UK-Based Infrastructure Provider

Compliance-First
Transactional Messaging
Infrastructure

Authridge delivers enterprise-grade secure communication infrastructure for SaaS platforms, financial institutions, and regulated businesses across the UK and Europe.

99.5%Delivery Rate
0.2%Bounce Rate
0.01%Complaint Rate
100%KYC Verified Clients
Authridge API — Live Status
endpoint:smtp.authridge.co.uk:587
auth_method:STARTTLS + OAuth2
tls_version:TLSv1.3
dkim_status:✓ PASS
spf_status:✓ PASS
dmarc_policy:reject
ip_reputation:97/100
compliance:UK GDPR • PECR
Delivery Rate
99.5%
Health Score
98.4
Uptime SLA
99.99%
Bounce Rate
0.2%

Trusted by regulated enterprises across the UK and Europe

FinServ Group Meridian Health LegalBridge UK NovaSaaS Ltd ClearTrust PLC

Infrastructure built for compliance

Every component of Authridge's platform is designed for enterprises operating in regulated environments where reliability and accountability are non-negotiable.

📨

Transactional Email Infrastructure

High-throughput transactional messaging delivery with full audit trails, bounce management, and real-time reporting dashboards.

🔒

Secure SMTP Relay

Dedicated SMTP relay endpoints with enforced STARTTLS, DANE support, and mutual TLS authentication for enterprise senders.

🔗

Communication API

RESTful API for programmatic message dispatch, suppression list management, webhook callbacks, and delivery analytics retrieval.

Domain Authentication

Guided onboarding for SPF, DKIM, and DMARC configuration with automated validation checks and ongoing monitoring alerts.

🛡️

Dedicated IP Allocation

Isolated IP pools with managed warm-up schedules, proactive blacklist monitoring, and separate pools for critical traffic classes.

📊

Delivery Analytics

Granular reporting on delivery, bounce, complaint, and open metrics with exportable audit logs for regulatory compliance.

We do not support unsolicited bulk email — ever.

Authridge is strictly a transactional messaging provider. All accounts undergo manual compliance review and identity verification prior to activation. We enforce opt-in communication requirements across our entire platform with automated abuse detection and immediate suspension policies for policy violations.

Opt-in communications only
Manual review for all new accounts
KYC identity verification required
UK GDPR and PECR compliance framework
Automated abuse detection and monitoring
Immediate suspension for policy violations
Regulatory Frameworks Active
UK GDPRPECRCAN-SPAMISO 27001SOC 2 Type IIICO Registered

All new client accounts are subject to a comprehensive onboarding review including business verification, intended use case assessment, and legal entity confirmation. Accounts suspected of violating our Acceptable Use Policy are suspended immediately and referred to our internal risk and compliance team.

Founded in London to solve enterprise communication infrastructure

Authridge Ltd was founded in 2021 by a team of infrastructure engineers and compliance specialists with backgrounds in financial services technology. The company was established to address a clear gap in the UK market: the absence of a purpose-built, compliance-first transactional messaging provider built to meet the standards of regulated industries.

Our Mission

We provide the infrastructure backbone for transactional communications that regulated organisations depend upon. Our platform is not a bulk mailing service — it is a precision delivery layer built around identity verification, domain authentication, and continuous compliance monitoring.

Every decision we make as a company prioritises the integrity of the email ecosystem and the trust placed in us by our clients and their end users.

Legal Entity

Registered Name
Authridge Ltd
Company Number14287163
VAT NumberGB 412 8834 05
IncorporatedMarch 2021
JurisdictionEngland & Wales
ICO RegistrationZB489714

Leadership Team

JH

James Hartwell

Chief Executive Officer

Former Head of Infrastructure Engineering at a FTSE 250 financial services firm. 18 years' experience in enterprise messaging and identity systems.

SR

Sophie Ramshaw

Chief Compliance Officer

Data protection and regulatory compliance specialist. Former senior adviser at the Information Commissioner's Office (ICO). LLM, University of Edinburgh.

DP

Daniel Petrov

Chief Technology Officer

Distributed systems engineer with expertise in high-availability messaging infrastructure, TLS implementation, and abuse detection systems.

Registered Office

Authridge Ltd
71–75 Shelton Street
Covent Garden
London WC2H 9JQ
United Kingdom

Infrastructure for every critical use case

Authridge's platform is purpose-built for transactional messaging only. Our solutions cover every layer of the email delivery stack, from authentication to reputation management.

