Five sites.
One network.
A core ring across Falkenstein, Nuremberg and Helsinki, with Oslo and Sofia uplinked into it.
SECURITY FEATURES
Built to keep your email and your data safe
Every account gets the same security features, on every plan.
Two-factor authentication, enforced
Protect your account with TOTP-based 2FA, and require it for your whole team with account-wide enforcement.
Learn moreSingle sign-on
Log in through your own identity provider with OpenID Connect SSO, including PKCE and multi-domain support.
Learn moreScoped API keys
Restrict every API key to specific domains and granular permissions, so a leaked key for one service cannot touch anything else.
Learn moreIP allow lists
Lock any API key to the IPv4/IPv6 addresses or CIDR ranges you specify. Changing an allow list requires re-authentication and alerts your admins.
Learn moreSigned webhooks
All webhooks follow the Standard Webhooks specification with HMAC signatures and timestamps, so your endpoints can verify every event.
Learn moreSandbox mode
Test your full integration, including bounces and webhooks, without a single real email leaving the platform.
Learn moreYou decide how long we keep your data
Message metadata for 1 to 30 days, full message content anywhere from 30 days down to zero.
Learn moreOur infrastructure is
the security feature
Most email providers rent their infrastructure and inherit its risks. We took the opposite route. Owning the full stack means we control patching, hardening, and monitoring down to the metal. The answer to "where does my email data live?" is one sentence: in Europe, on machines we own.
European datacenters, on our own network with our own ASN. No US hyperscaler underneath.
Nothing sits between you and the mail server, and no foreign jurisdiction has a legal claim on your data in transit.
We control patching and hardening; delivery is TLS-secured and our current status is always public at status.ahasend.com.
Where your data lives
All email content, message data, metadata, logs, and analytics stay within the EU and EEA (EEA because part of our infrastructure runs in Norway). Two exceptions in the interest of full transparency: (1) the nameservers for ahasend.com itself are currently at Cloudflare. That affects DNS resolution of our website, not your email data, and a migration is planned. (2) a optional US egress node exists, is strictly opt-in and never used unless you explicitly choose it.
COMPLIANCE
Compliance, in writing
GDPR
AhaSend is a European company under European law. Our Data Processing Agreement is public, ready to sign, and doesn't hide a US parent behind an EU letterbox.
CSA Certified Sender
AhaSend is certified by the Certified Senders Alliance, the sender accreditation programme run with eco and the German mailbox providers.
ISO 27001
Our certification audit is scheduled for September 2026, and we're doing it transparently: our Trust Center shows the current status, our controls, and our policies as they stand today, not after a certificate makes it look effortless.
Subprocessors
The full list of subprocessors is published in our DPA: Hetzner, DA International Group Ltd, and Blix. Owning our infrastructure means there's very little to disclose.
Responsible disclosure
Found a vulnerability? We have a published responsible disclosure policy and we respond fast.
See for yourself
The Trust Center has the documents. The free tier has 1,000 emails a month. Your security team can read while your developers send.