Castra Secure Mailboxes · castra.email
A security-first mailbox for staff who handle sensitive records
Castra Secure Mailboxes gives the staff who handle the most sensitive mail -- the registrar, the front office, the business office -- a hardened, locked-down address of their own. Each mailbox is a real, access-controlled inbox on our own private system, so student and family details stay inside that system instead of an outside marketing company. We keep the description honest: controlled access and accounts kept tight, on a private system we run ourselves, with no borrowed certifications attached. The address is open to claim.
Example address: [email protected]. Checkout is not open yet — the figures on the plans page are catalog estimates, not a charge, and no mailbox is created or billed.
The problem with security pages
Almost every page like this one is a wall of badges. This one has none, on purpose.
The standard way to sell a secure mailbox is to show a row of logos and let the reader infer that the logos are load-bearing. Most of them are not: an audit tells you a process was examined on a date, and it says almost nothing about whether the specific thing you are about to buy denies the specific access it ought to deny.
We have no such logos to show you and we are not going to imply otherwise. What we can do instead is name the mechanisms that exist, say who they apply to, point at the module that implements each one, and be exact about the difference between what runs in the wider system today and what the mailbox itself will do when it is turned on.
That difference is the whole design of this site, so it gets a device rather than a footnote.
Two chips, and what they mean
Platform — a control that is built and running in the wider system this mailbox will live inside. Describing it is describing the house, not the room.
Mailbox — a statement about the address itself. Mailbox provisioning is a founder-confirmed step and is currently off, so every mailbox-scoped claim on this site is about what is built, never about a running inbox.
Every mechanism named on this site carries one of the two. That is not decoration: a platform control quoted as if it were a mailbox feature is a true sentence with its scope removed, and that is the most common way a page like this stops being honest.
One thing said plainly before anything else: a Castra mailbox is not provisioned. There is no inbox on this domain today. Everything you read here is either a description of controls that are genuinely running in the system this mailbox will live inside, or a statement about what the address is intended to be. Each one is labelled, and none of them is dressed up as the other.
Who this is for
Three desks, and two jobs this is the wrong tool for
The brand exists for the people who sit closest to sensitive records. That is a narrower audience than "the school", and the narrowness is the product.
The registrar
Transcript and records correspondence
The registrar's mail is the highest-consequence correspondence in a building that is not a safeguarding matter: requests to release a record, confirmations that a record was released, questions about what a record contains.
The reason it wants its own address rather than a shared office inbox is not secrecy, it is attribution. A reply about a record should come from a named function that a receiving institution can recognise, and it should be findable afterwards by the person who has to answer for it.
The platform-side controls that govern reading a record at all are described on who can open what.
The front office
The desk everything arrives at
The front office receives the widest range of sensitive material of anyone in a school, usually unsolicited: a note about a custody arrangement, a medical detail volunteered by a parent, a change of address that matters more than it looks.
A shared role address that more than one person covers is the right shape here, because coverage cannot lapse when somebody is away from the desk. That is sharing, not a ticketing system, and this product does not pretend to be one.
The business office
Money, and the paperwork behind it
Fee questions, payment arrangements, and the correspondence that follows them. This is the mail most likely to be impersonated from outside, because an invoice redirection is the oldest profitable attack on an institution.
A consistent sending address on a domain the school controls is part of what makes an impersonation attempt look wrong to the recipient. That is a modest, real benefit, and it is smaller than the benefit usually claimed for it.
What the sending side can and cannot promise is set out on what we will not say.
Who it is not for
Two jobs this is the wrong tool for
A safeguarding workflow. If what you need is a channel with escalation, case tracking and an audited chain of custody over a report, that is a different kind of system and this mailbox is not it. Naming that plainly matters more here than anywhere else on this site.
Bulk family communication. There is no list manager, no campaign builder, and no send-to-everyone. This is a small number of addresses for a small number of people who handle the sensitive end of the correspondence.
The one property worth paying for
Every uncertain answer falls the same way
Read enough of this codebase and one habit shows up everywhere, in code written by different people for different purposes: when the system cannot tell, it chooses the answer that cannot cause the irreversible mistake.
An administrative grant with no tenant bound to it matches nothing, rather than matching everything. A retention floor nobody has signed becomes a hold, rather than a deletion. An access to personal data that cannot be attributed to a person is still written to the trail, under a reserved identifier, rather than skipped. A suppression check that cannot reach its store blocks the send, rather than letting it through.
Each of those costs something on an ordinary day. That cost is the feature, and a product that has removed it to make an operator's afternoon smoother has sold the thing you were buying.
The counts, computed from the tables on this site
What is running, and what is not
What it would cost
What a mailbox would cost
Catalog figures for planning a budget, not a price you are charged. This is the entry plan; the rest are on the plans page.
Team $2.50 per mailbox / month
Catalog price — not a charge
Includes 5 mailboxes · 25 GB each.
A small set of on-brand school addresses for a department or office.
At the included 5 mailboxes, that is about $12.50 / month at catalog rates — an estimate, never billed.
- Prices shown are catalog estimates, not a charge -- checkout is not open yet.
- Mailbox provisioning is a founder-confirmed step and is currently off; no mailbox is created and no card is billed.
- A branded address is a professional mailbox, not a claim that any specific school or studio uses it.
Elsewhere on this site
The rest of it
Who can open what
Permissions, tenancy scope, the access trail, and a hash chain that makes tampering detectable rather than impossible.
Read it →How long things stay
A schedule a build can fail on, an unsigned floor that becomes a hold, and what none of it says about your mail.
Read it →What we will not say
The badge wall we do not have, the words we refuse, and the questions we answer with 'we do not know yet'.
Read it →Plans
Catalog figures for planning a budget. Checkout is not open and nothing here bills.
Read it →