📨

Transactional Email Infrastructure

Core Service

Our transactional email infrastructure is designed exclusively for system-generated, opt-in communications: account notifications, password resets, order confirmations, statements, and regulatory disclosures. All sending is subject to strict use case validation during the onboarding process.

Features include: dedicated MX routing, real-time delivery status webhooks, configurable retry logic, suppression list enforcement, and full MIME audit logging. Messages are never queued for bulk or marketing delivery — all traffic passes through transactional routing rules with per-message latency targets.

🔒

Secure SMTP Relay

Infrastructure

Our SMTP relay service provides authenticated, encrypted relay endpoints for enterprise senders requiring a robust outbound gateway. Connections are secured with STARTTLS (enforced), with TLSv1.3 preferred and TLSv1.2 as a minimum requirement.

Relay access is restricted to approved IP addresses and authenticated credentials. All sessions are logged, rate-limited per account tier, and monitored for anomalous behaviour by our automated abuse detection systems.

🔗

Communication API

Developer

The Authridge RESTful API enables programmatic integration of transactional messaging into applications. Endpoints are available for message dispatch, template management, suppression list operations, domain verification status, and analytics retrieval.

API access is issued following successful account approval. All API keys are scoped to specific sending domains and carry rate limits aligned with account tier. API usage is fully audited and visible within the client dashboard.

🛡️

Reputation & IP Management

Compliance

Dedicated IP pools are allocated per client on qualifying plans, with structured warm-up programmes managed by our delivery team. We monitor all IPs against major blacklist databases (Spamhaus, Barracuda, Sorbs) in real time and provide immediate notification and remediation support in the event of a listing.

Bounce and complaint feedback loops are configured for all major ISPs. Complaint rates are monitored continuously and accounts approaching threshold limits receive automated notifications before suspension is considered.

Built for regulated sectors

Authridge's platform is designed for organisations where the integrity of transactional communications carries legal and reputational weight.

🏦
Financial Services
FCA-regulated firms, challenger banks, payment processors, and insurance providers requiring compliant transactional notification infrastructure.
⚖️
Legal & Professional Services
Law firms, accountancy practices, and regulated professional bodies requiring auditable, secure client communication channels.
🏥
Healthcare & MedTech
NHS-adjacent digital health platforms, CQC-regulated providers, and medical device software requiring GDPR-compliant messaging.
📦
Enterprise SaaS
B2B software platforms that generate high volumes of transactional system notifications, onboarding flows, and automated alerts.
🏛️
Public Sector & GovTech
Central government digital services, local authority platforms, and GDS-aligned projects with strict data handling requirements.
🛒
E-Commerce & Retail
Order confirmation, dispatch notification, and account management communications for compliant e-commerce operations.
🎓
Education & EdTech
Universities, awarding bodies, and EdTech platforms requiring reliable, compliant learner and staff communication systems.
🔐
Identity & Cybersecurity
Identity providers, cybersecurity platforms, and authentication services requiring secure, high-reliability OTP and alert delivery.

Transparent, usage-based pricing

All plans require a completed compliance review and identity verification before activation. Pricing is exclusive of UK VAT.

Starter
£149
per month + usage
Up to 50,000 messages / month
  • Shared IP pool
  • SPF / DKIM / DMARC guidance
  • API access (REST)
  • Delivery analytics dashboard
  • Bounce & complaint monitoring
  • Manual compliance review
  • KYC onboarding
  • Email support (48hr SLA)
  • Dedicated IP
  • Custom routing
Enterprise
Custom
volume-based agreement
Unlimited messages + SLA
  • Dedicated IP range
  • Custom MX routing
  • Multi-region failover
  • 99.99% uptime SLA
  • SOC 2 Type II report access
  • Custom compliance framework
  • DPA & GDPR agreements
  • 24/7 telephone support
  • Quarterly compliance reviews
  • On-site onboarding available

All pricing excludes UK VAT at the prevailing rate. Overage charges apply at £1.20 per 1,000 messages beyond plan limits. Annual agreements available with 15% discount. All accounts subject to compliance review — activation is not guaranteed.

Overview

Welcome to the Authridge technical documentation. This reference covers everything required to integrate with the Authridge platform for compliant transactional email delivery.

Account Approval Required — API keys and SMTP credentials are not issued until your account has completed the compliance review and KYC identity verification process. All new accounts are manually reviewed before activation.

