Senthop trust center
Trust center
Transparency about how we protect your data, where it lives, and what certifications we hold. Built for organisations that need to know exactly where their email infrastructure sits.
Postmark 01
Data residency
Where your data lives
All customer data — account information, email metadata, delivery logs, contact lists, suppression records, and configuration — is stored on servers physically located in Portsmouth, England, United Kingdom.
Senthop is UK-built and hosted: your data is stored and processed in the UK, under UK law and UK GDPR.
Database backups are stored on Contabo Object Storage in the EU (Nuremberg, Germany), subject to EU GDPR. Backups are encrypted in transit and automatically pruned after 30 days.
Optional AI-powered deliverability features run on Google Cloud Vertex AI, region-pinned to the UK (europe-west2, London), under the Google Cloud Data Processing Addendum. Content processed for these features stays in the UK region and is not used to train Google's models.
Data flow
Your application
Senthop API (UK, Portsmouth)
Compliance checks (UK)
SMTP relay (UK)
DKIM signing (UK)
Recipient mail server (worldwide)
Email processing runs on UK infrastructure. Final delivery to the recipient's mail server crosses the networks between us and them — inherent to email and true of every provider.
Postmark 02
Security
Certifications and registrations
- In progress
Cyber Essentials
UK government-backed scheme certifying baseline cyber security hygiene. Cyber Essentials certification is currently in progress; we are not yet certified.
- Active
ICO registration
Reference ZC180480 with the UK Information Commissioner's Office.
- Active
Companies House
Skyie Global InfoTech Ltd, Company Number 17294509. Registered office: 1 Surjit Court, 259 High Street, Rochester, ME1 1HZ.
Application security
- TLS 1.2+ encryption on all connections (API, dashboard, SMTP)
- DKIM, SPF, and DMARC authentication on all outbound email
- Passwords stored as bcrypt hashes with per-user salt
- API keys stored as SHA-256 hashes — shown once, never retrievable
- CSRF double-submit cookie protection on all state-changing requests
- Row-level security (RLS) policies enforcing tenant isolation
- Rate limiting on authentication and email sending endpoints
- IP allowlisting available for API access control
- Two-factor authentication (TOTP) with backup codes
- Security headers: CSP, HSTS (1 year, preload), X-Frame-Options, X-Content-Type-Options
- Automated suppression of hard-bounced and complained addresses
Infrastructure security
- Internal services on an isolated Docker network with no public egress
- PostgreSQL and Redis unreachable from the internet
- Secrets managed via GitHub Actions, injected at deploy time, never in code
- Daily automated database backups to off-site S3-compatible storage with checksum verification
- Continuous integration with automated linting, type checking, and test suites
- Deterministic builds via locked dependency files across all services
X-Forwarded-Fortrusted only from RFC 1918 private ranges; public clients cannot spoof source IP past our rate limits- Post-deploy synthetic probe on every release: five assertions (API health, frontend render, unauthenticated access denial, container inventory, restart-loop guard) — any failure aborts the deploy
Supply-chain provenance
Every production deploy publishes a CycloneDX SBOM generated by Syft over the source tree, signed with Sigstore cosign (keyless OIDC). The signing certificate is issued by Fulcio and bound to the specific GitHub Actions workflow run — repo, branch, commit SHA, runner identity.
Verifiable offline:
cosign verify-blob sbom-<sha>.cdx.json \
--signature sbom-<sha>.cdx.json.sig \
--certificate sbom-<sha>.cdx.json.pem \
--certificate-identity-regexp \
'https://github.com/sgadminuk/skyie-relay/\.github/workflows/deploy\.yml@refs/heads/main' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comCustomers under NDA can request the SBOM + signature bundle for any released version at [email protected].
Security operations
- 10 operational runbooks covering the top incident classes (Postgres / Redis down, DKIM milter fail, queue backlog, IP reputation drop, Stripe webhook failure, auth outage, bounce storm, warmup stall, Gemini quota exhausted)
- Written incident-response policy: SEV1–SEV4 severity classification, response targets, communications, postmortem requirements, 7-year audit-log retention
- Quarterly disaster-recovery drill recipe with documented success criteria (MTTR ≤ 60 minutes) — first rehearsal scheduled in Phase 3
- Weekly OWASP ZAP baseline scan against the public edges (app.maielr.com, relay.maielr.com); findings auto-open a GitHub issue
- Non-blocking
pnpm auditCVE gate on every pull request - E2E test suite covering signup, login, CSRF, JWT refresh, tenancy isolation, password reset, webhook CRUD, suppression list, accessibility — runs on every PR against a full-stack CI environment
Postmark 03
Subprocessors
Third parties that process data on our behalf
| Provider | Purpose | Location | Data processed |
|---|---|---|---|
| Contabo GmbH | Infrastructure hosting | UK (Portsmouth) | All service data |
| Contabo GmbH | Backup storage | EU (Nuremberg) | Database backups |
| Stripe, Inc. | Payment processing | US (with EU/UK SCCs) | Billing data only |
| Google Cloud | Vertex AI deliverability (optional) | UK (europe-west2, London) | Content, in-region, under Cloud DPA, no training |
Postmark 04
Compliance
Email compliance
- CAN-SPAM Act compliance checks on every outbound message
- Automatic suppression of bounced and complained addresses
- Double opt-in support for consent management
- One-click unsubscribe headers (RFC 8058) on marketing emails
- IP and domain warmup to protect sender reputation
- DMARC report ingestion and monitoring
Data protection
- UK GDPR compliant data processing
- Data Processing Agreements (DPA) available for enterprise customers
- Right of access, rectification, erasure, and portability honoured within 30 days
- Data retention policies documented in our Privacy Policy
- Breach notification within 72 hours as required by UK GDPR Article 33
Detailed supporting documentation (sub-processor register, per-table data retention schedule, DPIA for AI processing, incident-response policy) is available to customers under NDA at [email protected].
Postmark 05
API stability
What you can rely on
- Major version (
/v1/*) — breaking changes trigger a new major; the old major is supported for at least 12 months after a new one ships - Minor releases — additive only; every response carries
X-Api-Version: YYYY-MM-DD. Customers do not need to pin - Deprecation — announced 12 months ahead via
X-Api-Deprecationresponse header, the public changelog, email to affected customers, and a dashboard banner - Webhook signatures — HMAC-SHA256 over
<timestamp>.<raw body>, algorithm stable through the lifetime of v1 - Error format — machine-readable
errorcodes never change without a major bump
Full contract + per-release changelog are maintained in the repository alongside the source that enforces them.