Home Products Blog Contact Privacy Terms Support
BulkForge · Email Governance

Why BulkForge Deploys an Agent Into Your Subscription Instead of Just Asking for API Keys

September 2026

The fastest way to build a bulk email SaaS is to ask customers to paste in their Postmark or SendGrid API key and let a hosted service call it on their behalf. Most tools in this category work exactly that way. BulkForge doesn't, and that's not an oversight — it's the entire reason the product is shaped the way it is.

The API-key model has one structural problem

The moment you paste in a credential, it lives somewhere you don't control. It's stored in a third party's database, used by their infrastructure, and covered by their security posture, not yours. If that vendor gets breached, your sending credential is part of the blast radius, whether or not anything about your own environment was ever at risk. That's the exact scenario we wrote about in "The Hidden Cost of Pasting Your Email Credentials Into Someone Else's Dashboard" — and it's the specific thing BulkForge's architecture is built to avoid.

Here's the actual mechanics

BulkForge is two layers. AgeeBgee hosts the control plane — the dashboard where you build campaigns, review delivery reports, and manage jobs. But the control plane never touches your delivery credentials directly. Instead, you deploy a lightweight agent into your own Azure subscription via the Marketplace. That agent polls the control plane for jobs, then executes delivery itself, using credentials that live in your own tenant the entire time.

What this buys you concretely

  • Your Postmark, ACS, or SendGrid credentials never leave your Azure subscription. AgeeBgee's infrastructure never sees them, never stores them, and isn't part of their access chain.
  • If AgeeBgee's control plane were ever compromised, there's no delivery credential sitting there to steal — because there isn't one.
  • Your existing Azure security posture (network policies, Key Vault access controls, whatever your team already has in place) applies to the agent the same way it applies to everything else in your subscription. You're not standing up a parallel security model for one vendor.
  • It's auditable in the way security and compliance reviews actually want: "where do our delivery credentials live" has one answer — your own tenant — instead of "our tenant, plus this vendor's, plus however carefully they say they've secured it."

The trade-off, stated plainly

This is more setup than pasting an API key into a form. Deploying an agent means an actual Marketplace deployment into your subscription, not a two-minute signup. That's a real cost, and it's worth being honest about it instead of pretending it's free. What you get for that cost is a genuinely different security model, not just a marketing claim about one — the credential-exposure risk that comes standard with most bulk-email SaaS tools isn't mitigated in BulkForge's architecture, it's structurally absent.

If a security or compliance review is part of how your organization evaluates a new vendor for bulk email, this is the conversation worth having before anything else: not what BulkForge's dashboard looks like, but where your credentials actually live once you're using it.

See how BulkForge works
← Back to Blog