---
title: Certifications
url: 'https://omnivery.com/about/certifications'
markdown: 'https://omnivery.com/about/certifications.md'
lang: en
date: '2026-08-11'
description: 'Every Omnivery certification with its certificate number, standard version, scope and expiry: seven ISO standards plus HIPAA, all published for download.'
---

Trust and compliance

# Seven ISO standards plus HIPAA, all published

Omnivery publishes every certificate it holds, with the certificate number, the standard version, the certified scope and the expiry date. Nothing here requires a sales call to verify.

Last reviewed July 2026

[Download all ISO certificates](https://omnivery.com/documents/omnivery_iso_certificates.pdf)[Download HIPAA certificate](https://omnivery.com/documents/omnivery_hipaa_certificate.pdf)

## What Omnivery is certified to

Omnivery holds seven ISO certifications and an independently assessed HIPAA compliance certificate. All eight are issued by TAYLLORCOX, a Prague-based certification body, and all eight are available to download below.

7

ISO standards certified

1

HIPAA compliance certificate

2022

first ISO certification

8

certificates published for download

ISO certifications

## The seven ISO certificates in full

Each certificate is issued to Omnivery s.r.o. (company ID 25734105), Oranžová 225, 252 19 Chrášťany, Czech Republic, by the certification body TAYLLORCOX GCS.

 | Standard | Management system certified | Certificate No. | First certified | Valid until | Document |
|---|---|---|---|---|---|
| **ISO 9001:2015** | Quality Management System | 2505302253 | 2 June 2022 | 2 June 2027 | [PDF](https://omnivery.com/documents/9001.pdf) |
| **ISO/IEC 20000-1:2018** | Information Technology Service Management System | 2505307112 | 30 May 2025 | 29 May 2028 | [PDF](https://omnivery.com/documents/omnivery_iso_certificates.pdf) |
| **ISO 22301:2019** | Business Continuity Management Systems | 2505308267 | 2 June 2022 | 2 June 2027 | [PDF](https://omnivery.com/documents/22301.pdf) |
| **ISO/IEC 27001:2022** | Information Security Management System | 2505303078 | 2 June 2022 | 2 June 2027 | [PDF](https://omnivery.com/documents/27001.pdf) |
| **ISO/IEC 27017:2017** | Code of practice for information security controls based on ISO/IEC 27002 for cloud services | 2505305996 | 30 May 2025 | 29 May 2028 | [PDF](https://omnivery.com/documents/omnivery_iso_certificates.pdf) |
| **ISO/IEC 27018:2019** | Code of Practice for Protecting Personal Data in the Cloud | 2505305789 | 30 May 2025 | 29 May 2028 | [PDF](https://omnivery.com/documents/omnivery_iso_certificates.pdf) |
| **ISO/IEC 27701:2019** | Privacy Information Management System | 2505307311 | 4 August 2023 | 2 June 2027 | [PDF](https://omnivery.com/documents/27701.pdf) |

All figures taken from the certificates themselves, issued by TAYLLORCOX GCS (TAYLLORCOX s.r.o., Na Florenci 1055/35, Praha 1). ISO/IEC 20000-1, 27017 and 27018 are published in the combined ISO certificate pack; 9001, 22301, 27001 and 27701 are additionally available as individual documents. The ISO/IEC 27001 certificate is valid in conjunction with the Statement of Applicability dated 8 January 2024.

What they buy you

## What the less familiar certifications cover

ISO/IEC 27001 is common among email providers. The ones below are not.

### ISO/IEC 27701 - privacy

Extends the 27001 management system to personal data specifically, which is the standard a GDPR-focused reviewer asks about. Omnivery has held it since August 2023. Neither SendGrid, Mailgun nor SparkPost publishes an ISO/IEC 27701 certificate.

### ISO 22301 - business continuity

Certifies a tested continuity management system rather than a written recovery plan. Financial services and insurance reviews frequently require evidence of this, and a policy document is not evidence.

### ISO/IEC 20000-1 - service management

Covers IT service management: incident handling, change control and service levels as an audited system. This is the standard that operational resilience and third-party risk questionnaires map onto.

### ISO/IEC 27017 and 27018 - cloud and cloud privacy

Cloud-specific control sets: 27017 for information security controls in cloud services, 27018 for protecting personal data in the cloud. Both apply to how Omnivery governs the infrastructure it owns and operates itself.

HIPAA

## The HIPAA certificate

HIPAA is United States legislation, not a certification scheme. No government body issues a HIPAA certificate, which is why most email providers describe themselves as "HIPAA compliant" or "HIPAA ready" and offer nothing a reviewer can inspect.

