SECURITY

Know what is sealed, what is processed, and what stays visible.

Good security copy should describe boundaries—not ask for faith. ZeiroMail separates your stored archive, optional AI processing, routing metadata, and outbound approval into clear decisions.

A ZeiroMail security agent beside a sealed archive case and a separate processing tray
Two separate decisionsArchived to your key. AI processing only with consent.
MessageSealed archiveAI off by default

THE FOUR BOUNDARIES

Security you can explain to the rest of the company.

01 · THE ARCHIVE

Encrypted to the inbox owner’s key.

The stored message object is encrypted on arrival. ZeiroMail retains the sealed archive, not the private key that opens it. Receiving and sending still process plaintext, even when AI is off. A lost private key cannot be recovered by the service.

02 · PROCESSING

Optional, explicit, and separate.

AI processing starts off. With recorded consent, bounded text from future incoming email and supported PDFs can be sent to the deployment-configured OpenAI model. There is no per-mailbox model picker.

03 · METADATA

Some information must remain operable.

Sender, subject, timestamps, routing, threading, delivery state, and limited attachment metadata stay server-readable so mail can work.

04 · SENDING

A human approves the exact message.

A person approves the exact recipient, subject, bodies and attachment bytes. Edits invalidate approval; an agent cannot approve its own send. This release allows one recipient per outbound send. Provider acceptance is not confirmed delivery.

TWO MODES, ONE CLEAR CHOICE

Receive first. Add intelligence only where it belongs.

A legal archive, an automated support queue, and a low-risk system notification mailbox do not need identical processing rules. Choose at the mailbox boundary, then keep that choice visible.

SEALED ARCHIVE

AI processing off

  • receive and route
  • encrypt permanent archive
  • keep operational metadata
TRUSTED PROCESSING

AI processing enabled

  • bounded text sent to configured OpenAI model
  • temporary copies protected, then cleaned up
  • derived memory retains source provenance

Email transport is not end-to-end encryption.

Ordinary internet email still passes through the usual mail systems. ZeiroMail’s user-key encryption applies to the permanent archive after receipt; it does not make SMTP itself end-to-end encrypted.

What remains readable, and what deletion means.

Archive encryption, model-provider retention and live-data cleanup are different boundaries.

Derived memory is server-readable.

Memory uses an organization key protected by AWS KMS, not your archive private key. Authorized workspace users and agents with an explicit memory grant can read it. Turning AI off stops new extraction; it does not delete existing memory.

Provider retention is separate.

Extraction and assisted queries send bounded text to OpenAI using store=false. This does not establish Zero Data Retention. Default abuse-monitoring retention is up to 30 days, with legal and safety exceptions. Special retention controls require provider approval and configuration; no such entitlement is asserted here.

OpenAI data controls

Cleanup can take time.

Temporary processing copies are encrypted with AWS KMS protection and removed after success or invalid/withdrawn input. Failures may retain them for bounded retry and human replay. Age cleanup becomes eligible at 24 hours; this is not a deletion deadline. Replay does not renew age. Raw incoming mail is removed after all required recipient copies are durable.

Some metadata survives deletion.

Deletion receipts and inbound replay-prevention records have no automatic expiry in this release. They retain identifiers, status, timestamps and recovery checkpoints, not message bodies, attachments or private keys. This keeps deletion outcomes discoverable and prevents old notifications from recreating erased mail.

Keep your deletion receipt until cleanup is complete.

Account, workspace and inbox deletion first blocks access, then cleans live data asynchronously. Save the receipt before confirming; it lets you inspect pending, failed or completed cleanup and retry eligible failures after sign-out. Backups and versioned objects are outside that live-data completion result; this release does not assert a fixed backup-erasure deadline. Deletion cannot recall recipients’ copies, downloaded mail or your private key.

START WITH A CLEAR BOUNDARY

Give an agent a mailbox without giving up the final say.

Keep AI off or explicitly enable it for future incoming mail. Both modes keep user-key-encrypted archives.

Access options