Platform Summary

Authridge provides a transactional messaging infrastructure layer consisting of three primary integration methods:

  • SMTP Relay — authenticated SMTP relay via smtp.authridge.co.uk on port 587 (STARTTLS required)
  • REST API — programmatic message dispatch and account management via HTTPS
  • Webhook Callbacks — real-time delivery event notifications sent to your configured endpoints

Base API Endpoint

https://api.authridge.co.uk/v1/

Authentication

API requests are authenticated using Bearer token authentication. Include your API key in the Authorization header:

Authorization: Bearer auk_live_xxxxxxxxxxxxxxxxxxxxxxxx

Send a Transactional Message

POST /v1/messages/send

{
  "from": "noreply@yourdomain.co.uk",
  "to": "recipient@example.com",
  "subject": "Your account statement is ready",
  "html": "<p>Your monthly statement is now available.</p>",
  "text": "Your monthly statement is now available.",
  "tags": ["statement", "finance"],
  "tracking": {
    "opens": false,
    "clicks": false
  }
}
📌 Permitted Use Only — The send endpoint may only be used for transactional communications to recipients who have explicitly opted in to receive messages from your organisation. Marketing, promotional, or unsolicited bulk messages are strictly prohibited and will result in immediate account suspension.

SMTP Configuration

SettingValue
Hostnamesmtp.authridge.co.uk
Port587
SecuritySTARTTLS (required)
AuthenticationLOGIN or PLAIN
UsernameYour API key
TLS MinimumTLSv1.2
TLS PreferredTLSv1.3

Webhook Events

Authridge delivers real-time delivery event data to your configured webhook endpoint via HTTPS POST. The following event types are supported:

  • delivered — message accepted by recipient mail server
  • bounced — hard or soft bounce received, with classification
  • complained — FBL complaint received from ISP
  • deferred — temporary delivery failure, retry scheduled

Webhook payloads are signed using HMAC-SHA256 with your webhook secret. Validate the X-Authridge-Signature header on all incoming requests.

Infrastructure security and regulatory compliance

Authridge's platform is built on the principle that security and compliance are foundational properties, not optional add-ons. Every layer of our infrastructure is designed to meet the requirements of regulated industries.

🔐

TLS Encryption in Transit

All connections to Authridge infrastructure are encrypted. SMTP relay requires STARTTLS with a minimum of TLSv1.2. API endpoints enforce TLSv1.3. We do not accept unencrypted connections from senders. Certificate validation is enforced for all outbound delivery attempts where the recipient supports DANE or MTA-STS.

Mandatory Domain Authentication

All sending domains must have valid SPF, DKIM, and DMARC records configured and verified before a domain is activated for sending. We provide guided setup documentation and automated verification tools. Domains with a DMARC policy below "reject" are flagged for review and may be restricted.

🛡️

Dedicated IP Reputation Management

Dedicated IP clients receive isolated IP pools with no shared reputation exposure. Our delivery team monitors all IP addresses against major real-time blacklist databases 24 hours a day. IP warm-up programmes are managed by our team to protect sender reputation from the outset.

🔍

Real-Time Abuse Monitoring

Our automated abuse detection systems analyse sending behaviour, complaint rates, bounce patterns, and volume anomalies continuously. Accounts triggering threshold alerts are automatically rate-limited pending manual review. Our internal risk team reviews flagged accounts within one business hour.

📋

Compliance-First Onboarding

Every new account undergoes a structured onboarding review before credentials are issued. This includes business identity verification (KYC), use case assessment, intended recipient relationship review, and legal entity confirmation. Accounts are not activated without explicit approval from our compliance team.

⚖️

Internal Fraud & Risk Assessment

Authridge maintains an internal fraud prevention programme including device fingerprinting, registrant identity cross-referencing, and ongoing behavioural analytics. Accounts with indicators of fraudulent intent are declined at onboarding or suspended immediately if identified post-activation.

