Home / Trust Center

Trust Center

Last updated: June 13, 2026

The DDSEMail Trust Center is the single place to evaluate our security and compliance posture: HIPAA-conscious handling with a signed BAA, AES-256 encryption, TLS 1.3 in transit, audit logging, an annual SOC 2 Type II program, a named sub-processor list, and a coordinated vulnerability-disclosure process. Use the links below for the detail your review needs.

Compliance at a glance

AreaPostureDetail
HIPAASigned BAA on supported tiers; PHI handled accordinglyBAA overview
SOC 2Type II program, audited annuallySecurity
EncryptionAES-256 at rest; TLS 1.3 in transitSecurity
Audit loggingAccess and meaningful actions recordedSecurity
Privacy / GDPRController/processor roles; data-subject rightsPrivacy · GDPR
Sub-processorsShort, named list with data categoriesSub-processors

Security overview

DDSEMail encrypts traffic with TLS 1.3, encrypts sessions and sensitive material at rest with AES-256-GCM, stretches passwords with PBKDF2, and records access in an audit trail. The full description lives on the Security page.

HIPAA & the BAA

Where we handle protected health information, we sign a Business Associate Agreement and process PHI only to operate the service. See the BAA overview for what's in and out of scope and how to request the executed agreement.

Sub-processors

We rely on a short, named list of third-party providers, each contractually bound to protect your data. The current list and the data categories involved are on the Sub-processors page.

Reporting a vulnerability

We welcome coordinated disclosure. See security.txt for how to reach our security contact. Please do not test against production patient data.

Documentation requests

Need a SOC 2 report, completed security questionnaire, or signed BAA/DPA for vendor review? Contact us and we'll route the request. Compliance documentation contact: {{TODO: security/compliance contact email}}.

See also: Privacy · Terms · Cookies · Security · Sub-processors · BAA · Contact