Lettermint is ISO 27001 certified

Earlier this year, in our look back at 2025, we wrote that obtaining our ISO 27001 certification was one of our goals for 2026. Today is the day. Lettermint is now certified to ISO/IEC 27001:2022, the international standard for information security. Time for some confetti.
We've taken security and privacy seriously from day one. No surprise, since the transactional emails that run through our platform regularly contain sensitive information. Password resets, order confirmations, invoices. We've talked about how we protect that data before, for example on our Trust Center (opens in a new window). With this certification, an independent auditor has now assessed our approach against the standard and confirmed it meets the requirements. Lettermint is now officially an ISO 27001 certified email provider.
In this blog we'll explain what ISO 27001 actually covers and what it means for you. No long nights this time, but a whole lot of documents.
What is ISO 27001
You probably just wanted to know whether we have the certificate. For those who are curious anyway: ISO 27001 is the international standard for information security. Certification means an independent auditor has assessed how an organization manages its security and confirmed it meets the standard. Think of who has access to your email data, how that data is stored encrypted, how backups are handled and what happens during an incident.
You don't get a certificate like this by filling out a questionnaire. The auditor reviews policies, processes and evidence to see whether security works in practice, not just on paper. And they come back to check again.
The certification covers our entire email infrastructure, from receiving emails to processing and sending them. The certificate and its validity details are available in our Trust Center (opens in a new window).
What this means for our customers
For most users, nothing changes in practice. Your emails are still sent just like you're used to. What does change is what you can prove.
Do you work at an organization that reviews vendors on security? You can now point to our certificate in the Trust Center (opens in a new window) during vendor reviews. It won't make every questionnaire disappear, but it does make those reviews a lot faster.
Are you an agency building applications for clients? Then the certification answers a question that comes up more and more: how secure are the parties you work with?
And if you simply send emails for your own project? Then this is mostly confirmation that your data is in good hands, with a European email provider that is externally audited too.
What's next
The certificate is now framed and hanging in our office. But we're not done. The audits keep coming back and the measures have to keep working every day. And that's a good thing.
Meanwhile, we keep building. Our roadmap shows what's coming, and security plays a role there regularly too.
Questions about the certification or about how we handle your data? Take a look at our Trust Center (opens in a new window) or send us a message.