--- title: "Five sites. One network." description: "How AhaSend secures your email: own European infrastructure, CSA Certified Sender, a signable DPA, ISO 27001 in progress, 2FA, SSO and scoped API keys." url: https://ahasend.com/security markdown_url: https://ahasend.com/security.md lang: en type: page_builder published: 2026-08-11 updated: 2026-08-27 --- # Five sites. One network. **WHERE AHASEND RUNS** A core ring across Falkenstein, Nuremberg and Helsinki, with Oslo and Sofia uplinked into it. - **5** EU / EEA sites - **4** Countries GDPR compliant · Hosted in Europe · ISO 27001 · in progress _SECURITY FEATURES_ ## Built to keep your email and your data safe Every account gets the same security features, on every plan. - **Two-factor authentication, enforced**: Protect your account with TOTP-based 2FA, and require it for your whole team with account-wide enforcement. ([Learn more](https://ahasend.com/docs/security/2fa)) - **Single sign-on**: Log in through your own identity provider with OpenID Connect SSO, including PKCE and multi-domain support. ([Learn more](https://ahasend.com/docs/security/sso)) - **Scoped API keys**: Restrict every API key to specific domains and granular permissions, so a leaked key for one service cannot touch anything else. ([Learn more](https://ahasend.com/docs/security/scoped-credentials)) - **IP allow lists**: Lock any API key to the IPv4/IPv6 addresses or CIDR ranges you specify. Changing an allow list requires re-authentication and alerts your admins. ([Learn more](https://ahasend.com/blog/restrict-your-api-keys-specific-ips-ip-allow-lists/)) - **Signed webhooks**: All webhooks follow the Standard Webhooks specification with HMAC signatures and timestamps, so your endpoints can verify every event. ([Learn more](https://ahasend.com/docs/api-reference/webhooks/security)) - **Sandbox mode**: Test your full integration, including bounces and webhooks, without a single real email leaving the platform. ([Learn more](https://ahasend.com/docs/send-api/sandbox)) - **You decide how long we keep your data**: Message metadata for 1 to 30 days, full message content anywhere from 30 days down to zero. ([Learn more](https://ahasend.com/docs/retention)) ## Our infrastructure is the security feature Most email providers rent their infrastructure and inherit its risks. We took the opposite route. Owning the full stack means we control patching, hardening, and monitoring down to the metal. The answer to "where does my email data live?" is one sentence: in Europe, on machines we own. ### Own hardware, own network European datacenters, on our own network with our own ASN. No US hyperscaler underneath. ### No hidden subprocessors Nothing sits between you and the mail server, and no foreign jurisdiction has a legal claim on your data in transit. [Learn more](https://ahasend.com/dpa) ### Monitored down to the metal We control patching and hardening; delivery is TLS-secured and our current status is always public at status.ahasend.com. ## Where your data lives All email content, message data, metadata, logs, and analytics stay within the EU and EEA (EEA because part of our infrastructure runs in Norway). Two exceptions in the interest of full transparency: (1) the nameservers for ahasend.com itself are currently at Cloudflare. That affects DNS resolution of our website, not your email data, and a migration is planned. (2) a optional US egress node exists, is strictly opt-in and never used unless you explicitly choose it. _COMPLIANCE_ ## Compliance, in writing - **GDPR**: AhaSend is a European company under European law. Our Data Processing Agreement is public, ready to sign, and doesn't hide a US parent behind an EU letterbox. [Learn more](https://ahasend.com/dpa) - **CSA Certified Sender**: AhaSend is certified by the Certified Senders Alliance, the sender accreditation programme run with eco and the German mailbox providers. [Learn more](https://certified-senders.org/certificate/?id=8527228af85c77463bc7668b7d4f628f) - **ISO 27001**: Our certification audit is scheduled for September 2026, and we're doing it transparently: our Trust Center shows the current status, our controls, and our policies as they stand today, not after a certificate makes it look effortless. [Learn more](https://ahasend.com/blog/ahasend-pursuing-iso-27001-certification) - **Subprocessors**: The full list of subprocessors is published in our DPA: Hetzner, DA International Group Ltd, and Blix. Owning our infrastructure means there's very little to disclose. [Learn more](https://ahasend.com/dpa) - **Responsible disclosure**: Found a vulnerability? We have a published responsible disclosure policy and we respond fast. [Learn more](https://ahasend.com/responsible-disclosure) ## Questions a security review will ask ### Where is my data stored? All email content, message data, metadata, logs, and analytics are processed and stored within the EU/EEA, in datacenters on hardware AhaSend owns and operates. No US hyperscalers underneath. Our optional US egress node is strictly opt-in and never used unless you explicitly choose it. ### Does mail sent through the standard EU endpoints ever transit US infrastructure? No. The standard API and SMTP endpoints route EU-only. The US egress node is opt-in only, exactly as shown on the map above. ### Can I control data retention? Yes. Retention is configurable per account and per message, down to not storing message content at all, with optional archiving to your own S3-compatible storage. ### How do you secure API access? Scoped API keys with granular permissions, per-key IP allow lists, sandbox keys for testing, and 2FA or SSO on every dashboard account. ### Do you have a DPA I can sign? Yes — it is public at [ahasend.com/dpa](https://ahasend.com/dpa) and ready for signature. ### Are you ISO 27001 certified? Our certification audit is scheduled for September 2026. The Trust Center shows the live status and our current controls. ### Do you fully support SPF, DKIM, and DMARC on our own sending domains? Yes, full support on every plan, including per-domain DKIM selectors for painless migrations. Still have questions? [Check our documentation](https://ahasend.com/docs) · [Contact support](https://ahasend.com/contact) ## See for yourself The Trust Center has the documents. The free tier has 1,000 emails a month. Your security team can read while your developers send. - [Visit our Trust Center](https://ahasend.com/blog/ahasend-pursuing-iso-27001-certification) - [Start for free](https://dash.ahasend.com/user/register)