Skip to main content
New Pair with DMARC Report for complete email authentication Learn more → →

Compliance & Trust

OutboundSMTP runs on DuoCircle's compliance program.

OutboundSMTP is built and operated by DuoCircle LLC. The OutboundSMTP service line is in scope for our SOC 2 Type II examination and has its own CSA STAR registry entry. All vendor-assessment documents are published in one place at the DuoCircle Trust Center.

SOC 2 Type II

Annual examination since 2022 by Hancock Askew & Co, LLP. All four Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity. Report available under Bonterms Mutual NDA.

CSA STAR Level 1

OutboundSMTP has its own entry in the Cloud Security Alliance public registry. CAIQ Lite, subset of CCM v4.1. Renewed annually.

View OutboundSMTP on CSA STAR →

HECVAT Full

For colleges and universities, the Higher Education Community Vendor Assessment Toolkit, current version, available under NDA.

Penetration testing

Annual third-party penetration test. Executive summary available under NDA.

Need the SOC 2, HECVAT, or our policy pack?

Submit one request through the DuoCircle Trust Center. We use the standardized Bonterms Mutual NDA, published in advance so your legal team can review it before any conversation begins. We respond within one business day, and most often the same day.

Public, no NDA

OutboundSMTP runs on the standardized Bonterms Cloud Terms. Self-serve plans run on Bonterms Online Cloud Terms, accepted at sign-up. Enterprise plans run on a counter-signed Cover Page. Same balanced framework either way, no surprise additions.

Reviewed 2026-05-06.

See also: Privacy Policy · Cloud Terms · DPA