# Resend

> Sends the emails a piece of software triggers itself, such as sign-in links, password resets, invoices and notifications, through an API or SMTP, takes care of domain authentication, bounces and the suppression list, and reports delivery, opens and clicks back by webhook.

- Vendor: Plus Five Five, Inc., San Francisco
- Canonical URL: https://www.convios.com/en/toolbox/resend
- Language version: https://www.convios.com/de/werkzeugkasten/resend
- Area: Content & web · Cluster: transactional email
- Role: Building block · Origin: Established, AI retrofitted
- As of: 2026-09-17 · Reviewed: 2026-09-17 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: Without reliable email sending there is no sign-in link, no password reset and no invoice, and a product whose emails land in the spam folder loses users before their first login. That makes this building block mandatory. It opens no gap to competitors, because every competitor can set up the same account in five minutes. The difference to older sending services lies in the developers' work: the API, templates in React and debugging in the log are quicker to set up. For a company in the German-speaking market a different question decides: by the vendor's own account, message content, logs and account data are always stored in the United States, even when Ireland is chosen as the sending region. Anyone who promises its customers hosting in the European Union has to settle that before the first send.

## Suitability by company size

- Solo: suitable — The free plan carries 3,000 emails a month with at most 100 a day, three domains and one webhook, with no payment details. Pro costs 20 dollars a month for 50,000 emails with no daily limit. For a start-up or a side project that lasts a long time, and the data processing agreement applies from the very first account.
- Mid-market: suitable with caveats — The price fits: Scale costs from 90 dollars a month for 100,000 emails, with each further thousand at 0.90 dollars or less. The condition lies in your own customer contracts. Message content carries names, invoice amounts and sign-in links, and that data sits in the United States for 30 days. Anyone who promises customers a storage location in the European Union, or ships a subprocessor list with countries, has to add this vendor there with the country USA. The role model knows only Admin and Member, and two-factor sign-in cannot be enforced across the team.
- Enterprise: suitable with caveats — The enterprise terms of 17 August 2026 are fit for contract: 99.99 per cent availability with service credits, a termination right for repeated outages, a 90-day export window after the contract ends, a contractual training ban, a liability cap equal to a year's fees with a doubled cap for data protection breaches, and cyber insurance of at least one million dollars. Sign-in through your own identity provider costs a 150-dollar monthly surcharge on the Scale plan and is only included in the Enterprise plan, which the vendor tailors to teams sending roughly three million emails a month or more. Three points remain even there: no storage location in the European Union, no ISO/IEC 27001 certificate, and the venue is San Francisco under Californian law.

## Vendor staying power

Funded: The company behind the product is Plus Five Five, Inc., with an address in San Francisco, and the Y Combinator directory gives 2023 as the founding year and the Winter 2023 batch. A commercial register extract could not be retrieved in this run, because the State of California's register blocks automated queries. Two financings are documented with dates: a 3-million-dollar seed round on 18 July 2023 and an 18-million-dollar Series A led by Andreessen Horowitz on 4 December 2024. On 3 June 2026 the vendor writes that it has been profitable since the previous year and employs 43 people, up from 28 in December 2025. Two acquisitions in 2025 are reported by the vendor with dates.

- Legal entity and address: Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, named as processor in Exhibit B of the data processing agreement; the vendor publishes no legal notice (Impressum) (source: https://resend.com/legal/dpa, as of 2026-09-17)
- Founding and batch: founded 2023, Winter 2023 batch at Y Combinator, team size 45 per the directory, retrieved 17.09.2026, against 43 in the vendor post of 03.06.2026, status active (source: https://www.ycombinator.com/companies/resend, as of 2026-09-17)
- Seed financing 2023: 3 million dollars, vendor announcement of 18 July 2023, with Y Combinator and SV Angel plus founders such as Dylan Field, Guillermo Rauch and Paul Copplestone (source: https://resend.com/blog/resend-raises-3m-seed-round, as of 2026-09-17)
- Series A 2024: 18 million dollars led by Andreessen Horowitz, vendor and investor announcements of 4 December 2024; neither announcement states whether existing shareholders sold stakes (source: https://a16z.com/announcement/investing-in-resend/, as of 2026-09-17)
- Profitability and headcount by the vendor's own account, two dates: 18 December 2025: 1 million users, revenue up fivefold in 2025, team grown from 12 to 28 people; 3 June 2026: 3 million users, 43 people, profitable since the previous year; all figures without methodology and without published accounts (source: https://resend.com/blog/3-million-users, as of 2026-09-17)
- Acquisitions: Mergent, a background job service, announced on 23 April 2025; Briefer, announced on 5 August 2025; purchase prices not disclosed (source: https://resend.com/blog/resend-acquires-mergent, as of 2026-09-17)

