Compliance-first transactional messaging infrastructure

Enterprise messaging
infrastructure, built for
regulated industries

Highcroft Digital provides secure, authenticated transactional email infrastructure for financial institutions, SaaS platforms, and enterprise software providers operating across the UK and Europe.

Standards
🔒 UK GDPR 📋 PECR Compliant ✉️ DMARC Enforced 🛡 TLS 1.3 🏢 ICO Registered
Infrastructure Overview Live
99.5%
Delivery Rate
0.2%
Bounce Rate
0.01%
Complaint Rate
Messages Processed – 7 Days
SPF / DKIM / DMARC Authenticated
IP Reputation Score 98 / 100
Compliance Health Excellent
⚠️ Important – Permitted Use Only: Highcroft Digital infrastructure is exclusively authorised for transactional and operational messaging. All new accounts undergo mandatory compliance review and identity verification (KYC). Unsolicited bulk email, marketing campaigns, and opted-out communications are strictly prohibited and result in immediate account suspension. By accessing our platform you agree to our Acceptable Use Policy.
Core Services

Infrastructure built for
enterprise reliability

Every component of our platform is designed with security, deliverability, and regulatory compliance at its core.

📨
Transactional Email Infrastructure
High-throughput transactional message delivery with real-time processing, priority queuing, and guaranteed SLA-backed delivery for mission-critical communications.
🔐
Secure SMTP Relay
TLS-encrypted SMTP relay with authenticated connections, credential management, and dedicated relay endpoints for enterprise sending volumes.
Communication API
RESTful API with comprehensive SDKs supporting synchronous and asynchronous message dispatch, webhook callbacks, and real-time delivery status events.
🌐
Domain Authentication
Guided implementation of SPF, DKIM, and DMARC records with ongoing monitoring, reporting, and policy enforcement recommendations.
📊
Delivery Analytics & Reporting
Granular real-time reporting across delivery, bounce, complaint, and engagement metrics with exportable data and customisable dashboards.
🛡
Reputation & IP Management
Dedicated IP allocation, warmup planning, real-time blacklist monitoring, and proactive reputation management by our deliverability team.
99.5%
Average delivery rate
0.01%
Complaint rate
250ms
Average processing time
99.98%
Platform uptime SLA
Why Highcroft Digital

Compliance-first from day one

We built Highcroft Digital to address a gap in the UK market: enterprise-grade messaging infrastructure that takes regulatory compliance as seriously as deliverability performance.

Every account undergoes a manual compliance review before activation. We conduct identity verification of all account holders and require documented proof of sender authorisation before any sending infrastructure is provisioned.

This is not a self-serve bulk mailing platform. We serve organisations with legitimate, transactional communication needs who require verifiable infrastructure provenance.

Mandatory KYC Verification

All account holders must complete identity verification before account activation.

Manual Compliance Review

Every new account is reviewed by our compliance team prior to infrastructure access.

Transactional Use Only

Sending rights are scoped to approved transactional use cases documented at onboarding.

Real-time Abuse Monitoring

Automated systems and human oversight monitor all traffic for policy violations.

About Highcroft Digital

Built on compliance.
Delivered with precision.

Highcroft Digital Ltd is a London-registered communication infrastructure company, founded in 2021 to provide compliance-first transactional messaging services to UK and European enterprises.

Our Mission

Infrastructure with integrity

Highcroft Digital was founded with a clear purpose: to provide financial institutions, regulated SaaS platforms, and enterprise software providers with messaging infrastructure that meets the standards their industries demand.

Unlike commodity email service providers, we do not operate as an open or self-serve platform. Every client relationship begins with a compliance review. We take responsibility for the infrastructure we provide, which means holding every sender to the same high standards we set for ourselves.

We are registered with the UK Information Commissioner's Office (ICO) and operate in accordance with the UK General Data Protection Regulation, the Privacy and Electronic Communications Regulations (PECR), and all applicable data protection legislation.

Company Information
Legal NameHighcroft Digital Ltd
Company TypePrivate Limited Company
Company Number13847291
VAT NumberGB 412 8836 09
Founded2021
ICO RegistrationZB487301
Registered OfficeFourth Floor, 12 Finsbury Square,
London EC2A 1AR,
United Kingdom
Our Team

Leadership

Our leadership team brings experience across financial services technology, enterprise infrastructure, and regulatory compliance.

JT
James Thornton
Chief Executive Officer
SR
Sophie Ramsden
Chief Technology Officer
MH
Marcus Holloway
Head of Compliance
AK
Anita Kaur
Head of Infrastructure
Solutions

The full stack of transactional
messaging infrastructure

From SMTP relay to delivery analytics, every component is designed for enterprise reliability and regulatory compliance.

