Trust and compliance
Omnivery publishes every certificate it holds, with the certificate number, the standard version, the certified scope and the expiry date. Nothing here requires a sales call to verify.
Last reviewed July 2026
At a count
Omnivery holds seven ISO certifications and an independently assessed HIPAA compliance certificate. All eight are issued by TAYLLORCOX, a Prague-based certification body, and all eight are available to download below.
ISO certifications
Each certificate is issued to Omnivery s.r.o. (company ID 25734105), Oranžová 225, 252 19 Chrášťany, Czech Republic, by the certification body TAYLLORCOX GCS.
| Standard | Management system certified | Certificate No. | First certified | Valid until | Document |
|---|---|---|---|---|---|
| ISO 9001:2015 | Quality Management System | 2505302253 | 2 June 2022 | 2 June 2027 | |
| ISO/IEC 20000-1:2018 | Information Technology Service Management System | 2505307112 | 30 May 2025 | 29 May 2028 | |
| ISO 22301:2019 | Business Continuity Management Systems | 2505308267 | 2 June 2022 | 2 June 2027 | |
| ISO/IEC 27001:2022 | Information Security Management System | 2505303078 | 2 June 2022 | 2 June 2027 | |
| ISO/IEC 27017:2017 | Code of practice for information security controls based on ISO/IEC 27002 for cloud services | 2505305996 | 30 May 2025 | 29 May 2028 | |
| ISO/IEC 27018:2019 | Code of Practice for Protecting Personal Data in the Cloud | 2505305789 | 30 May 2025 | 29 May 2028 | |
| ISO/IEC 27701:2019 | Privacy Information Management System | 2505307311 | 4 August 2023 | 2 June 2027 |
All figures taken from the certificates themselves, issued by TAYLLORCOX GCS (TAYLLORCOX s.r.o., Na Florenci 1055/35, Praha 1). ISO/IEC 20000-1, 27017 and 27018 are published in the combined ISO certificate pack; 9001, 22301, 27001 and 27701 are additionally available as individual documents. The ISO/IEC 27001 certificate is valid in conjunction with the Statement of Applicability dated 8 January 2024.
What they buy you
ISO/IEC 27001 is common among email providers. The ones below are not.
Extends the 27001 management system to personal data specifically, which is the standard a GDPR-focused reviewer asks about. Omnivery has held it since August 2023. Neither SendGrid, Mailgun nor SparkPost publishes an ISO/IEC 27701 certificate.
Certifies a tested continuity management system rather than a written recovery plan. Financial services and insurance reviews frequently require evidence of this, and a policy document is not evidence.
Covers IT service management: incident handling, change control and service levels as an audited system. This is the standard that operational resilience and third-party risk questionnaires map onto.
Cloud-specific control sets: 27017 for information security controls in cloud services, 27018 for protecting personal data in the cloud. Both apply to how Omnivery governs the infrastructure it owns and operates itself.
HIPAA
HIPAA is United States legislation, not a certification scheme. No government body issues a HIPAA certificate, which is why most email providers describe themselves as "HIPAA compliant" or "HIPAA ready" and offer nothing a reviewer can inspect.
Omnivery holds an independent third-party assessment instead. Certificate No. 2510225512, issued 22 October 2025 by TAYLLORCOX Institut, confirms that Omnivery s.r.o. underwent an independent assessment of its administrative, technical and physical safeguards for the protection of Protected Health Information, against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule (45 CFR Parts 160, 162 and 164). The recorded result is that compliance with HIPAA requirements has been confirmed.
Unlike the ISO certificates, the HIPAA document carries an assessment date rather than an expiry date.
Business Associate Agreements: yes. Omnivery signs BAAs as a standard part of onboarding a covered entity or business associate. See HIPAA compliant email for how the platform handles PHI, including message content never being stored and metadata capped at 30 days.
Certified scope
All seven ISO certificates carry the same registered scope:
Design, development and operation of technology for marketing automation.
The scope covers the design, development and operation of the platform. It was registered when Omnivery's management system was first certified in 2022 and uses the wording of Mailkit, the email platform founded in 2006 that Omnivery grew out of. The same certified infrastructure carries transactional traffic today.
If your vendor review needs the scope statement to name your specific use case, raise it with us during onboarding.
Certificate numbers are printed on every document above. TAYLLORCOX can confirm the validity of any of them directly: +420 725 536 797 or audit@tayllorcox.com.
