Security

An email client your
security team will sign off on.

maiLane is built on a hardened, multi-tenant architecture with defense-in-depth controls, independent audits, and continuous monitoring — without slowing your team down.

SOC 2 Type II ISO 27001 GDPR aligned HIPAA-ready 99.99% uptime SLA

Encryption

TLS 1.3 in transit on every channel. AES-256 at rest across all storage layers. Optional customer-managed encryption keys via AWS KMS for Enterprise customers.

Identity & authentication

SAML 2.0 / OIDC SSO, SCIM 2.0 provisioning, passkeys, hardware-backed MFA, IP allowlisting, and granular session controls.

Network & infrastructure

Workloads isolated per region in dedicated VPCs. Private network paths for storage and key management. Continuous vulnerability scanning.

Application security

SDLC with mandatory code review, dependency scanning, static analysis, and annual external penetration testing.

Audit & observability

Every admin and user action emits a structured, tamper-evident event. Stream to your SIEM, S3 bucket, or Datadog in real time.

Data residency

Pin customer data to EU or US regions. Region-locked processing for regulated workloads.

Compliance

Independently verified.

maiLane maintains an active compliance program reviewed by external auditors and updated continuously.

SOC 2 Type II

Annual audit covering security, availability, and confidentiality. Latest report available under NDA.

ISO 27001

Information security management system certified by an accredited registrar.

GDPR

Customers can sign our DPA online. EU data residency available for all plans.

HIPAA

BAA available on the Enterprise plan. Dedicated environment for regulated workloads.

CCPA & CPRA

Privacy program aligned with California consumer privacy regulations.

Vendor diligence

Security and privacy questionnaires returned within 5 business days for active prospects.

Reliability

Public status. Public incident history.

Real-time component health and a transparent incident log at status.mailane.net.

status.mailane.net
All systems operational Updated just now
APIOperational · 99.99%
Inbound deliveryOperational · 99.99%
Outbound deliveryOperational · 99.98%
Routing engineOperational · 99.99%
Web dashboardOperational · 99.99%
IMAP / SMTPOperational · 99.99%
Responsible disclosure

Working with the security community.

We welcome reports from independent researchers. Encrypted reports to security@mailane.net (PGP key on request) receive an acknowledgement within 24 hours.

Need our security documentation?

Request our SOC 2 Type II report, penetration test summary, and sub-processor list.