Mail a compliance officer can audit.
Appointment reminders, results notifications, and care communications where a silent failure is a clinical problem before it is a technical one — and where “we think it was delivered” is not an acceptable answer to anybody.
Black-box handling of sensitive communications
A platform that reports a percentage and discards the provider's response leaves you unable to answer the only question that matters during a review: what happened to this specific message, and when?
Thin auditability
Short retention windows and normalised-only event records mean the evidence is gone by the time anyone asks for it. Audits happen on someone else's schedule.
Unclear operational responsibility
Shared pools and vague SLAs make it genuinely hard to say who is accountable when mail stops arriving — which is exactly the question an auditor will ask.
Every event explainable
Delivery, bounce, deferral, and complaint events all keep the receiving provider's raw payload. You can reconstruct the lifecycle of any individual message with timestamps, not infer it from a summary.
Infrastructure you can inspect
The core is open source. Your security team can read exactly how sending, suppression, and reputation scoring work rather than accepting a description of them — or run the whole thing inside your own perimeter.
Isolation, not a shared pool
Regulated sending belongs on infrastructure nobody else is using. Reputation is scored per domain and per workspace, and a BAA is offered on Dedicated plans where that isolation is contractual.
Retention you choose
Event retention is configurable on Dedicated, so your evidence window matches your compliance obligation rather than our default.
One product, three versions of the same problem.
We do not build a separate edition per industry. The five things below are what every OutSend account gets, and they are what makes each of these workloads tractable.
Agents are first-class
API, CLI, and MCP with verifiable outcomes.
Per-ISP truth
See where every email went — and why.
Reputation sovereignty
Your reputation is yours. No neighbor can burn it.
Observable sending
Explainable by a person or an agent.
Portable by construction
Read it. Run it. Leave freely.
What we will and will not say.
We operate HIPAA-compliant medical sending workloads today. We are not going to name those customers, publish volumes, or turn regulated communications into a case study — and you should be sceptical of any vendor who would.
A Business Associate Agreement is offered on the Dedicated plan, on request. We do not offer one on shared plans, because a BAA over a shared sending pool would be a document rather than a control.
We do not ask for or want protected health information in the message content we retain. If your use case requires content retention limits, tell us before you send and we will configure it — see the security page for the specifics.
Ready to see where your email goes?
Seven days free. No card to start, and everything we claim is checkable.
Open core · never venture-backed · operated by Martin Business Consultants