Regulatory Compliance

FrameworkApplicabilityStatusNotes
UK GDPRAll clients✓ ActiveData Processing Agreements available for all accounts
PECR 2003UK senders✓ ActiveOpt-in enforcement enforced at platform level
CAN-SPAM ActInternational clients✓ ActiveUnsubscribe mechanics required for eligible traffic
ISO 27001InfrastructureIn CertificationAudit completed Q1 2025, certification pending
SOC 2 Type IIEnterprise clients✓ ActiveReport available under NDA to enterprise accounts
ICO RegistrationUK data processing✓ RegisteredRegistration ZB489714

⛔ Zero Tolerance: Unsolicited Messaging

Authridge maintains a zero-tolerance policy for unsolicited bulk email, spam, and any form of messaging to recipients who have not provided explicit prior consent. Use of Authridge infrastructure for unsolicited communications, purchased lists, scrape-sourced contacts, or any form of spam will result in immediate account termination, forfeiture of any pre-paid fees, and referral to the relevant regulatory authority. We actively cooperate with the ICO, Ofcom, and law enforcement agencies in cases of alleged abuse.

Get in touch

All new account applications require a completed enquiry form. Our compliance team reviews each request and will respond within two business days.

Account Enquiry

By submitting this form you acknowledge that all account applications are subject to compliance review and identity verification. Submission does not guarantee account approval. Authridge does not accept applications for bulk, marketing, or promotional email services.

Contact Information

📧
General Enquiries
support@authridge.co.uk
💼
Sales
sales@authridge.co.uk
🔒
Abuse Reports
abuse@authridge.co.uk
📞
Telephone
+44 (0)20 7946 0812

Registered Office

Authridge Ltd
71–75 Shelton Street
Covent Garden
London WC2H 9JQ
United Kingdom

Office Hours

Monday – Friday: 09:00 – 18:00 GMT
Compliance team: 09:00 – 17:30 GMT
Emergency support: 24/7 (Enterprise only)

Privacy Policy

Last updated: 1 January 2026 | Version 3.1

1. About This Policy

This Privacy Policy explains how Authridge Ltd ("Authridge", "we", "us", "our"), a company registered in England and Wales under company number 14287163, collects, uses, stores, and protects personal data. We are registered with the Information Commissioner's Office (ICO) under registration number ZB489714.

This policy applies to all personal data processed through our website (authridge.co.uk), our client portal, our API services, and our internal business operations.

2. Data We Collect

We collect personal data in the following categories:

3. Legal Basis for Processing

We process personal data on the following legal bases under UK GDPR:

4. Data Retention

We retain account and transaction records for a minimum of six years following the end of the client relationship, in accordance with UK financial record-keeping requirements. Technical logs are retained for 90 days. Identity verification documents are retained for five years following account closure in compliance with applicable KYC obligations.

5. Third-Party Processors

We engage third-party sub-processors to support our operations. All processors are bound by appropriate data processing agreements. We do not sell or share personal data with third parties for advertising or marketing purposes. Our sub-processor register is available upon request.

6. Your Rights

Under UK GDPR, you have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain types of processing. To exercise any of these rights, contact us at privacy@authridge.co.uk. We will respond within one calendar month.

7. Data Transfers

Our primary infrastructure is hosted within the United Kingdom and European Economic Area. Where data is transferred outside these regions, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the ICO.

8. Contact

For privacy-related enquiries, contact our Data Protection Officer at privacy@authridge.co.uk or write to our registered office.

Terms of Service

Last updated: 1 January 2026 | Version 4.0

1. Agreement

These Terms of Service ("Terms") govern your access to and use of services provided by Authridge Ltd, a company incorporated in England and Wales (company number 14287163), registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. By registering for an account or using our services, you agree to be bound by these Terms.

2. Account Eligibility

Accounts are available to businesses only. Individual consumer accounts are not offered. You must be a duly authorised representative of your organisation and provide accurate, complete information during the registration and identity verification process. Authridge reserves the right to decline any application at our sole discretion.

3. Acceptable Use

Your use of the Authridge platform is governed by our Acceptable Use Policy, incorporated herein by reference. In summary: services may only be used for lawful, opt-in transactional communications. Unsolicited bulk email, spam, and any communication to recipients who have not provided explicit prior consent are strictly and absolutely prohibited.

4. Compliance Obligations

You are responsible for ensuring that all messages sent via the Authridge platform comply with applicable law, including UK GDPR, PECR, and the CAN-SPAM Act where applicable. You must maintain accurate suppression lists and honour unsubscribe requests within five business days.

5. Service Availability

Authridge commits to the uptime levels specified in your service agreement. Planned maintenance windows are communicated with a minimum of 48 hours' notice. The service is provided on an "as is" basis subject to the limitations and warranties in your subscription agreement.

