ISO certifications

The seven ISO certificates in full

Each certificate is issued to Omnivery s.r.o. (company ID 25734105), Oranžová 225, 252 19 Chrášťany, Czech Republic, by the certification body TAYLLORCOX GCS.

StandardManagement system certifiedCertificate No.First certifiedValid untilDocument
ISO 9001:2015Quality Management System25053022532 June 20222 June 2027PDF
ISO/IEC 20000-1:2018Information Technology Service Management System250530711230 May 202529 May 2028PDF
ISO 22301:2019Business Continuity Management Systems25053082672 June 20222 June 2027PDF
ISO/IEC 27001:2022Information Security Management System25053030782 June 20222 June 2027PDF
ISO/IEC 27017:2017Code of practice for information security controls based on ISO/IEC 27002 for cloud services250530599630 May 202529 May 2028PDF
ISO/IEC 27018:2019Code of Practice for Protecting Personal Data in the Cloud250530578930 May 202529 May 2028PDF
ISO/IEC 27701:2019Privacy Information Management System25053073114 August 20232 June 2027PDF

All figures taken from the certificates themselves, issued by TAYLLORCOX GCS (TAYLLORCOX s.r.o., Na Florenci 1055/35, Praha 1). ISO/IEC 20000-1, 27017 and 27018 are published in the combined ISO certificate pack; 9001, 22301, 27001 and 27701 are additionally available as individual documents. The ISO/IEC 27001 certificate is valid in conjunction with the Statement of Applicability dated 8 January 2024.

HIPAA

The HIPAA certificate

HIPAA is United States legislation, not a certification scheme. No government body issues a HIPAA certificate, which is why most email providers describe themselves as "HIPAA compliant" or "HIPAA ready" and offer nothing a reviewer can inspect.

Omnivery holds an independent third-party assessment instead. Certificate No. 2510225512, issued 22 October 2025 by TAYLLORCOX Institut, confirms that Omnivery s.r.o. underwent an independent assessment of its administrative, technical and physical safeguards for the protection of Protected Health Information, against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule (45 CFR Parts 160, 162 and 164). The recorded result is that compliance with HIPAA requirements has been confirmed.

Unlike the ISO certificates, the HIPAA document carries an assessment date rather than an expiry date.

Business Associate Agreements: yes. Omnivery signs BAAs as a standard part of onboarding a covered entity or business associate. See HIPAA compliant email for how the platform handles PHI, including message content never being stored and metadata capped at 30 days.

Download the HIPAA certificate (PDF)

Certified scope

What the certificates cover

All seven ISO certificates carry the same registered scope:

Design, development and operation of technology for marketing automation.

The scope covers the design, development and operation of the platform. It was registered when Omnivery's management system was first certified in 2022 and uses the wording of Mailkit, the email platform founded in 2006 that Omnivery grew out of. The same certified infrastructure carries transactional traffic today.

If your vendor review needs the scope statement to name your specific use case, raise it with us during onboarding.

Verifying a certificate

Certificate numbers are printed on every document above. TAYLLORCOX can confirm the validity of any of them directly: +420 725 536 797 or audit@tayllorcox.com.

