WORM archive — write once, read many: data in scope cannot be altered or deleted and is timestamped. An active hold is visible on your panel with scope and dates; every step of the process is written to the chain, so the hold itself is verifiable.
When the audit comes, you won’t be caught unprepared.
The encryption key is scoped to your account, outbound mail is scanned for personal data, every action is written to a SHA-256 chain, and identity is governed by your company directory. Six hardening layers work in depth — if one is breached, the others hold. When the auditor asks for evidence, your answer is one click: a timestamped, signed PDF.
The key belongs to your account; the content sits inside the envelope.
Envelope encryption integrated with your enterprise KMS provider: the root key stays in the KMS, an account-scoped key wraps the data key, and rotation runs automatically. Every key operation is written to the audit log; compliance reports are prepared targeting PCI DSS, SOC 2 and HIPAA. Backups follow the same discipline: written hourly to your own S3-compatible vault with dual-layer encryption — and you can restore to any moment you choose.
- STEP 1 · VAULT Backups written to you
Backups land in your own S3-compatible storage — your data stays in your own vault.
- STEP 2 · CIPHER Hourly, dual layer
Snapshots are taken hourly and written with AES-256-GCM dual-layer encryption.
- STEP 3 · RESTORE Back to any moment
With PITR you rewind the archive to the moment you choose and restore that exact state.
Personal data is caught before it leaves the door.
The DLP scanner checks every outbound email against regular expressions: national ID numbers, IBAN, credit cards, phone numbers. Your account policy decides what happens — warn or block; you add your own patterns too. Hide-my-email protects the opposite direction: you give customers a unique alias instead of your real address, and incoming mail passes spam cleaning before reaching your real inbox. If an alias is compromised, you disable it with one click.
- National ID (TC Kimlik)
1********46BLOCK - IBAN
TR** **** **** 8812BLOCK - Credit card
**** **** **** 4629BLOCK - Phone number
+•• 5•• *** ** **WARN - Custom pattern
contract-\d{6}WARN
- STEP 1 · GENERATE You hand out an alias
You give the customer or the form a unique alias instead of your real address.
- STEP 2 · FORWARDED It lands in your real inbox
Mail sent to the alias passes spam cleaning and is forwarded to your real inbox.
- STEP 3 · DISABLE One click on a leak
If the alias is compromised, you disable it with one click — your real address was never exposed.
You present a verifiable chain, not a promise.
Every record written to the audit log carries the SHA-256 hash of the previous one. Changing a single line in the past breaks the rest of the chain; the break shows up instantly on verification, together with the exact record. Integrity is verified weekly and records are kept for 5 years. On audit day you download the evidence PDF — RFC 3161 timestamped, PAdES-T signed — and integrity and time are verified independently of us.
- #14830 List exported
prev 5e90…b3c1 → chain 7c1d…42aa - #14831 Campaign sent
prev 7c1d…42aa → chain 03be…f1e7 - #14832 Legal hold opened
prev 03be…f1e7 → chain a3f5…9e2c
The evidence PDF carries an RFC 3161 timestamp and a PAdES-T signature — standards-compliant with Law No. 5070 (Turkish e-signature) and eIDAS. Timestamps are issued by a qualified RFC 3161 authority; integrity and time are verified independently of us.
Joiners open automatically, leavers close automatically.
Identity stays with your company: your team signs in through your company identity provider via SAML 2.0, with domain verification built in. SCIM 2.0 watches your directory — a new hire is created automatically, a departing employee is deactivated at once. You use Passkeys instead of passwords and require step-up verification on critical actions. The account is monitored continuously: a new device, new IP, new country or impossible travel raises an instant alert; if you wish, you open the panel to your company IP range only.
- SSO / SAML 2.0 single sign-on with your company identity · domain verificationBUSINESS+
- SCIM 2.0 automatic member creation + deactivation from your directoryENTERPRISE
- Passkey / WebAuthn passwordless sign-in + step-up on critical actionsFREE
- Anomaly alerts new device · new IP · new country · impossible travelSTARTER+
- IP allowlist panel access only from your company IP rangeBUSINESS+
- 2FA TOTP + backup codes
- Passkey enrolment + step-up on critical actions
- 5 failed logins → 15-minute lock
- Session management + remote sign-out
- Per-account + per-IP rate limits
- Disposable-address block + signup velocity checks
Let us design an infrastructure that fits your enterprise audit.
KMS, SCIM, DLP, hide-my-email, legal hold, dedicated engineer. Configured under contract; not a self-serve flow.