## Cost of leaving

Low: For plain transactional email the switch is small. Sending runs through an API or SMTP, and any other service accepts the same messages. Templates can be built with React Email, an open-source library from the vendor under the MIT licence that also works with other sending services. CSV exports exist for emails, broadcasts, contacts, domains, logs and keys. Three things still take time. First, deliverability: new DNS records for DKIM and SPF, and with dedicated IP addresses a warm-up phase in which emails arrive more slowly or in spam. Second, the suppression list of bounces and complaints, which has to move along so that blocked addresses stay blocked. Third, everything built in the vendor's editor: broadcasts, automations and editor templates exist in no standard format. Anyone running marketing there should plan for medium effort. The standard contract has no export window after cancellation, and deleting a team is immediate and final; only the enterprise terms guarantee 90 days of export.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | public, automatically in force for every account, with EU standard contractual clauses — The data processing agreement in its version of 27 August 2026 is available without login and, according to the GDPR page, takes effect when the account is created, pre-signed by the vendor, with no separate countersignature and tied to no plan. It covers subprocessors with 14 days' prior notice and a right to object, support with data subject requests, breach notification without undue delay, and audit rights once a year at the customer's cost. It carves out one role expressly: under Section 9 the vendor is an independent controller for account, billing and usage data. By its own account the vendor only negotiates changes to the agreement on the Enterprise plan. | evidenced | 2026-09-17 |
| Storage location | United States for all customer data; the Ireland region only controls sending — This is the profile's most important finding. When adding a domain you choose a sending region, including Ireland, and the vendor automatically recommends that region to users in Europe. The documentation on choosing a region makes clear, however, that the region only determines where emails are sent from. Message content, delivery logs, webhook payloads and account data sit in the United States regardless, and according to the GDPR page there is no setting that moves stored data to the European Union. Section 6.1 of the data processing agreement records that processing takes place primarily in the United States. The location is therefore clearly named, but the customer cannot choose it. | partially evidenced | 2026-09-17 |
| Subprocessors | 22 named with purpose, all with the country USA; two analytics services only in the privacy policy — The list of 27 August 2026 names 22 subprocessors with purpose and the country USA for each, among them Amazon Web Services for hosting and sending, PlanetScale and Supabase for databases, Snowflake and Tinybird for data analysis, Svix for webhooks, Cloudflare as firewall, plus Anthropic for artificial intelligence and RunPod for self-hosted language models. Which customer data each service receives is not stated. The condition comes from the comparison: the privacy policy of the same date names Mixpanel and Plausible for analysing use of the service, and both are missing from the list. Anyone passing a list of their own on to customers should ask before signing whether customer data runs through those two services. | partially evidenced | 2026-09-17 |
| Third-country transfer | transfer to the United States, based on standard contractual clauses and the EU-US Data Privacy Framework — The legal basis is anchored in the contract. Section 6.2 of the data processing agreement counts as entering into the EU standard contractual clauses, module two for controllers and module three for processors, under Irish law and Irish courts, plus the UK addendum and adjustments for Switzerland. Section 11 adds the certification under the EU-US Data Privacy Framework, which the vendor announced on 13 March 2025, and the GDPR page stresses that the standard contractual clauses apply independently of it. Section 6.6 contains supplementary measures on requests from authorities. That gives procurement everything it needs for its own transfer impact assessment. | evidenced | 2026-09-17 |