Omnivery holds an independent third-party assessment instead. Certificate No. 2510225512, issued 22 October 2025 by TAYLLORCOX Institut, confirms that Omnivery s.r.o. underwent an independent assessment of its administrative, technical and physical safeguards for the protection of Protected Health Information, against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule (45 CFR Parts 160, 162 and 164). The recorded result is that compliance with HIPAA requirements has been confirmed.

Unlike the ISO certificates, the HIPAA document carries an assessment date rather than an expiry date.

**Business Associate Agreements: yes.** Omnivery signs BAAs as a standard part of onboarding a covered entity or business associate. See [HIPAA compliant email](https://omnivery.com/solutions/hipaa-compliant-email) for how the platform handles PHI, including message content never being stored and metadata capped at 30 days.

[Download the HIPAA certificate (PDF)](https://omnivery.com/documents/omnivery_hipaa_certificate.pdf)

Certified scope

## What the certificates cover

All seven ISO certificates carry the same registered scope:

> Design, development and operation of technology for marketing automation.

The scope covers the design, development and operation of the platform. It was registered when Omnivery's management system was first certified in 2022 and uses the wording of Mailkit, the email platform founded in 2006 that Omnivery grew out of. The same certified infrastructure carries transactional traffic today.

If your vendor review needs the scope statement to name your specific use case, raise it with us during onboarding.

### Verifying a certificate

Certificate numbers are printed on every document above. TAYLLORCOX can confirm the validity of any of them directly: +420 725 536 797 or audit@tayllorcox.com.

Processing and memberships

## Sub-processors, memberships and the CSA acronym

### Sub-processors

There are no US sub-processors in the core email service; US-incorporated vendors apply only to optional, customer-selectable features. Omnivery engages two sub-processors, each attached to an optional feature and both processing in the EU: **Bouncer Sp. z o.o.** (Wrocław, Poland) for e-mail validation, and **ProfiSMS s.r.o.** (Prague, Czechia) for SMS delivery. Bouncer in turn runs on **Amazon Web Services** infrastructure in the Frankfurt region, as Bouncer's own sub-processor rather than one Omnivery engages. If you enable neither feature, no data reaches any of them.

Omnivery's processing entity is the Czech company, and the delivery path runs on infrastructure Omnivery owns, with no AWS, Azure or Google Cloud beneath it. The published sub-processor list is on the [GDPR page](https://omnivery.com/legal/gdpr), and the regulatory analysis, including CLOUD Act and Schrems II, is on the [GDPR compliant email API](https://omnivery.com/solutions/gdpr-compliant-email-api) page.

Message body content is never stored. Delivery metadata is capped at 30 days, and strict privacy mode anonymizes it fully.

### Industry accreditation and memberships

Omnivery is a certified member of the [Certified Senders Alliance](https://certified-senders.org/), the European sender accreditation scheme operated in Germany. CSA admission is not a subscription: an applicant has to pass a certification process against the CSA's legal and technical criteria, and has to keep meeting them to stay listed. Receivers in Germany and the wider DACH region treat CSA listing as a sender-side trust signal, which is why it carries weight there specifically.

Omnivery is also a member of [M3AAWG](https://www.m3aawg.org/), the global anti-abuse working group, and of [Signal Spam](https://www.signal-spam.fr/) in France. Those two are memberships rather than certifications. All three matter operationally for the same reason: they make escalation possible at receivers with no public contact route.

CSA accreditation is separate from the seven ISO certifications and HIPAA listed above, which are accredited third-party audits issued by TAYLLORCOX.

### CSA means Certified Senders Alliance

Not Cloud Security Alliance. Omnivery holds no Cloud Security Alliance membership and no CSA STAR listing. The two organizations are unrelated, and a vendor questionnaire using the abbreviation can easily mean one and receive an answer about the other.

