Sofia sites are transit only: mail passes through on its way to the recipient and is not retained there. Oslo is why we say EU/EEA rather than EU. Two exceptions, in the interest of full transparency: (1) The nameservers for ahasend.com itself are currently at Cloudflare. That affects DNS resolution of our website, not your email data or any of our endpoints. A migration is planned. (2) An optional US node exists. It is strictly opt-in and never used unless you explicitly choose it. Decommission is planned.
COMPLIANCE
Compliance, in writing
GDPR
AhaSend is a European company under European law. Our Data Processing Agreement is public, ready to sign, and doesn't hide a US parent behind an EU letterbox.
CSA Certified Sender
AhaSend is certified by the Certified Senders Alliance, the sender accreditation programme run with eco and the German mailbox providers.
ISO 27001
Our Phase 2 certification audit was completed in September 2026 and the certificate is expected in early October. Our Trust Center shows the current status, our controls and our policies.
Subprocessors
The full list of subprocessors is published in our DPA: Hetzner, DA International Group Ltd, and Blix. Running our own stack means the list stays short.
Responsible disclosure
Found a vulnerability? We have a published responsible disclosure policy and we respond fast.
See for yourself
The Trust Center has the documents. The free tier has 1,000 emails a month. Your security team can read while your developers send.