Security your clients can verify

EgreedMail was designed for organisations that handle contracts, records and personal data in Rwanda and across East Africa — where a shared consumer inbox is a liability.

Controls that ship by default

Nothing here is an add-on tier. These protections apply to every account.

Per-mailbox isolation

Every mailbox and folder is guarded by row-level security in the database. A user cannot query another team member's mail or files, even with a valid session.

No public file URLs

Storage buckets are private. Files are only reachable through short-lived signed URLs generated for an authorised request.

Expiring share links

Public links can carry a password, an expiry timestamp and a maximum download count. Revoke any link instantly from the workspace.

Auto-lock with 6-digit PIN

Idle sessions lock behind a PIN across every open tab, with a countdown warning and password-gated recovery after repeated failures.

Authenticated mail delivery

Outbound mail is signed with SPF and DKIM on a verified sending domain so messages reach Gmail, Outlook, Yahoo and Proton inboxes instead of spam.

Audited administration

Roles live in a dedicated privileges table checked server-side. Security events are written to an append-only activity log.

Data handling

What we store, why we store it, and what leaves your organisation.

Mail content

Stored so your team can search and reply. Only the mailbox owner and explicitly granted administrators can read it.

Files and versions

Kept in private storage with version history and a recoverable trash window before permanent deletion.

Security events

Sign-ins, lock events and PIN failures are logged for your own audit trail, without recording the PIN itself.

Third parties

External delivery uses an authenticated mail relay for messages leaving your domain. Internal staff-to-staff mail never leaves Egreed infrastructure.

Need a security review for a tender?

Our Kigali team can walk your compliance officer through the architecture.

Talk to Egreed Tech