At a glance

## Omnivery certifications at a glance

- Omnivery holds seven ISO certifications: ISO 9001:2015, ISO/IEC 20000-1:2018, ISO 22301:2019, ISO/IEC 27001:2022, ISO/IEC 27017:2017, ISO/IEC 27018:2019 and ISO/IEC 27701:2019.
- Omnivery holds an independently issued HIPAA compliance certificate, No. 2510225512, dated 22 October 2025, assessed against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule (45 CFR Parts 160, 162 and 164).
- All eight certificates are published for public download. No NDA or sales contact is required to obtain them.
- Every certificate is issued to Omnivery s.r.o., company ID 25734105, Chrášťany, Czech Republic, by the certification body TAYLLORCOX.
- The ISO 9001, ISO 22301, ISO/IEC 27001 and ISO/IEC 27701 certificates run to 2 June 2027. The ISO/IEC 20000-1, ISO/IEC 27017 and ISO/IEC 27018 certificates run to 29 May 2028.
- Omnivery was first ISO certified on 2 June 2022, covering ISO 9001, ISO 22301 and ISO/IEC 27001.
- The registered scope on all seven ISO certificates reads "Design, development and operation of technology for marketing automation" and covers the platform itself.
- Omnivery signs Business Associate Agreements for HIPAA-covered senders as a standard part of onboarding.
- There are no US sub-processors in the core email service. US-incorporated vendors apply only to optional, customer-selectable features: e-mail validation uses Bouncer Sp. z o.o. (Poland), which runs on Amazon Web Services infrastructure in the Frankfurt region, and SMS uses ProfiSMS s.r.o. (Czechia). All processing is in the EU.
- Omnivery is a certified member of the Certified Senders Alliance, having passed its certification process against the CSA legal and technical criteria, and is a member of M3AAWG and Signal Spam. CSA here means Certified Senders Alliance, not Cloud Security Alliance.
- Neither SendGrid, Mailgun nor SparkPost publishes an ISO/IEC 27701 certificate or a HIPAA certificate.

Questions

## Certification questions

How many ISO certifications does Omnivery hold?

Seven. ISO 9001:2015 (quality management), ISO/IEC 20000-1:2018 (IT service management), ISO 22301:2019 (business continuity), ISO/IEC 27001:2022 (information security), ISO/IEC 27017:2017 (cloud security controls), ISO/IEC 27018:2019 (personal data in the cloud) and ISO/IEC 27701:2019 (privacy information management). All seven are published for download with their certificate numbers and expiry dates.

Is Omnivery HIPAA certified, and can I see the certificate?

Yes, and yes. Omnivery holds HIPAA compliance certificate No. 2510225512, issued 22 October 2025 by TAYLLORCOX Institut following an independent assessment of administrative, technical and physical safeguards for Protected Health Information against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule. The certificate is published at /documents/omnivery\_hipaa\_certificate.pdf and requires no NDA or sales contact. HIPAA is US legislation rather than a certification scheme with an official registry, so no government-issued HIPAA certificate exists for any provider. Most providers offer a self-declaration; Omnivery offers a dated third-party assessment.

Does Omnivery sign a Business Associate Agreement?

Yes. Omnivery signs BAAs, and it is a standard part of onboarding a covered entity or business associate rather than something that has to be negotiated or escalated to a sales conversation.

Why does the ISO certificate scope say "marketing automation"?

That is the scope wording registered when Omnivery's management system was first certified in 2022, and it reflects the platform's origin in Mailkit, the email platform founded in 2006 that Omnivery grew out of. All seven certificates carry the same scope statement - "Design, development and operation of technology for marketing automation" - covering the design, development and operation of the platform. The same certified infrastructure carries transactional traffic. If a vendor review needs the scope statement to name a specific use case, raise it during onboarding.

Who issued the certificates and can I verify them independently?

All eight were issued by TAYLLORCOX, a Prague-based certification body (TAYLLORCOX s.r.o., Na Florenci 1055/35, Praha 1). Every certificate carries a certificate number, and TAYLLORCOX will confirm the validity of any of them on +420 725 536 797 or at <audit@tayllorcox.com>.

How does this compare with SendGrid, Mailgun or SparkPost?

SendGrid (Twilio), Mailgun (Sinch) and SparkPost (now Bird Email, MessageBird) all run on shared public cloud, and none of them publishes an ISO/IEC 27701 certificate or a HIPAA certificate. The full matrix, including the ISO 22301 and ISO/IEC 20000-1 rows, is on the [provider comparison](https://omnivery.com/compare) page.

Does CSA mean Cloud Security Alliance?

No. On Omnivery pages CSA means the Certified Senders Alliance, the European email sender accreditation scheme operated in Germany, of which Omnivery is a member. Omnivery makes no claim to Cloud Security Alliance membership or to a CSA STAR listing. The two organizations are unrelated and the abbreviation collision is a common source of confusion in vendor questionnaires.

## Published, numbered, verifiable

Every certificate on this page is downloadable without a form, an NDA or a sales call. Forward them to your security reviewer as they are.

 [Download all ISO certificates](https://omnivery.com/documents/omnivery_iso_certificates.pdf)[Talk to us about a vendor review](https://app.omnivery.com/invite)

---

## Navigation

- Parent: [About Us](https://omnivery.com/about.md)
- Previous: [Partners](https://omnivery.com/about/partners.md)
