trust
last updated 2026-08-24 · mittera.eu
mittera is an flndrn brand · mittera.eu · operated by flndrn Limited (Cyprus)
What the platform is
mittera is a hosted email platform. Concretely, that means:
- Transactional email over a REST API and SDKs — from, to, subject, HTML and text bodies, attachments and headers.
- Sending domains with DKIM and SPF verification, so mail from your own domain is delivered rather than sent to spam.
- API keys you can narrow — scoped to sending or full access, stored as SHA-256 hashes and compared in constant time. The plaintext is shown once and never again.
- Audiences and contacts, broadcasts, templates, a suppression list, and webhooks for delivery events.
- A dashboard with organisations, roles, per-resource permissions and an audit log.
- Delivery through SMTP2GO — an interim managed SMTP relay, disclosed at /subprocessors. The delivery provider is swappable and will move to an EU-sovereign provider when one is ready.
What we do not offer yet
As of the date above, the platform does not provide:
- No certification of any kind. No SOC 2, no ISO 27001, no HIPAA, no PCI DSS. No external audit has ever been carried out on mittera.
- SSO, SCIM or MFA. Sign-in is email and password, or a one-time code sent to your email.
- An end-user auth product for your application. Sign-in on mittera.eu is for the dashboard only.
- Off-site backups of customer data. Keep your own export where it matters.
- Multi-region, read replicas or autoscaling. One region, one deployment, by deliberate choice rather than by delay — and therefore no contractual uptime percentage (see /sla).
- An EU-sovereign delivery path today. SMTP2GO is a US/AU relay. This is an interim; the swap to an EU-sovereign provider is the stated direction.
If one of these is a hard requirement for you today, mittera is not the right choice yet, and we would rather you knew that before you migrate than after.
Where data lives
The whole platform runs as a single deployment on one server: the dashboard, the control-plane database, the email log and delivery event store. Customer data is isolated per organisation. The hosting provider and region are disclosed once they can be stated accurately; ask at legal@mittera.eu if your evaluation depends on it.
Encryption
- TLS on every public endpoint.
- Stored credentials: AES-256-GCM at rest with a platform-held key.
- Session cookies: HTTP-only, Secure in production.
- API keys: SHA-256 hashed; only short suffixes displayed.
Access and audit
Platform actions — creating a key, adding a domain, changing a member, sending a broadcast — are written to an append-only audit log. IPs are hashed before storage where the Privacy Policy requires it.
Incident disclosure
We aim to disclose incidents that affect customer data within 72 hours of detection to affected accounts, and publish a post-mortem within 30 days when material. Report security issues to security@mittera.eu.
Legal contacts
Privacy and DPA: legal@mittera.eu. Operator: flndrn Limited, Limassol, Cyprus. The Terms and Privacy Policy live under this site’s legal section.