6. Suspension and Termination

Authridge may suspend or terminate any account immediately and without notice where we have reasonable grounds to believe that the account is being used in violation of these Terms, our Acceptable Use Policy, or applicable law. Suspended accounts do not receive refunds for pre-paid periods.

7. Limitation of Liability

To the maximum extent permitted by law, Authridge's total liability to you in connection with these Terms shall not exceed the fees paid by you to Authridge in the twelve months preceding the event giving rise to the claim.

8. Governing Law

These Terms are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Acceptable Use Policy

Last updated: 1 January 2026 | Version 2.3

⛔ Core Prohibition

Authridge infrastructure may not be used for any form of unsolicited bulk email, spam, or messaging to recipients who have not provided explicit, verifiable prior consent. Violation of this policy will result in immediate account termination.

1. Permitted Use

The Authridge platform is authorised exclusively for the following use cases:

2. Prohibited Use

The following activities are strictly prohibited:

3. Consent Requirements

All recipients of messages sent via the Authridge platform must have provided explicit prior consent to receive communications from your organisation. Consent must be freely given, specific, informed, and unambiguous. You are responsible for maintaining records of consent and making these available to Authridge upon request.

4. Complaint and Bounce Thresholds

Accounts must maintain complaint rates below 0.08% and bounce rates below 2.0% at all times. Accounts approaching these thresholds will receive automated alerts. Accounts that persistently exceed these thresholds may be suspended pending investigation.

5. Enforcement

Authridge monitors all accounts in real time for compliance with this policy. Violations may result in immediate suspension, account termination, and referral to the relevant regulatory authorities including the ICO, Ofcom, or law enforcement. We cooperate fully with legitimate legal requests from regulatory bodies.

6. Reporting Abuse

If you believe Authridge infrastructure is being misused, please report it to abuse@authridge.co.uk. All abuse reports are reviewed by our compliance team within one business hour during office hours.

Client Portal

Sign in to access your dashboard

Forgot password?
Demo Portal
This is a demonstration environment. No real data is transmitted. All dashboard figures are simulated.
Dashboard Overview
Account: Acme Financial Services Ltd · Plan: Business · Last 30 days
All Systems Operational
Delivery Rate
99.5%
↑ 0.1% vs last period
Bounce Rate
0.2%
↓ 0.05% vs last period
Complaint Rate
0.01%
↓ 0.002% vs last period
Messages Processed
287,441
↑ 12.3% vs last period
Compliance Score
98.4
Excellent
IP Reputation
97/100
↑ 1pt this week
API Calls (Today)
14,822
Normal range
Active Domains
3
All authenticated

API Message Volume — Last 14 Days

8 Feb10 Feb12 Feb14 Feb16 Feb18 Feb20 Feb22 Feb

Authenticated Domains

  • acmefinancial.co.uk
    SPF DKIM DMARC
  • mail.acmefinancial.co.uk
    SPF DKIM DMARC
  • notifications.acmefin.com
    SPF DKIM DMARC
⚠ notifications.acmefin.com — DMARC policy not yet configured. View setup guide →

Compliance Health Score

98.4
EXCELLENT
Based on last 30 days activity
Delivery Rate99.5% ✓
Bounce Rate (target <2%)0.2% ✓
Complaint Rate (target <0.08%)0.01% ✓
Domain Authentication2/3 domains ⚠

IP Reputation & Activity

97
EXCELLENT
IP Reputation Score
Dedicated IPs: 198.51.100.42, 203.0.113.17
Spamhaus DBLClean
Barracuda BRBLClean
MXToolboxClean
SORBSClean

Recent Activity Log

  • Message batch dispatched — 4,218 messagesToday 14:32 UTCOK
  • DKIM key rotation completed — acmefinancial.co.ukToday 09:11 UTCOK
  • Suppression list updated — 14 addresses addedYesterday 17:44 UTCInfo
  • Bounce threshold alert cleared — bounce rate returned below 0.5%Yesterday 12:08 UTCOK
  • API key rotated — user james.h@acmefinancial.co.uk21 Feb 08:55 UTCInfo
  • Message batch dispatched — 9,881 messages20 Feb 14:00 UTCOK
  • Domain verification check — mail.acmefinancial.co.uk — PASS19 Feb 06:00 UTCOK
  • Compliance review — monthly automated check completed18 Feb 00:01 UTCOK