📨

Transactional Email Infrastructure

Purpose-built for high-volume transactional messaging: account notifications, password resets, order confirmations, billing alerts, and operational system messages.

  • Priority message queuing with guaranteed delivery windows
  • Multi-region redundancy across UK and EU infrastructure
  • Real-time delivery status tracking and webhook callbacks
  • Suppression list management and bounce handling
🔐

Secure SMTP Relay

Enterprise SMTP relay with enforced TLS, certificate-pinned connections, and per-client authentication. Suitable for application-layer integration without modifying existing infrastructure.

  • STARTTLS and implicit TLS 1.3 support
  • Per-client SMTP credentials with rotation policies
  • Port 587 (submission) and 465 (SMTPS) endpoints
  • IP allow-listing for additional access control

Communication API

A RESTful API designed for developer integration, with official SDKs for Python, Node.js, PHP, Ruby, Java, and .NET. Full OpenAPI 3.0 specification available.

  • Synchronous and asynchronous dispatch modes
  • Webhook event streaming for real-time status updates
  • Idempotency keys for safe message retry logic
  • Rate limiting with per-account quotas and burst allowances
🌐

Domain Authentication Support

Comprehensive SPF, DKIM, and DMARC implementation guidance, with ongoing monitoring and alerting for authentication failures or policy drift.

  • Guided DNS record setup with validation tooling
  • DMARC policy progression from monitoring to enforcement
  • Aggregate and forensic report analysis
  • Subdomain alignment and multi-domain configurations
📊

Delivery Analytics & Reporting

Full-funnel visibility across every message sent through our infrastructure. Exportable reporting for compliance evidence, performance reviews, and internal audits.

  • Real-time delivery, bounce, and complaint dashboards
  • Per-domain and per-campaign breakdown views
  • Scheduled report delivery via email or webhook
  • Data retention in accordance with UK GDPR requirements
🛡

Dedicated IP & Reputation Management

Dedicated IP addresses with structured warmup plans, continuous blacklist monitoring, and proactive intervention from our deliverability specialists.

  • Single-tenant dedicated IPs for enterprise accounts
  • Managed IP warmup over 4–8 week ramp periods
  • Real-time blacklist monitoring across 80+ RBLs
  • ISP feedback loop (FBL) enrolment and monitoring
Industries

Serving regulated industries
across the UK and Europe

Our infrastructure is deployed by organisations where messaging reliability, auditability, and compliance are non-negotiable.

🏦
Financial Services & Banking
Banks, building societies, payment processors, and FCA-regulated firms rely on Highcroft Digital for account alerts, transaction notifications, fraud communications, and regulatory correspondence. Our infrastructure supports the stringent audit trail requirements of the financial services sector.
FCA Regulated Transaction Alerts Fraud Notifications Account Servicing PCI DSS Environments
💻
SaaS Platforms & Software Providers
Software-as-a-service companies and ISVs use our infrastructure to power user authentication emails, subscription notifications, product alerts, and operational system communications at scale, without compromising deliverability or compliance standing.
Auth & Password Reset Subscription Lifecycle Product Notifications Billing Alerts
🛒
E-commerce & Retail
Online retailers and marketplace operators depend on reliable order confirmation, dispatch notifications, return authorisation, and customer account communications. We support high-volume transactional flows during peak trading periods without degradation in deliverability.
Order Confirmations Dispatch Notifications Returns & Refunds Peak Volume Support
⚕️
Healthcare & Life Sciences
Healthcare providers, health tech platforms, and life sciences organisations require messaging infrastructure that operates in accordance with data protection requirements specific to health information. Our compliance team has experience supporting UK GDPR Article 9 special category data obligations.
Patient Communications Appointment Reminders UK GDPR Article 9 Data Processing Agreements
⚖️
Legal & Professional Services
Law firms, accountancy practices, and professional services organisations use Highcroft Digital for client portal notifications, document delivery confirmations, and operational communications requiring documented delivery evidence.
Client Portal Notifications Document Delivery Audit Trail Support SRA Regulated Practices
Pricing

Transparent pricing for
enterprise infrastructure

All plans require successful completion of our compliance review process before activation. Pricing excludes UK VAT at 20%.