| Training on customer data | contractual training ban only in the enterprise terms; standard terms are silent — Section 6.4 of the enterprise terms of 17 August 2026 prohibits using customer content to train models offered to other customers and excludes message bodies and recipients' personal data from any training corpus. Internal systems for spam detection, abuse and deliverability remain exempt, and Section 6.3 allows aggregated, de-identified data for the vendor's own purposes. The terms of service and the privacy policy that apply to the Free, Pro and Scale plans say nothing about training. That matters, because the product runs AI features on customer content and lists Anthropic and RunPod as subprocessors. Anyone buying below the Enterprise plan does not have the commitment. | partially evidenced | 2026-09-17 |
| Retention and deletion | 30 days in ongoing operation, deletion within 90 days after the account ends, backups 7 days; enterprise terms with a different period — The periods are quantified. On the Free, Pro and Scale plans emails and logs are kept for 30 days, on the Enterprise plan as agreed. Exhibit A of the data processing agreement promises deletion within 90 days after the account ends, and according to the security page backups exist for 7 days. The condition lies in the comparison with Section 15.4 of the enterprise terms: there a 90-day export window is followed by 30 days until deletion from production systems, up to 120 days in total. Which period applies belongs in the order form. At the same time, the 30-day period means that evidence of a sent email has gone from the vendor after one month. | partially evidenced | 2026-09-17 |
| Certifications | SOC 2 Type II, reporting period 1 February 2025 to 1 February 2026, report only after login; no ISO/IEC 27001 — One attestation is documented with auditor and period: SOC 2 Type II, audited by Advantage Partners, reporting period 1 February 2025 to 1 February 2026, plus an annual penetration test with a letter of attestation. Report and letter sit in the account's documents area; only the summary is public. The GDPR page expressly denies an ISO/IEC 27001 certificate and suitability for health data under HIPAA. The ISO attestations in Exhibit C of the data processing agreement belong to the data centre operators. The last publicly named reporting period ended on 1 February 2026; whether a follow-up report exists is not publicly visible. | partially evidenced | 2026-09-17 |
| EU AI Act, Article 50 | AI features write email copy, no statement on the regulation — The product contains an AI system within the meaning of Regulation 2024/1689: in the editor it generates entire emails and rewrites passages, it builds automations, suggests subject lines and preview text, reviews content and answers questions through an assistant. The pricing page bills this through AI credits, and Section 9 of the enterprise terms covers outputs from third-party models and automated agents whose consequences the customer bears. The vendor mentions neither the regulation itself nor an ISO/IEC 42001 certification in any document read. Generated text only reaches recipients once the customer sends it, so the operator can set a label itself. Whether the vendor sees itself bound by Article 50 for text generation, it does not say. | partially evidenced | 2026-09-17 |
| Audit logging | log of API calls with export, 30 days; no documented audit log for sign-ins and team changes — In the dashboard customers see every API call with endpoint, method, status code, time, key, and request and response body, filterable, available through a dedicated API since 9 April 2026 and exportable as CSV. On the standard plans the retention period is 30 days. That answers the question of which machine sent what and when. The second half stays open: a log of dashboard sign-ins, role changes, keys created in the interface or changed domains is described neither in the documentation nor in the contract. Exhibit C of the data processing agreement describes logging only on the vendor's side. | partially evidenced | 2026-09-17 |

