Skip to content
[—]mail

Mail

Secure corporate email for institutions.

Overview

A corporate email platform for institutions and large organizations, written in Rust from the ground up. Multi-tenant by design — each institution runs as a fully isolated tenant, enforced at the database with row-level security. Strong server-side encryption at rest, full email authentication (SPF, DKIM, DMARC, ARC, MTA-STS) and built-in KVKK/GDPR tooling.

Key facts

Status
Live
Development
In active development
Category
Platform
Founded
2026
Parent
RUBIKLABS

Technology

  • Rust
  • Kubernetes
  • PostgreSQL
  • OIDC / SCIM
  • PGP / S/MIME
  • TLS 1.3

Why Mail

01

Encrypted at rest

Message bodies, attachments and archives are encrypted at rest with AES-256-GCM and per-tenant keys. Optional PGP and S/MIME for correspondents who need end-to-end.

02

Multi-tenant isolation

Many institutions on one platform. Each tenant is isolated at the database with row-level security — data, policies and archives kept apart.

03

Data residency controls

Storage residency is configurable, with the production environment being commissioned in Türkiye. No foreign lock-in by design.

04

Enterprise identity

OpenID Connect SSO (Keycloak), SCIM provisioning, TOTP two-factor and WebAuthn / FIDO2 passkeys.

05

Email authentication

Full SPF, DKIM, DMARC, ARC and MTA-STS on every message in and out.

06

Standards alignment

Built to an internal security-control program, with ISO 27001 alignment as a stated target — not a held certificate.

Layers of security

01

Network

TLS 1.3 on every connection, hardened transport.

02

Transport

SPF, DKIM, DMARC, ARC and MTA-STS verification on every message in and out.

03

Application

TOTP two-factor, WebAuthn / FIDO2 passkeys, breached-password rejection and risk-based step-up.

04

Data

AES-256-GCM encryption at rest with per-tenant keys.

05

Key management

Keys managed through HashiCorp Vault and a pluggable KMS.

06

Audit

Signed, append-only audit log chain (HMAC-SHA256) with configurable retention.

Capabilities

01

Smart inbox

Automatic threading, label system, advanced search syntax (from:, has:attachment, is:unread).

02

Spam and virus protection

Multi-stage inbound pipeline with ML and heuristic spam classification, DNSBL checks and ClamAV virus scanning.

03

Every device

Webmail, plus desktop and mobile clients through an IMAP bridge and Exchange ActiveSync.

04

Centralized administration

Unified admin console, user groups, role-based access control (RBAC).

05

Your own domains

Multiple domains on one platform with per-domain policies.

06

Data loss prevention

Inline DLP on outbound mail — detectors for TC ID, IBAN and card numbers, enforced before send.

Compliance and archiving

01

KVKK / GDPR

Data-subject request workflow (export and erasure), consent enforcement, and VERBIS / ROPA / DPIA tooling.

02

Legal hold

Dual-approval, query-based legal hold. Held mail is exempt from deletion until the hold is lifted.

03

e-Discovery

Bulk export to MBOX, EML and JSONL for litigation and audit response.

04

Flexible retention

Configurable retention policies per institution, domain or user.

Why Rust

Mail is written in Rust from the ground up. For a security product the choice matters: memory safety eliminates an entire class of vulnerabilities, and it sits in the language category recommended by NSA and CISA for safety-critical systems.

Built for

01

Government institutions

Data residency controls, KVKK compliance tooling and configurable long-term retention.

02

Universities

Large user bases, multi-domain by faculty, SCIM provisioning and academic archive requirements.

03

Large enterprises

OIDC SSO, inline DLP, e-discovery and legal hold, integration with existing infrastructure.

04

Defense industry

Strong encryption at rest, fully isolated tenant model and a signed, append-only audit trail.

What we are building toward

01

A complete corporate email feature set

The full set of collaboration and office-suite features institutions expect. This is the development target Mail is moving toward — a direction, not a description of today.

02

ISO 27001 alignment

Built to an internal security-control program, with ISO 27001 alignment as a stated target. Not a held certificate yet.

03

Turkey-based production

Data residency controls exist today; the production environment is being commissioned in Türkiye. Full in-country hosting is being stood up, not yet live.

Demo and deployment

Mail is in production today. For a demo or to discuss deployment for your institution, get in touch.

One call. Your problem, your scale, your constraint. A proposal within a week.