Secure corporate email for institutions.
Overview
A corporate email platform for institutions and large organizations, written in Rust from the ground up. Multi-tenant by design — each institution runs as a fully isolated tenant, enforced at the database with row-level security. Strong server-side encryption at rest, full email authentication (SPF, DKIM, DMARC, ARC, MTA-STS) and built-in KVKK/GDPR tooling.
Key facts
- Status
- Live
- Development
- In active development
- Category
- Platform
- Founded
- 2026
- Parent
- RUBIKLABS
Technology
- Rust
- Kubernetes
- PostgreSQL
- OIDC / SCIM
- PGP / S/MIME
- TLS 1.3
Why Mail
Encrypted at rest
Message bodies, attachments and archives are encrypted at rest with AES-256-GCM and per-tenant keys. Optional PGP and S/MIME for correspondents who need end-to-end.
Multi-tenant isolation
Many institutions on one platform. Each tenant is isolated at the database with row-level security — data, policies and archives kept apart.
Data residency controls
Storage residency is configurable, with the production environment being commissioned in Türkiye. No foreign lock-in by design.
Enterprise identity
OpenID Connect SSO (Keycloak), SCIM provisioning, TOTP two-factor and WebAuthn / FIDO2 passkeys.
Email authentication
Full SPF, DKIM, DMARC, ARC and MTA-STS on every message in and out.
Standards alignment
Built to an internal security-control program, with ISO 27001 alignment as a stated target — not a held certificate.
Layers of security
Network
TLS 1.3 on every connection, hardened transport.
Transport
SPF, DKIM, DMARC, ARC and MTA-STS verification on every message in and out.
Application
TOTP two-factor, WebAuthn / FIDO2 passkeys, breached-password rejection and risk-based step-up.
Data
AES-256-GCM encryption at rest with per-tenant keys.
Key management
Keys managed through HashiCorp Vault and a pluggable KMS.
Audit
Signed, append-only audit log chain (HMAC-SHA256) with configurable retention.
Capabilities
Smart inbox
Automatic threading, label system, advanced search syntax (from:, has:attachment, is:unread).
Spam and virus protection
Multi-stage inbound pipeline with ML and heuristic spam classification, DNSBL checks and ClamAV virus scanning.
Every device
Webmail, plus desktop and mobile clients through an IMAP bridge and Exchange ActiveSync.
Centralized administration
Unified admin console, user groups, role-based access control (RBAC).
Your own domains
Multiple domains on one platform with per-domain policies.
Data loss prevention
Inline DLP on outbound mail — detectors for TC ID, IBAN and card numbers, enforced before send.
Compliance and archiving
KVKK / GDPR
Data-subject request workflow (export and erasure), consent enforcement, and VERBIS / ROPA / DPIA tooling.
Legal hold
Dual-approval, query-based legal hold. Held mail is exempt from deletion until the hold is lifted.
e-Discovery
Bulk export to MBOX, EML and JSONL for litigation and audit response.
Flexible retention
Configurable retention policies per institution, domain or user.
Why Rust
Mail is written in Rust from the ground up. For a security product the choice matters: memory safety eliminates an entire class of vulnerabilities, and it sits in the language category recommended by NSA and CISA for safety-critical systems.
Built for
Government institutions
Data residency controls, KVKK compliance tooling and configurable long-term retention.
Universities
Large user bases, multi-domain by faculty, SCIM provisioning and academic archive requirements.
Large enterprises
OIDC SSO, inline DLP, e-discovery and legal hold, integration with existing infrastructure.
Defense industry
Strong encryption at rest, fully isolated tenant model and a signed, append-only audit trail.
What we are building toward
A complete corporate email feature set
The full set of collaboration and office-suite features institutions expect. This is the development target Mail is moving toward — a direction, not a description of today.
ISO 27001 alignment
Built to an internal security-control program, with ISO 27001 alignment as a stated target. Not a held certificate yet.
Turkey-based production
Data residency controls exist today; the production environment is being commissioned in Türkiye. Full in-country hosting is being stood up, not yet live.
Demo and deployment
Mail is in production today. For a demo or to discuss deployment for your institution, get in touch.