Information for supplier questionnaires (NIS2)
If your company falls under NIS2, you have to assess your suppliers. So that you do not have to ask us every time, the usual answers are here to copy.
| Question | Answer for SMTPly |
|---|---|
| Does the vendor process our data? | No. SMTPly runs entirely on your server. There is no telemetry and no cloud hop; message content goes exclusively to your own Microsoft 365. Other outbound connections: a daily license check with Polar (license key and a hashed server identifier, no content) and the update check with smtply.app or GitHub. |
| Is a data processing agreement required? | No, because no processing takes place on our behalf. Your existing relationship with Microsoft is unaffected. |
| Are the released files signed? | Yes. Installer and program files are signed through Azure Artifact Signing, issued to IT-Beratung - Andreas Hähnel. A SHA-256 checksum is published for every version, and the in-app update verifies both checksum and signature before installing. |
| Is there a contact point for vulnerabilities? | Yes, per RFC 9116 at /.well-known/security.txt. Acknowledgement within three working days. |
| Is there a documented reporting process? | Yes, written down and aligned with the Cyber Resilience Act deadlines: 24 hours, 72 hours, final report. |
| Can you provide a software bill of materials (SBOM)? | Yes. A bill of materials in CycloneDX format is produced at build time for every version. On request we provide it for the version you run. |
| Has the software been security tested? | Yes. A security review was carried out and the findings implemented. Dependencies are checked against the vulnerability database on every build. |
| How large is the vendor risk? | SMTPly comes from a one-person business, so there is no round-the-clock on-call. More relevant for your risk assessment is the architecture: the software runs with no connection to the vendor. If the vendor were to disappear, your mail delivery would keep working unchanged. With a cloud relay that would be different. |
This describes the state of the software and is not legal advice. Whether and how NIS2 applies to your company is for you or your legal counsel to decide.