ENTERPRISE SECURITY

When the audit comes, you won’t be caught unprepared.

The encryption key is scoped to your account, outbound mail is scanned for personal data, every action is written to a SHA-256 chain, and identity is governed by your company directory. Six hardening layers work in depth — if one is breached, the others hold. When the auditor asks for evidence, your answer is one click: a timestamped, signed PDF.

SHA-256
audit chain — every record bound to the previous one
RFC 3161
qualified RFC 3161 timestamp, signed evidence PDF
SAML 2.0 + SCIM
enterprise identity — joiners created, leavers deactivated
BYOS + PITR
backups in your own vault, restore to any moment
01 / Encrypt

The key belongs to your account; the content sits inside the envelope.

Envelope encryption integrated with your enterprise KMS provider: the root key stays in the KMS, an account-scoped key wraps the data key, and rotation runs automatically. Every key operation is written to the audit log; compliance reports are prepared targeting PCI DSS, SOC 2 and HIPAA. Backups follow the same discipline: written hourly to your own S3-compatible vault with dual-layer encryption — and you can restore to any moment you choose.

LAYER SCHEME · ENVELOPE ENCRYPTION ENTERPRISE
KMS root keyheld by your enterprise KMS provider
Account keyscoped to your account · automatic rotation
Data keyencrypts the content
Content stored encrypted
One account’s key never opens another account’s data.
BACKUP + RECOVERY · BYOS + PITR ENTERPRISE
  1. STEP 1 · VAULT Backups written to you

    Backups land in your own S3-compatible storage — your data stays in your own vault.

  2. STEP 2 · CIPHER Hourly, dual layer

    Snapshots are taken hourly and written with AES-256-GCM dual-layer encryption.

  3. STEP 3 · RESTORE Back to any moment

    With PITR you rewind the archive to the moment you choose and restore that exact state.

02 / Protect

Personal data is caught before it leaves the door.

The DLP scanner checks every outbound email against regular expressions: national ID numbers, IBAN, credit cards, phone numbers. Your account policy decides what happens — warn or block; you add your own patterns too. Hide-my-email protects the opposite direction: you give customers a unique alias instead of your real address, and incoming mail passes spam cleaning before reaching your real inbox. If an alias is compromised, you disable it with one click.

SAMPLE VIEW · DLP SCANNER ENTERPRISE
  • National ID (TC Kimlik) 1********46 BLOCK
  • IBAN TR** **** **** 8812 BLOCK
  • Credit card **** **** **** 4629 BLOCK
  • Phone number +•• 5•• *** ** ** WARN
  • Custom pattern contract-\d{6} WARN
You add the pattern; warn-or-block is your account policy’s call.
HIDE-MY-EMAIL — THE ALIAS LOOP ENTERPRISE
  1. STEP 1 · GENERATE You hand out an alias

    You give the customer or the form a unique alias instead of your real address.

  2. STEP 2 · FORWARDED It lands in your real inbox

    Mail sent to the alias passes spam cleaning and is forwarded to your real inbox.

  3. STEP 3 · DISABLE One click on a leak

    If the alias is compromised, you disable it with one click — your real address was never exposed.

03 / Prove

You present a verifiable chain, not a promise.

Every record written to the audit log carries the SHA-256 hash of the previous one. Changing a single line in the past breaks the rest of the chain; the break shows up instantly on verification, together with the exact record. Integrity is verified weekly and records are kept for 5 years. On audit day you download the evidence PDF — RFC 3161 timestamped, PAdES-T signed — and integrity and time are verified independently of us.

SAMPLE VIEW · AUDIT HASH CHAIN CHAIN VERIFIED
  1. #14830 List exported
    prev 5e90…b3c1 → chain 7c1d…42aa
  2. #14831 Campaign sent
    prev 7c1d…42aa → chain 03be…f1e7
  3. #14832 Legal hold opened
    prev 03be…f1e7 → chain a3f5…9e2c
Weekly integrity verification · 5-year retention · one-click PDF report
LEGAL HOLD ENTERPRISE

WORM archive — write once, read many: data in scope cannot be altered or deleted and is timestamped. An active hold is visible on your panel with scope and dates; every step of the process is written to the chain, so the hold itself is verifiable.

TIMESTAMP · RFC 3161 SIGNED EVIDENCE PDF

The evidence PDF carries an RFC 3161 timestamp and a PAdES-T signature — standards-compliant with Law No. 5070 (Turkish e-signature) and eIDAS. Timestamps are issued by a qualified RFC 3161 authority; integrity and time are verified independently of us.

04 / Govern

Joiners open automatically, leavers close automatically.

Identity stays with your company: your team signs in through your company identity provider via SAML 2.0, with domain verification built in. SCIM 2.0 watches your directory — a new hire is created automatically, a departing employee is deactivated at once. You use Passkeys instead of passwords and require step-up verification on critical actions. The account is monitored continuously: a new device, new IP, new country or impossible travel raises an instant alert; if you wish, you open the panel to your company IP range only.

SAMPLE VIEW · IDENTITY + ACCESS
  • SSO / SAML 2.0 single sign-on with your company identity · domain verification
    BUSINESS+
  • SCIM 2.0 automatic member creation + deactivation from your directory
    ENTERPRISE
  • Passkey / WebAuthn passwordless sign-in + step-up on critical actions
    FREE
  • Anomaly alerts new device · new IP · new country · impossible travel
    STARTER+
  • IP allowlist panel access only from your company IP range
    BUSINESS+
Compatible with every enterprise identity provider that speaks SAML 2.0.
STANDARD ON EVERY PLAN — NOT AN ENTERPRISE EXTRA
  • 2FA TOTP + backup codes
  • Passkey enrolment + step-up on critical actions
  • 5 failed logins → 15-minute lock
  • Session management + remote sign-out
  • Per-account + per-IP rate limits
  • Disposable-address block + signup velocity checks
Data residency. Infrastructure runs in the European Union (Germany) and data is processed under the GDPR. Sub-processors are listed in our privacy notice.
Enterprise contract. KMS/BYOS technical documentation, the DPA and custom SLA samples are shared in the sales conversation; a technical POC is set up with a dedicated engineer within 2 weeks. Talk to sales.
ENTERPRISE

Let us design an infrastructure that fits your enterprise audit.

KMS, SCIM, DLP, hide-my-email, legal hold, dedicated engineer. Configured under contract; not a self-serve flow.