📋 Compliance Review Required: All accounts — regardless of plan tier — are subject to a manual compliance review and KYC verification process before access is granted. This typically takes 2–5 business days. We do not provide immediate self-serve access.
Starter
£299 /month
Suitable for small SaaS platforms and technology companies with modest transactional volumes.
  • Up to 50,000 messages/month
  • Shared IP infrastructure
  • Standard SMTP relay access
  • API access included
  • SPF/DKIM setup support
  • Standard delivery analytics
  • Email support (business hours)
  • UK GDPR data processing agreement
Enterprise
Custom pricing
For financial institutions, large SaaS platforms, and enterprises with complex or high-volume requirements.
  • Unlimited messages (contracted volume)
  • Multiple dedicated IPs
  • Custom sending domains
  • Enterprise API SLAs
  • Full domain authentication suite
  • Custom reporting & data exports
  • Dedicated account manager
  • 24/7 priority support
  • SLA: 99.98% uptime
  • Custom DPA & contractual terms
  • On-site security review available

Additional Usage Charges

Item Starter Professional Enterprise
Additional messages (per 1,000)£1.20£0.80Contracted
Additional dedicated IPN/A£45/monthContracted
IP warmup managementN/A£150 one-timeIncluded
DMARC reporting analysisN/A£75/monthIncluded
Data processing agreementIncludedIncludedCustom

All prices exclude UK VAT at the standard rate of 20%. Annual contracts available at a 15% discount. Contact our sales team for volume pricing above 5 million messages per month.

Documentation

Technical Documentation

Integration guides, API reference, and best practices for the Highcroft Digital platform.

Platform Overview

The Highcroft Digital platform provides secure transactional messaging infrastructure via two primary integration paths: a RESTful HTTP API and SMTP relay. Both methods require prior compliance review and account activation.

📋 Account Activation Required: API credentials and SMTP access are only issued following successful completion of the compliance review and KYC process. All API calls must include a valid, account-specific API key.

Base URL

# All API requests use the following base URL
https://api.highcroftdigital.co.uk/v1

Authentication

All API requests must include your account API key in the Authorization header using Bearer token authentication.

# Example request header
Authorization: Bearer hd_live_sk_xxxxxxxxxxxxxxxxxxxxxxxx
Content-Type: application/json

Send a Transactional Message

The following example demonstrates sending a transactional notification via the API. All requests must originate from verified, authenticated domains registered within your account.

// POST /v1/messages
{
  "from": {
    "email": "noreply@yourdomain.co.uk",
    "name": "Your Application"
  },
  "to": [{ "email": "recipient@example.com" }],
  "subject": "Your account notification",
  "html": "<p>This is a transactional message.</p>",
  "tags": ["account-notification"],
  "idempotency_key": "unique-message-id-12345"
}

SMTP Configuration

For application-level SMTP integration, use the following relay endpoint. TLS 1.2 or higher is mandatory — connections over unencrypted SMTP are not accepted.

Host: smtp.highcroftdigital.co.uk
Port: 587 (STARTTLS required)
Port: 465 (Implicit TLS)
Auth: LOGIN or PLAIN (over TLS only)
Username: [your SMTP username]
Password: [your SMTP password]

Webhook Events

Configure webhook endpoints within your account dashboard to receive real-time delivery status events. All webhook payloads are signed using HMAC-SHA256.

  • message.delivered — Message accepted by receiving MTA
  • message.bounced — Permanent or temporary delivery failure
  • message.complained — Recipient submitted a spam complaint
  • message.deferred — Temporary deferral, queued for retry
Security & Compliance

Security-first infrastructure
for regulated environments

Highcroft Digital is built around the principle that infrastructure security and regulatory compliance are foundational, not optional features.

Infrastructure Security

Technical Security Measures

🔒
TLS Encryption in Transit

All data transmitted via our API and SMTP relay is encrypted using TLS 1.3. TLS 1.2 is the minimum accepted version. Unencrypted connections are rejected at the transport layer.

🛡
Mandatory Domain Authentication

All sending domains must have SPF, DKIM, and DMARC records validated and confirmed before traffic is accepted. We enforce p=quarantine or p=reject DMARC policies for enterprise accounts.

🔑
API Credential Security

API keys are issued per account with role-based scoping. Keys can be rotated on demand and are never stored in recoverable form. All access is logged and available in your account audit trail.

📡
Infrastructure Resilience

Our sending infrastructure is distributed across geographically separated UK and EU data centres, with automated failover and no single point of failure for message processing.

🔍
Real-time Abuse Detection

Automated systems monitor all outbound traffic for anomalous patterns, volume spikes, complaint rate increases, and other indicators of policy violation or account compromise.

Regulatory Compliance

Compliance Framework

📋
UK GDPR Compliance Support

We act as a data processor for our clients and provide a Data Processing Agreement (DPA) compliant with UK GDPR Articles 28 and 29. We do not use personal data for any purpose beyond message delivery.

