RadMail · Trust

Trust & compliance

How we handle your data, who processes it, and how the platform serves regulated tenants. Everything below is a statement of what is actually in force — we don’t claim certifications we don’t hold.

The proof, not the promise

Every refusal ships a receipt you can check yourself

When RadMail hard-stops an unsafe send — a wire change, a money request, a first-contact sender — it issues a signed, tamper-evident receipt. Anyone you hand it to — a bank confirming a payment instruction, an auditor sampling controls, a customer checking your story — can verify it with no login and no access to anyone’s mailbox. The page only checks the signature; alter a single character and verification fails.

The receipt carries only the decision id, the reason class, and a timestamp — never email content. We haven’t seen another inbox AI ship a machine-checkable refusal contract: most can tell you they blocked something, but they can’t hand you proof a third party can independently confirm.

Verify a receipt →No account needed.

Security posture

Tenant isolation

Postgres Row-Level Security on every tenant-scoped table; a row can never be read cross-tenant even if an app query forgets its filter.

Encryption

TLS in transit; encryption at rest. Regulated tenants get a dedicated database tier with a customer-managed key.

Access control

Role-based access (owner / manager / member / viewer). API access uses scoped, revocable, per-org keys — hashed at rest.

Audit log

Append-only audit trail (database-enforced — no updates or deletes). Regulated tenants additionally log reads.

Least-data LLM

Email content is fenced as untrusted input to the model. Regulated tenants are routed to a BAA-covered model endpoint only.

SOC 2

We are building toward a SOC 2 Type II report; the controls are in place and the observation clock is the next milestone. We share our current status under NDA.

Subprocessors

The third parties that may process tenant data, their role, and the agreement under which they do so. This is our vendor register.

SubprocessorRolePurposeRegionAgreement
Anthropic (Claude API, direct)llmEmail classification + reply drafting (non-regulated tenants).US
AWS Bedrock (Claude on Bedrock)llmLLM for regulated tenants (BAA-covered path).us-east-1
BAA signedFedRAMP moderate
AWS Bedrock (GovCloud)llmLLM for federal/CUI tenants (FedRAMP-authorized).us-gov
FedRAMP high
Neon (Postgres, shared)dbTenant data store for the shared-RLS pool (non-regulated).US
Neon (dedicated, BAA)dbDedicated per-tenant DB for regulated tenants.US
BAA signed
Resend (ESP)espOutbound email delivery (non-regulated tenants).US
Resend Inbound (forwarding relay)relayInbound forwarding-address relay (fast onboarding, non-regulated).US
Microsoft 365 (BAA mailbox)mailboxBAA-covered mailbox connection + send path for regulated tenants.US
BAA signed
Vercel (host)hostApplication hosting + edge.US
covered by terms

Regulated tenants — computed subprocessor coverage

Compliance is a per-tenant attribute, not a one-size posture. For a regulated tenant, the platform filters the subprocessor set to the covered subset and refuses to route data to anything outside it. A tenant’s chain validity is computed from that coverage, not assumed. For HIPAA tenants we sign a BAA; for federal tenants we operate on FedRAMP-aligned infrastructure under a shared-responsibility model.

HIPAA (we act as a Business Associate)
chain valid

BAA-covered subset only

In scope
AWS Bedrock (Claude on Bedrock)Neon (dedicated, BAA)Microsoft 365 (BAA mailbox)Vercel (host)
Excluded by construction
Anthropic (Claude API, direct)AWS Bedrock (GovCloud)Neon (Postgres, shared)Resend (ESP)Resend Inbound (forwarding relay)
Federal / CUI (FedRAMP-aligned)
1 gap(s)

FedRAMP-authorized subset only

In scope
AWS Bedrock (GovCloud)Vercel (host)
Excluded by construction
Anthropic (Claude API, direct)AWS Bedrock (Claude on Bedrock)Neon (Postgres, shared)Neon (dedicated, BAA)Resend (ESP)Resend Inbound (forwarding relay)Microsoft 365 (BAA mailbox)
  • Vercel (host): not FedRAMP-authorized

How we talk about compliance

Using RadMaildoes not by itself make your organization compliant with any regulation — compliance is a shared responsibility between your organization and us. We provide BAA-covered infrastructure and the controls; you operate within your own program. We sign a BAA for HIPAA tenants and operate on FedRAMP-aligned, 800-171-ready infrastructure for federal tenants. We never claim to be “certified” for a frame we have not been assessed against.

RadMail v0.80.0 · Home · Get started