Mailway carries other people's email — the most sensitive kind of application data there is. This page is the plain-language record of where it runs, how it's protected, and who else is involved. Every claim here is meant to be checkable; if something looks wrong, tell us via the contact form.
Data residency
Mail is ingested, routed, and archived inside the European Union: dedicated Hetzner servers in Falkenstein, Germany, with archived payloads in AWS S3 eu-central-1 (Frankfurt). One EU region today — additional regions join the map as we grow, and this page will say so when they do. There is no "US processing unless you pay for the EU region" asterisk.
Encryption
- In transit — TLS on every surface. The SMTP submission ports refuse authentication before STARTTLS; implicit-TLS ports are available; the console, APIs, and webhooks are HTTPS-only.
- At rest — the provider credentials you connect are encrypted at the application layer; archived payloads are stored compressed and encrypted.
- Fidelity — messages are relayed byte-for-byte: no tracking pixels, no link rewriting, no content mutation. What your app sends is what arrives, provably.
Product security
- Two-factor authentication — TOTP and WebAuthn (hardware keys / passkeys), with optional team-wide 2FA enforcement.
- Role-based access — four roles (admin, developer, finance, member) over per-project access allowlists; provider secrets are admin-only.
- Audit trail — security-relevant actions are written to an append-only audit log that team admins can review in the console.
- Signed webhooks — outbound webhooks carry an HMAC signature so you can verify every delivery; endpoints that keep failing are safely disabled.
- Share links — public email share links use hashed 256-bit tokens, expire (4-day ceiling), are revocable, and are served from a separate cookie-less origin.
- Suppressions — per-project suppression lists are enforced at send time, so a bounced or complaining address stays protected.
BYOK isolation
Mailway never sends from shared IPs. You connect your own provider accounts; your sending reputation is yours alone, and nobody else's spam problem can become yours. Provider credentials are stored encrypted, scoped to your team, and used only to send your mail as you've configured it.
Sub-processors
The third parties that process data in the course of running Mailway. We announce additions or replacements at least 30 days in advance (per DPA §5). The email providers you connect under BYOK are your own vendors and are not on this list.
| Sub-processor | Role | Location | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Dedicated servers — application, database, SMTP ingress | Falkenstein, Germany (EU) | — (EU processing) |
| Amazon Web Services EMEA SARL | Object storage for archived payloads (S3) | eu-central-1 (Frankfurt, Germany, EU) | — (EU processing) |
| Cloudflare, Inc. | DNS, CDN, static hosting for the console and this site | Global edge network (US company) | EU–US DPF / SCCs |
| Stripe Payments Europe, Ltd. | Subscription billing — card data never touches Mailway | Ireland (EU), with US affiliates | EU–US DPF / SCCs |
| Functional Software, Inc. (Sentry) | Application error monitoring | United States | EU–US DPF / SCCs |
| GitHub, Inc. | Source code hosting — no customer mail content | United States | EU–US DPF / SCCs |
Retention and deletion
Message content is retained per your plan's retention window and removed by an automated retention process when the window lapses. Account deletion removes account data; terminated customers get a 30-day export wind-down before deletion (DPA §8).
Incident response
If a security incident affects your data, we notify the affected teams by email without undue delay, with what we know and what we're doing about it. Material security events are published within 72 hours. We keep this promise deliberately simple while the team is small — no status-page theater, just direct notification.
Responsible disclosure
Security research done in good faith is welcome. Report vulnerabilities via the contact form — the channel is also published at /.well-known/security.txt (RFC 9116). We confirm receipt within 72 hours, keep you informed while we fix, and credit you if you want credit. We will not pursue legal action for good-faith research that avoids privacy violations, data destruction, and service disruption. There is no paid bounty program yet; we say thank you and mean it.
Certifications
Honest answer: none yet. Mailway is GDPR-native by construction (EU processing, DPA, this page), and ISO 27001 certification is on the roadmap ahead of broad enterprise availability — this page will carry the certificate, not a badge-shaped promise, when it exists. Enterprise security questionnaires are answered on request via the contact form.
Track record
Mailway has run in production since late 2020: 865,000+ messages relayed with a 99.6% provider-accept rate. The platform predates its public launch by five years — it was built to carry a digital agency's client mail, and earned its way out.