Processing and memberships
There are no US sub-processors in the core email service; US-incorporated vendors apply only to optional, customer-selectable features. Omnivery engages two sub-processors, each attached to an optional feature and both processing in the EU: Bouncer Sp. z o.o. (Wrocław, Poland) for e-mail validation, and ProfiSMS s.r.o. (Prague, Czechia) for SMS delivery. Bouncer in turn runs on Amazon Web Services infrastructure in the Frankfurt region, as Bouncer's own sub-processor rather than one Omnivery engages. If you enable neither feature, no data reaches any of them.
Omnivery's processing entity is the Czech company, and the delivery path runs on infrastructure Omnivery owns, with no AWS, Azure or Google Cloud beneath it. The published sub-processor list is on the GDPR page, and the regulatory analysis, including CLOUD Act and Schrems II, is on the GDPR compliant email API page.
Message body content is never stored. Delivery metadata is capped at 30 days, and strict privacy mode anonymizes it fully.
Omnivery is a certified member of the Certified Senders Alliance, the European sender accreditation scheme operated in Germany. CSA admission is not a subscription: an applicant has to pass a certification process against the CSA's legal and technical criteria, and has to keep meeting them to stay listed. Receivers in Germany and the wider DACH region treat CSA listing as a sender-side trust signal, which is why it carries weight there specifically.
Omnivery is also a member of M3AAWG, the global anti-abuse working group, and of Signal Spam in France. Those two are memberships rather than certifications. All three matter operationally for the same reason: they make escalation possible at receivers with no public contact route.
CSA accreditation is separate from the seven ISO certifications and HIPAA listed above, which are accredited third-party audits issued by TAYLLORCOX.
Not Cloud Security Alliance. Omnivery holds no Cloud Security Alliance membership and no CSA STAR listing. The two organizations are unrelated, and a vendor questionnaire using the abbreviation can easily mean one and receive an answer about the other.
At a glance
Questions
Seven. ISO 9001:2015 (quality management), ISO/IEC 20000-1:2018 (IT service management), ISO 22301:2019 (business continuity), ISO/IEC 27001:2022 (information security), ISO/IEC 27017:2017 (cloud security controls), ISO/IEC 27018:2019 (personal data in the cloud) and ISO/IEC 27701:2019 (privacy information management). All seven are published for download with their certificate numbers and expiry dates.
Yes, and yes. Omnivery holds HIPAA compliance certificate No. 2510225512, issued 22 October 2025 by TAYLLORCOX Institut following an independent assessment of administrative, technical and physical safeguards for Protected Health Information against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule. The certificate is published at /documents/omnivery_hipaa_certificate.pdf and requires no NDA or sales contact. HIPAA is US legislation rather than a certification scheme with an official registry, so no government-issued HIPAA certificate exists for any provider. Most providers offer a self-declaration; Omnivery offers a dated third-party assessment.
Yes. Omnivery signs BAAs, and it is a standard part of onboarding a covered entity or business associate rather than something that has to be negotiated or escalated to a sales conversation.
That is the scope wording registered when Omnivery's management system was first certified in 2022, and it reflects the platform's origin in Mailkit, the email platform founded in 2006 that Omnivery grew out of. All seven certificates carry the same scope statement - "Design, development and operation of technology for marketing automation" - covering the design, development and operation of the platform. The same certified infrastructure carries transactional traffic. If a vendor review needs the scope statement to name a specific use case, raise it during onboarding.
All eight were issued by TAYLLORCOX, a Prague-based certification body (TAYLLORCOX s.r.o., Na Florenci 1055/35, Praha 1). Every certificate carries a certificate number, and TAYLLORCOX will confirm the validity of any of them on +420 725 536 797 or at audit@tayllorcox.com.
SendGrid (Twilio), Mailgun (Sinch) and SparkPost (now Bird Email, MessageBird) all run on shared public cloud, and none of them publishes an ISO/IEC 27701 certificate or a HIPAA certificate. The full matrix, including the ISO 22301 and ISO/IEC 20000-1 rows, is on the provider comparison page.
No. On Omnivery pages CSA means the Certified Senders Alliance, the European email sender accreditation scheme operated in Germany, of which Omnivery is a member. Omnivery makes no claim to Cloud Security Alliance membership or to a CSA STAR listing. The two organizations are unrelated and the abbreviation collision is a common source of confusion in vendor questionnaires.
Every certificate on this page is downloadable without a form, an NDA or a sales call. Forward them to your security reviewer as they are.