📜
PECR Adherence

Our platform supports PECR-compliant transactional messaging workflows. We do not permit electronic marketing to individuals without documented opt-in consent under Regulation 22.

🌍
CAN-SPAM Compliance

For clients sending to US-based recipients, we provide guidance and tooling to support CAN-SPAM Act compliance requirements, including unsubscribe management for commercial messages.

🏢
ICO Registered Data Controller

Highcroft Digital Ltd is registered with the Information Commissioner's Office as a data controller (Registration: ZB487301). Our registration is current and renewed annually.

⚠️
Anti-Spam Enforcement

We operate a zero-tolerance policy towards unsolicited bulk email. Accounts found to be transmitting unsolicited messages are suspended immediately and reported to relevant authorities where appropriate.

Onboarding Process

Compliance-first onboarding

01
Application Submission
Complete the account application including company details, intended use case, estimated volumes, and contact information.
02
KYC Verification
Provide identity documentation for the account holder and, where applicable, the responsible organisation. We verify company registration and director details.
03
Compliance Review
Our compliance team reviews the application, assesses the stated use case, and evaluates risk. This process typically takes 2–5 business days.
04
Infrastructure Provisioning
Upon approval, your account is activated, infrastructure is provisioned, and your onboarding engineer assists with integration and domain authentication.
Contact

Get in touch

Our team is available Monday to Friday, 09:00–17:30 GMT. Enterprise clients have access to extended support hours.

Request access or speak to our team

All account enquiries are reviewed by our compliance team before any access is granted. Please provide accurate information about your organisation and intended use case.

By submitting this form you agree to our Privacy Policy. We will only use your information to respond to your enquiry.

📍
Registered Office
Fourth Floor, 12 Finsbury Square
London EC2A 1AR, United Kingdom
📞
Telephone
+44 (0)20 3987 4400
Monday–Friday, 09:00–17:30 GMT
✉️
Support
support@highcroftdigital.co.uk
Technical and account support
💼
Sales
sales@highcroftdigital.co.uk
Enterprise enquiries and partnerships
🔒
Compliance & Data Protection
dpo@highcroftdigital.co.uk
UK GDPR enquiries and DPO contact
Company Details
Highcroft Digital Ltd
Company Number: 13847291
VAT Number: GB 412 8836 09
ICO Registration: ZB487301
Highcroft Digital — Client Dashboard
All systems operational
JT
James Thornton
Overview
📊 Dashboard
📨 Messages
📈 Analytics
Infrastructure
🌐 Domains
📡 IP Addresses
API Keys
🔔 Webhooks
Compliance
🛡 Compliance Health
🚫 Suppressions
📋 Audit Log
Account
⚙️ Settings
💳 Billing
📖 Documentation
Account Overview
YourCompany Ltd — Professional Plan · Last updated: just now
Delivery Rate
99.5%
▲ 0.1% vs last 30 days
Messages (30 days)
184,293
▲ 12% vs prior period
Bounce Rate
0.2%
→ Stable
Complaint Rate
0.01%
▼ 0.001% improvement
API Message Volume
Last 30 days — daily dispatches
1 Jan 31 Jan
Compliance Health Score
Assessed against Highcroft Digital policy thresholds
98
out of 100 — Excellent
Delivery Rate
99.5%
Bounce Rate
0.2%
Complaint Rate
0.01%
Auth Score
100%
Domain Authentication Status
Verified sending domains and authentication records
mail.yourcompany.co.uk
SPF ✓ DKIM ✓ DMARC ✓
notifications.yourcompany.co.uk
SPF ✓ DKIM ✓ DMARC ↻
billing.yourcompany.co.uk
SPF ✓ DKIM — DMARC ✗
Dedicated IP Reputation
Real-time reputation across major blacklist monitors
98/100
Sending IP: 185.207.xx.xx
Spamhaus
Clean
Barracuda
Clean
MX Toolbox
Clean
SORBS
Clean
Recent Activity
Account events and system notifications from the last 24 hours
Batch dispatched: 4,200 account notification messages processed via API. Delivery rate 99.7%.
09:14
Webhook delivered: 4,183 message.delivered events dispatched to https://hooks.yourcompany.co.uk/hd
09:15
DMARC advisory: notifications.yourcompany.co.uk DMARC policy is at p=none (monitoring). Enforcement recommended.
08:30
IP health check: Dedicated IP 185.207.xx.xx confirmed clean across 80 monitored RBLs.
07:00
Batch dispatched: 1,847 billing notification messages processed. 0 complaints recorded.
Yesterday 18:22
API key rotated: Production API key updated by account administrator j.thornton@yourcompany.co.uk
Yesterday 14:05