Flat and per-domain, because the thing we secure is your domain — not a seat count to audit. Every deployment starts as a 30-day pilot with success criteria agreed up front.
Every deployment starts here. You watch the drills pass on your own domain — or you walk away with your data.
Genuinely encrypted — inside their own walls. External mail falls back to portals or plain TLS, and key custody is each user's problem, which is how encrypted email has failed for 25 years. None verify who a sender is.
The provider decrypts your mail to inspect it, holds the keys, and parks external recipients in web portals. That's policy-based trust in the provider — the opposite of zero-access.
Server-side keys in every configuration: the provider's services still decrypt your content for indexing and scanning, and the option that truly locks them out is scoped by the vendor itself to a sliver of 'crown-jewel' data because it breaks search and eDiscovery.
Where we are: DMCN for business is in its design-partner phase. The protocol, custody model, bridge and client are live; the self-serve admin console, IMAP access and retention archive are on the roadmap — and pilots are priced and scoped accordingly. We'll always tell you which side of that line a feature is on.