## Cost

- Entry: Transactional email: Free with 3,000 emails a month and at most 100 a day, Pro from 20 dollars a month for 50,000 emails, Scale from 90 dollars for 100,000 up to 1,150 dollars for 2.5 million emails, with each further thousand at between 0.90 and 0.46 dollars. Marketing email is billed separately by contacts, from 40 dollars a month for 5,000 contacts. Enterprise on quote. (as of 2026-09-17)
- Where it gets expensive: In four places. First, sign-in through your own identity provider: a 150-dollar monthly surcharge on Scale, so 1,800 dollars a year just for sign-in, or a move to the Enterprise plan. Second, separate budgets: anyone sending both transactional and marketing email through the vendor pays both plans side by side, plus AI credits that expire each month and automation runs above 10,000 at 0.0015 dollars per run. Third, add-ons: a dedicated IP address for 30 dollars a month from 3,000 emails a day, and another 100 domains for 20 dollars. Fourth, the terms: under the terms of service prices may change at the end of every billing cycle, paid fees are not refunded, and liability is capped at the amount paid.

## Three routes compared

### Stay with an established sending service or pick one with EU storage

Twilio SendGrid and Mailgun are the counterparts large groups stay with: a long operating history, their own IP pools, framework agreements with procurement and deliverability consulting. The price is older APIs and more setup effort, and anyone leaving them usually does so because of the developer work. For a company that promises its customers data storage in the European Union, sending services based or storing data in the Union such as Mailjet or Brevo deserve a look. In both cases the concrete storage location of message content belongs in the contract in writing before deciding, because sending region and storage location do not necessarily coincide there either.

### A ground-up AI-native counterpart barely exists in this cluster

Email sending is infrastructure: DNS records, IP reputation, bounces and complaint rates decide, and a language model changes little there. In this cluster the vendor itself has gone furthest toward agents, with a hosted MCP server, a command line tool, skills for coding assistants and an inbox agents can react to. Anyone using that lets an agent send emails, maintain contacts and trigger broadcasts. What you give up is control: under Section 9 of the enterprise terms the customer bears the consequences of whatever an agent acting on its rules does. So the first thing to check is which keys an agent gets; the API knows keys that may only send.

### Send through Amazon SES in Frankfurt with your own layer on top

Anyone who wants to decide storage location and costs themselves builds the layer on top of a raw service. Amazon SES in the Frankfurt region handles sending, templates are built with React Email, send jobs run through n8n, bounces and complaints come back as notifications and land together with the send log and suppression list in Supabase in a European region, built with Claude Code. At 8 person-days and 1,200 euros a day that is roughly 9,600 euros one-off against 1,080 dollars a year for Scale with 100,000 emails. The arithmetic tips in three places, and none of them is the sending. The first is deliverability: warming up the domain, evaluating DMARC reports, keeping complaint rates below Google's and Yahoo's thresholds and reacting when an address lands on a blocklist. The second is on-call duty: if sending fails at night, no sign-in link arrives. The third is maintenance after the builder leaves. It pays off when a customer contract demands storage in the Union and email volume is high.

Recommendation by size:

- Solo: Take it. The free plan and Pro carry a young product for a long time, and the switch stays small as long as templates live in React Email.
- Mid-market: Take it if no customer contract promises storage in the European Union. Otherwise add the vendor with the country USA to your own subprocessor list first, or pick a service with EU storage.
- Enterprise: Only consider it with an Enterprise contract. Settle storage location, training ban, deletion period, audit log and venue in writing before signing.

## Context

- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The method measures how many obligations hang on a data flow. Application emails carry names, amounts and sign-in links, and the test shows whether storage in the United States is a footnote or a knock-out criterion for your own business.
- Implements method: [Activation as the Retention Lever](https://www.convios.com/en/methods/activation-as-retention-lever) — Activation decides retention, and a new user's first touchpoint is often a confirmation or sign-in email. The method directs attention to deliverability as an activation metric in this case.
- Implements method: ["Context: Moat or Wall?" Test](https://www.convios.com/en/methods/context-moat-or-wall-test) — The test asks whether an advantage remains when competitors buy the same thing. With email sending it does not, which explains why the building block is mandatory and why the choice should turn on storage location and contract.
- Displaces: Sending email through your web host's SMTP server, Self-run Postfix mail servers for application email, Hand-coded HTML table layouts for sign-in and invoice emails, Sorting bounces and complaints in a shared mailbox

