Hallo,
  we are in the process of setting up a new web- and
mailserver, and
 consider switching from sendmail to another mail agent...
 At the risk of launching a flamewar, which one would you recommend from
 a security and maintainability point of view? 
I would also go for Postfix. Reasons:
- While Postfix is much easier to configure than Sendmail (no
sendmail.cf anymore), it tries to be compatible with Sendmail in some
ways: /etc/aliases, .forward, sendmail command and so on. As far as I
know, exim and qmail not not implement this and are not so well suited
as a "Sendmail drop in replacement"
- Postfix implements a very secure separate process architecture, where
every process works with limited rights.
Greetings, Patrick