dmcn business Log in Talk to us
Platform Security Sovereignty Pricing For personal use
Log in Talk to us
Security

Enforced by architecture, not by policy.

Every guarantee below is enforced by architecture, not by policy. We publish how it works precisely so you don't have to take our word for anything.

The path of a message Report an issue

Encrypted on your devices

Mail is encrypted in the browser before it leaves the machine (Ed25519 signatures, X25519 key agreement, AES-256-GCM). Keys are held as non-extractable handles — the private key can't be exported by script, ours included.

Zero-access, literally

Our servers hold no key material at all — not even encrypted copies. The web backend is a relay to the network, nothing more. There is nothing on our side to breach, subpoena or quietly hand over.

Senders verified before delivery

Every message carries its sender's signature, checked against the sender's published identity record before it's accepted for delivery. A message that doesn't verify is dropped at the first relay — spoofing isn't filtered, it fails.

No passwords on our side

Signing in is a cryptographic challenge: your device proves it holds the account key. There's no password database to steal and no reset flow to socially engineer.

Blocking that sticks

Blocking binds to the sender's cryptographic identity, not their address string. A blocked sender can't come back with a fresh address — burning an identity costs them everything, which is why spam economics collapse.

Custody where it belongs

On a managed domain your administrator custodies account keys — onboarding, recovery and offboarding run inside your organization. Managed accounts say so in the product: employees see who can recover their mailbox.

The path of a message

How your company's mail is protected.

01

Sealed on the device

The message is signed by the sender's key and encrypted to the recipient before it leaves the machine.

02

Relayed, unreadable

Relays carry and store sealed envelopes they cannot open. Storage is encrypted because it never sees plaintext in the first place.

03

Verified on arrival

The recipient's device checks the signature against the sender's published identity before showing the message. No valid signature, no display.

04

Legacy mail, labelled

Mail from the old world is authenticated at the bridge (SPF, DKIM, DMARC) and arrives with a signed verdict your client verifies — trust tiers with receipts.

Two honest edges. Mail crossing the bridge to or from legacy email is protected in transit (TLS), not end-to-end encrypted — that's the floor every other provider calls normal, and you can run your own bridge to remove us from that path. And while message contents are always sealed, stronger delivery-metadata protection (onion-routed transport) is designed and on the roadmap.

Responsible disclosure

Found something? We want to hear it.

Security is a process, not a promise. If you believe you've found a vulnerability, tell us privately and we'll work with you to fix it quickly — and credit you if you'd like.

security@dmcnmail.com
Report privately and we'll respond fast — usually within a business day
We'll work with you on a fix and coordinate disclosure timing
Credit is yours if you want it; silence if you prefer
No legal threats for good-faith research. Ever.

Security your auditors can verify.

Book a design-partner pilot