## Evidence

- Data processing agreement of 27 August 2026: Plus Five Five, Inc. as processor with an address in San Francisco, subprocessors with 14 days' notice, transfers under modules two and three of the EU standard contractual clauses under Irish law, processing primarily in the United States, supplementary measures on requests from authorities, independent controllership for account and usage data, Data Privacy Framework, deletion within 90 days after the account ends — https://resend.com/legal/dpa (as of 2026-09-17)
- Subprocessor list of 27 August 2026 with 22 entries, all with the country USA, including Anthropic for artificial intelligence and RunPod for self-hosted language models — https://resend.com/legal/subprocessors (as of 2026-09-17)
- Privacy policy of 27 August 2026: transfer to the United States, Mixpanel and Plausible for usage analytics, no statement on training — https://resend.com/legal/privacy-policy (as of 2026-09-17)
- Terms of service of 27 August 2026: price changes at the end of each billing cycle, no refunds, liability capped at the amount paid, Californian law, no statement on training or an export period — https://resend.com/legal/terms-of-service (as of 2026-09-17)
- Enterprise terms of 17 August 2026: 99.99 per cent availability with service credits and a termination right for repeated outages, first response within one business day with no remedy, aggregated data, training ban in Section 6.4, AI features and agents in Section 9, liability caps, cyber insurance of at least one million dollars, 90-day export window and 30 days until deletion, venue San Francisco — https://resend.com/legal/enterprise-terms (as of 2026-09-17)
- GDPR page: all customer data stored in the United States regardless of sending region, agreement pre-signed for every account, 30-day retention on Free, Pro and Scale, deletion within 90 days, backups 7 days, no ISO/IEC 27001 and no HIPAA, contract changes only on the Enterprise plan — https://resend.com/security/gdpr (as of 2026-09-17)
- Documentation on choosing a region: four sending regions, the region only controls route and sending location, account and email data sit in the United States — https://resend.com/docs/dashboard/domains/regions (as of 2026-09-17)
- SOC 2 Type II, audited by Advantage Partners, reporting period 1 February 2025 to 1 February 2026, report and penetration test only after login — https://resend.com/security/soc-2 (as of 2026-09-17)
- Security page: encryption at rest and in transit, backups 7 days, HIPAA in progress — https://resend.com/security (as of 2026-09-17)
- Prices of the transactional and marketing plans, add-ons for domains, dedicated IP address and identity provider sign-in, automation runs, AI credits and the list of AI features, Enterprise tailored from roughly three million emails a month — https://resend.com/pricing.md (as of 2026-09-17)
- Log of API calls with endpoint, status, key and request and response body in the dashboard — https://resend.com/docs/dashboard/logs/introduction (as of 2026-09-17)
- Admin and Member roles, two-factor sign-in cannot be enforced team-wide — https://resend.com/docs/dashboard/settings/team (as of 2026-09-17)
- Sign-in through your own identity provider since 1 September 2026, an add-on on Scale and included on Enterprise — https://resend.com/changelog/sso (as of 2026-09-17)
- CSV exports for emails, broadcasts, contacts, domains, logs and keys, generally available since 13 November 2025 — https://resend.com/changelog/exports-general-availability (as of 2026-09-17)
- Certification under the EU-US Data Privacy Framework, announced on 13 March 2025 — https://resend.com/changelog/data-privacy-framework-certification (as of 2026-09-17)
- Founded 2023, Winter 2023 batch at Y Combinator, team size 45 — https://www.ycombinator.com/companies/resend (as of 2026-09-17)
- Seed financing of 3 million dollars on 18 July 2023 with Y Combinator, SV Angel and founders as backers — https://resend.com/blog/resend-raises-3m-seed-round (as of 2026-09-17)
- Series A of 18 million dollars led by Andreessen Horowitz, announced on 4 December 2024, more than 200,000 registered developers by the vendor's own account — https://resend.com/blog/series-a (as of 2026-09-17)
- Investor announcement of the investment dated 4 December 2024 — https://a16z.com/announcement/investing-in-resend/ (as of 2026-09-17)
- Vendor announcement of 18 December 2025: 1 million users, revenue up fivefold, team grown from 12 to 28 people, two acquisitions — https://resend.com/blog/1-million-users (as of 2026-09-17)
- Vendor announcement of 3 June 2026: 3 million users, 43 people, profitable since the previous year — https://resend.com/blog/3-million-users (as of 2026-09-17)
- Acquisition of Mergent, announced on 23 April 2025 — https://resend.com/blog/resend-acquires-mergent (as of 2026-09-17)
- Documented outage on 15 February 2026 lasting 3 hours and 31 minutes, emails delayed by about two hours, none lost, dashboard unreachable — https://resend.com/blog/incident-report-for-february-15-2026 (as of 2026-09-17)
- Documented outage on 18 November 2025 from 11:30 to 14:31 UTC caused by a Cloudflare disruption, through which all API traffic runs — https://resend.com/blog/incident-report-for-november-18-2025 (as of 2026-09-17)
- Since 5 May 2026, AI chats in the editor and in automations draw on your own broadcasts, templates and properties — https://resend.com/changelog/mentions-in-ai-chats (as of 2026-09-17)
- No legal notice (Impressum) in the vendor's sitemap of 950 addresses — https://resend.com/sitemap.xml (as of 2026-09-17)
