send25

Trust

Who runs this, and what happens to your mail.

Most providers put this on a legal page written to be unreadable. Here it is in plain language, with the parts that are inconvenient to us left in.

Who we are

Operated byMicroAge NL, St. John's, Newfoundland.A working IT company, not a holding entity. send25 is a service we run, and we use it ourselves.
Owned byOne Canadian owner. No foreign parent, no subsidiary, no US operations, no outside investors.
Where it runsOur own hardware in St. John's.Not a reseller account, not a cloud region we rent. The machine exists and we can point at it.
Who you deal withThe person who built it.There is no support tier to escalate through, because there is no tier.

What we keep

A relay has to read a message to send it. The question that matters is what is still there afterwards.

Message contentNever stored.No subject line, no body, no attachments. There is no column in our database that could hold them. Your message sits in the mail queue on disk only until it is delivered, then it is gone.
Delivery recordsSender, recipient, time, size, and the result.Enough to answer "did that invoice actually go out on the 3rd?" — which is the whole reason we keep anything.
How long30 days, then deleted.A job runs every night and removes anything older. It is enforced by the system, not a policy we intend to follow.
Bounced addressesKept while active.The one exception, and we would rather explain it than hide it. If an address hard-bounces we remember, so we stop mailing it. Deleting that record would mean resuming mail to a dead address and damaging your sending reputation. Deactivated entries are purged after a year.
What we never doSell it, share it, or train anything on it.You pay us to relay mail. We have no advertising business, no analytics product, and no investors asking us to build one.

Why this is short on purpose. Thirty days is long enough to settle a delivery question and short enough that we are not quietly building a record of who your company emails. Data we no longer hold cannot be leaked, subpoenaed, or sold. If you need a longer record than that, your own sent items are the right place for it — not our database.

Who can compel us

This is where most "Canadian hosting" claims quietly overreach, so here is the honest version.

We are a Canadian business, wholly Canadian-owned and Canadian-run, with no US parent company, no US subsidiary, and no US operations. The only government that can compel us to produce anything is Canada's, through a Canadian court, with Canadian legal remedies available to you.

That is a claim about jurisdiction, not about immunity — and the difference matters:

We can be compelledCanadian production orders apply to us like any other Canadian business. Anyone who tells you their service is beyond all government reach is selling you something.
Has it happened?No. We have never received a legal demand of any kind.If that ever changes, this line changes with it.
Is this urgent?Honestly, no.There are no documented cases of foreign law enforcement reaching into a Canadian company's hosted data. This is about structural exposure and being able to answer the question in an audit — not about an imminent threat. We would rather say so than frighten you into buying.
Storage location isn't the pointWho controls the data matters more than where it sits.A US-owned provider with a Canadian data centre is still a US-owned provider. That distinction is the reason this page exists.

We are also not going to tell you that Canadian privacy law requires you to keep your mail in Canada. For most organisations it does not. It is a reasonable preference and it makes some procurement questions easier to answer — that is all, and that is enough.

What we are not

The fair objections to a small provider, answered without spin. If any of these is a dealbreaker, we would rather you knew now than after you switched.

You are one server. What happens when it dies?

Today send25 runs on a single relay node. We are not going to dress that up.

What makes it survivable is that SMTP is store-and-forward: your printer or application queues the message locally and keeps retrying, typically for days. An outage on our side delays mail — it does not lose it. That is a property of the protocol, not a promise from us, and you can verify it against your own device's behaviour.

We would rather build a second node than advertise redundancy we do not have. Until one exists, we are not claiming it.

What if you get hit by a bus?

A real question for any small provider, and it deserves better than reassurance.

The structural answer is that you are never locked in: you control your own DNS. The records that point mail at us are in your zone, not ours, and you can repoint them at another provider in minutes without asking our permission. There is no proprietary format holding your data hostage — we run standard Postfix and rspamd, which any competent mail administrator can take over.

That is the guarantee we can actually make. A named second engineer is on the list; when there is one, this answer will say so.

Do you have SOC 2?

No, and we will be straight about why. A SOC 2 Type II audit runs tens of thousands of dollars up front plus an annual fee, on a timeline measured in quarters. At our size that cost lands on your invoice and what it buys you is a PDF.

What we offer instead is the thing SOC 2 is a proxy for: you can inspect the actual configuration. See below.

If your procurement process hard-requires SOC 2, we are the wrong vendor and we will tell you that on the first call rather than waste your time.

Is there someone there at 3am?

Not a staffed operations centre, no. Automated monitoring runs around the clock and alerts a real person, but our published response commitment is business hours, Newfoundland time, with an emergency contact for genuine emergencies. We are not going to claim staffing we do not have.

Compare that honestly against your current escalation path at a large provider before you count it against us.

Aren't the big platforms more reliable?

At their best, yes — and we are not going to claim we will beat AWS on uptime.

What we will claim is that we are more answerable. When a hyperscaler breaks, it breaks for everyone at once and there is no one to call; the October 2025 AWS and Azure outages took down services worldwide for hours. Scale does not mean no outages. It means the outage is someone else's decision and you wait it out.

Can you handle our volume?

Deliberately, only up to a point. We cap volume per customer and we cap how many customers we take. If you need to send half a million marketing emails a month, we are the wrong service and we will say so on the first call.

The caps are not a limitation we are apologising for. Shared sending reputation is the thing that actually breaks relays, and turning away traffic that would damage it is how we protect the customers we already have.

Don't take our word for it

Every claim on this page is meant to be checkable by your own IT person.

Message authenticationSend a test message to any mailbox and read the headers. SPF, DKIM and DMARC results are visible to the recipient, not just to us.
Where it runsTrace the route. Look up the sending address and its reverse DNS. The answer is a single machine in St. John's, and it will match what we told you.
What we hold on youSign in and look. Your console shows exactly the delivery records we hold, and nothing else exists.
The 30-day windowWatch it happen. Records age out and disappear on schedule; check back on something older than a month and it will be gone.
Ask us anythingIf your IT consultant wants to interrogate the configuration, put them on a call with us. We would rather answer than be taken on faith.