Security, compliance and availability

Your customers trust you with their data, and you need to trust the platform you use to contact them. everymessage has been ISO 27001 certified since 2009, hosts its platform in UK data centres with high availability across the UK and EU, and offers up to 99.999% availability with 24/7/365 support.

Security at a glance

everymessage is an ISO 27001 certified UK communications platform. We were one of the first in the industry to achieve ISO 27001 certification, in 2009, and have held it ever since. The platform is developed and supported by our own team in the UK, hosted in UK data centres with high availability across the UK and EU, and offers up to 99.999% availability with 24/7/365 support.

ISO 27001Certified since 2009
99.999%Up to this level of availability
24/7/365Support, every day of the year
UK + EUHigh availability across UK and EU data centres

ISO 27001 certified since 2009

ISO 27001 is the international standard for information security management. It requires an organisation to identify the risks to the information it holds, put controls in place to manage them, and keep reviewing and improving those controls, with regular independent audits. everymessage was one of the first in the industry to achieve ISO 27001 certification, in 2009, and has maintained it continuously since.

UK hosting and high availability

  • The platform is hosted in UK data centres
  • High availability across UK and EU data centres, so service continues if a site has a problem
  • Up to 99.999% availability
  • Multiple carrier routes for messaging, so messages keep flowing if one supplier has a problem
  • 24/7/365 support from our own UK team

How we protect your messages and data

Secure access

Two-factor authentication is mandatory for portal administrators, so a stolen password alone can’t open an admin account.

Encrypted connections

Our APIs and portal are only available over encrypted HTTPS connections.

Fixed IP addresses

Our API is available on fixed IP addresses, and our webhooks come from a fixed IP address, so you can lock down your firewalls.

Verified senders

RCS messages come from brands verified before they can send, and WhatsApp runs on Meta’s official platform, which helps protect your customers from impersonation.

Identity checks on documents

Digital letters can be protected by identity verification, so only the right person can open them.

Audit trails

Delivery reports, transcripts and document tracking give you a record of what was sent, delivered and opened.

Helping you stay compliant

  • UK GDPR: UK hosting and ISO 27001 controls help you meet your data protection obligations
  • PECR: built-in opt-out links and automatic suppression of unsubscribed numbers and email addresses
  • Email authentication: every sending domain is set up with SPF, DKIM and DMARC
  • Supplier due diligence: one platform for every channel means one supplier to assess, and our team is happy to help with your security questionnaires

Security and compliance FAQs

Is everymessage ISO 27001 certified?

Yes. everymessage has been ISO 27001 certified since 2009, one of the first in the industry, and has maintained the certification ever since.

Where is everymessage data hosted?

The everymessage platform is hosted in UK data centres, with high availability across UK and EU data centres.

What availability does everymessage offer?

everymessage offers up to 99.999% availability, supported by high availability across UK and EU data centres and multiple carrier routes for messaging.

What support does everymessage provide?

everymessage provides 24/7/365 support from its own team in the UK.

Does the everymessage portal support two-factor authentication?

Yes. Two-factor authentication is mandatory for all portal administrator accounts.

Can we allowlist everymessage IP addresses?

Yes. The everymessage API is available on fixed IP addresses, and webhooks are sent from a fixed IP address, so you can allowlist them in your firewall.

Does everymessage help with UK GDPR and PECR?

Yes. UK hosting and ISO 27001 controls support your data protection obligations, and built-in opt-out links and automatic suppression help you meet PECR rules on marketing messages.

Need to run due diligence?

Talk to our team about your security and compliance requirements. We’re happy to help with your supplier assessment.