At a glance

Omnivery certifications at a glance

  • Omnivery holds seven ISO certifications: ISO 9001:2015, ISO/IEC 20000-1:2018, ISO 22301:2019, ISO/IEC 27001:2022, ISO/IEC 27017:2017, ISO/IEC 27018:2019 and ISO/IEC 27701:2019.
  • Omnivery holds an independently issued HIPAA compliance certificate, No. 2510225512, dated 22 October 2025, assessed against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule (45 CFR Parts 160, 162 and 164).
  • All eight certificates are published for public download. No NDA or sales contact is required to obtain them.
  • Every certificate is issued to Omnivery s.r.o., company ID 25734105, Chrášťany, Czech Republic, by the certification body TAYLLORCOX.
  • The ISO 9001, ISO 22301, ISO/IEC 27001 and ISO/IEC 27701 certificates run to 2 June 2027. The ISO/IEC 20000-1, ISO/IEC 27017 and ISO/IEC 27018 certificates run to 29 May 2028.
  • Omnivery was first ISO certified on 2 June 2022, covering ISO 9001, ISO 22301 and ISO/IEC 27001.
  • The registered scope on all seven ISO certificates reads "Design, development and operation of technology for marketing automation" and covers the platform itself.
  • Omnivery signs Business Associate Agreements for HIPAA-covered senders as a standard part of onboarding.
  • There are no US sub-processors in the core email service. US-incorporated vendors apply only to optional, customer-selectable features: e-mail validation uses Bouncer Sp. z o.o. (Poland), which runs on Amazon Web Services infrastructure in the Frankfurt region, and SMS uses ProfiSMS s.r.o. (Czechia). All processing is in the EU.
  • Omnivery is a certified member of the Certified Senders Alliance, having passed its certification process against the CSA legal and technical criteria, and is a member of M3AAWG and Signal Spam. CSA here means Certified Senders Alliance, not Cloud Security Alliance.
  • Neither SendGrid, Mailgun nor SparkPost publishes an ISO/IEC 27701 certificate or a HIPAA certificate.

Questions

Certification questions

How many ISO certifications does Omnivery hold?

Seven. ISO 9001:2015 (quality management), ISO/IEC 20000-1:2018 (IT service management), ISO 22301:2019 (business continuity), ISO/IEC 27001:2022 (information security), ISO/IEC 27017:2017 (cloud security controls), ISO/IEC 27018:2019 (personal data in the cloud) and ISO/IEC 27701:2019 (privacy information management). All seven are published for download with their certificate numbers and expiry dates.

Is Omnivery HIPAA certified, and can I see the certificate?

Yes, and yes. Omnivery holds HIPAA compliance certificate No. 2510225512, issued 22 October 2025 by TAYLLORCOX Institut following an independent assessment of administrative, technical and physical safeguards for Protected Health Information against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule. The certificate is published at /documents/omnivery_hipaa_certificate.pdf and requires no NDA or sales contact. HIPAA is US legislation rather than a certification scheme with an official registry, so no government-issued HIPAA certificate exists for any provider. Most providers offer a self-declaration; Omnivery offers a dated third-party assessment.

Does Omnivery sign a Business Associate Agreement?

Yes. Omnivery signs BAAs, and it is a standard part of onboarding a covered entity or business associate rather than something that has to be negotiated or escalated to a sales conversation.

Why does the ISO certificate scope say "marketing automation"?

That is the scope wording registered when Omnivery's management system was first certified in 2022, and it reflects the platform's origin in Mailkit, the email platform founded in 2006 that Omnivery grew out of. All seven certificates carry the same scope statement - "Design, development and operation of technology for marketing automation" - covering the design, development and operation of the platform. The same certified infrastructure carries transactional traffic. If a vendor review needs the scope statement to name a specific use case, raise it during onboarding.

Who issued the certificates and can I verify them independently?

All eight were issued by TAYLLORCOX, a Prague-based certification body (TAYLLORCOX s.r.o., Na Florenci 1055/35, Praha 1). Every certificate carries a certificate number, and TAYLLORCOX will confirm the validity of any of them on +420 725 536 797 or at audit@tayllorcox.com.

How does this compare with SendGrid, Mailgun or SparkPost?

SendGrid (Twilio), Mailgun (Sinch) and SparkPost (now Bird Email, MessageBird) all run on shared public cloud, and none of them publishes an ISO/IEC 27701 certificate or a HIPAA certificate. The full matrix, including the ISO 22301 and ISO/IEC 20000-1 rows, is on the provider comparison page.

Does CSA mean Cloud Security Alliance?

No. On Omnivery pages CSA means the Certified Senders Alliance, the European email sender accreditation scheme operated in Germany, of which Omnivery is a member. Omnivery makes no claim to Cloud Security Alliance membership or to a CSA STAR listing. The two organizations are unrelated and the abbreviation collision is a common source of confusion in vendor questionnaires.