Posture
What we will not say
The words this product refuses, the badges it does not have, and the questions it answers with "we do not know yet". Each refusal has a reason, and the reasons are more useful than the refusals.
A security page is unusual among marketing pages in that its credibility is destroyed by exactly the sentences that make it more persuasive. So this page is organised around the sentences we are not going to write.
Eight refusals
Each one is a sentence we are not going to write
No certification, audit name or framework badge Deliberately not built
We hold none and we display none. A borrowed logo is the fastest way to make a page feel safe and it transfers no property to the product you are buying. If your procurement requires a specific certification, we do not meet it, and that is a real reason to choose something else.
Never 'unbreakable', 'tamper-proof' or 'immutable' Deliberately not built
The chained ledger makes tampering detectable, not impossible. Anyone with enough access can still alter a record; what they cannot do is leave the chain verifying afterwards. The overstated word is the one a buyer repeats to their own leadership, so it becomes their problem rather than ours.
Never 'your data never leaves' Deliberately not built
We run the system ourselves and keep the handling tight. Contact details stay inside our own private system and are not handed to an outside marketing company and not sold. That is the honest version, and it is a smaller claim than the one usually made with these words.
No legal conclusion, anywhere Deliberately not built
This site describes mechanisms. It does not tell you what any rule requires of your organisation and does not characterise an obligation. The retention page carries that bound in its own opening, not as a footnote.
No encryption specification we cannot hold to Deliberately not built
You will not find a list of cipher names on this page. Publishing a specific configuration on a marketing page creates a promise that has to be re-verified on every change and is usually stale within a year. Ask us directly and you will get a current answer from a person.
The mailbox is not provisioned Built, latched off
There is no inbox on this domain today. Provisioning is a founder-confirmed step and it is off. Every platform control this site describes is real and running; none of it is currently being applied to a message of yours, because there is no message of yours.
Sending is not live either Built, latched off
The owned mail server's accept latch is off. A send today becomes a durable queued row and is recorded as queued. Nothing reports a delivery that did not happen.
Not a safeguarding workflow Deliberately not built
If you need escalation, case tracking and an audited chain of custody over a report about a child, that is a different system and this mailbox is not it. This is the refusal on this page that matters most and it is stated without hedging.
Where AI is, and is not
No AI reads or writes anything on this surface
There is no drafting assistant here, no summariser over an inbox, and no classification pass over sensitive correspondence. On a product for the registrar's mail, that is worth being unusually explicit about: nothing here reads a message to improve anything.
The wider codebase does contain a message-personalization pass, and it is honest to say so. It may touch a subject line and an opening line and nothing else; it is structurally forbidden from touching a receipt or an authentication link; and it runs only when a caller injects a provider that runs inside our own network. No provider is wired into this surface, and every error or guard trip in it returns the original message unchanged.
So the state today is: no AI writes a message here, no AI drafts one, and no AI reads one. If that ever changes it will be stated on this page before it ships.
packages/notifications/src/ai/personalize.ts:83 (the excluded kinds) · :109 (the in-network-or-skip check)
Money
Catalog prices, not a charge
There is no buy button on this site and no signup that bills. Turning a mailbox on is a founder-confirmed step and it is currently off.
- Prices shown are catalog estimates, not a charge -- checkout is not open yet.
- Mailbox provisioning is a founder-confirmed step and is currently off; no mailbox is created and no card is billed.
- A branded address is a professional mailbox, not a claim that any specific school or studio uses it.
Questions
The eight we get asked, answered without hedging
Are you certified against any recognised framework?
No. We hold no certification and display no badge. If your procurement requires one, we do not meet that requirement today and you should treat that as disqualifying rather than as something to work around.
Is the mail encrypted?
The sending path upgrades a connection to an encrypted one whenever the receiving server offers it, and it defers the attempt rather than quietly sending in the clear if that upgrade fails. Beyond that, ask us directly: a specific configuration published on a marketing page goes stale and becomes a promise nobody re-checks.
Can an administrator read a user's mailbox?
That is a mailbox-scoped question and the mailbox is not provisioned, so the honest answer is that the behaviour has not been decided and published. We would rather say that than describe a design we have not committed to.
How long do you keep my messages?
Also not decided and published, for the same reason. The retention page explains the platform schedule that does exist and states plainly that it is not a statement about mailbox retention.
Where is the data held?
On our own private system, which we run. Contact details are not handed to an outside marketing company and are not sold. We do not claim the data can never leave; we keep the handling tight and describe it in those words.
Does anything here tell me what records I am required to keep?
No, and it is not going to. This site describes mechanisms only. Nothing on it is a legal conclusion and your own records officer is the person to ask.
Can I use this for safeguarding reports?
No. That needs escalation, case tracking and an audited chain of custody, and this is a mailbox. Using it for that would be worse than using nothing, because it would feel like a system.
What is actually running today, then?
The platform controls described on the access and retention pages, each cited by file and line. The mailbox itself is not provisioned and sending is latched off. Everything else on this site is labelled with which of the two it is.
Elsewhere on this site
The rest of it
Overview
Who this address is for, and what a security claim can honestly mean when a product is not provisioned.
Read it →Who can open what
Permissions, tenancy scope, the access trail, and a hash chain that makes tampering detectable rather than impossible.
Read it →How long things stay
A schedule a build can fail on, an unsigned floor that becomes a hold, and what none of it says about your mail.
Read it →Plans
Catalog figures for planning a budget. Checkout is not open and nothing here bills.
Read it →