Security Architecture

Enterprise-Grade Email Security

Sangi Mail is built with strict boundary controls, crypt session tokens, and absolute data isolation at its core.

Transit & Rest Encryption

All SMTP transmissions and HTTP REST API request handoffs enforce strong Transport Layer Security (TLS 1.2 and TLS 1.3). Email payloads, session stores, and user database schemas are encrypted at rest using AES-256 standard encryption.

Cryptographic HMAC Authentications

To protect client consoles from hijackings and spoofing, all session tokens are generated as custom HMAC-SHA256 signature blocks, verified cryptographically on the server. We also support two-factor TOTP authentications (2FA).

Role-Based Access Controls (RBAC)

Fine-tune partner access by defining precise Roles: Workspace Owners, Admins, and standard Members. Restrict administrative tasks, billing changes, and API key deletions to authorized team leads.

Audit Logs & Activity Telemetry

Every configuration change, key generation, domain verification request, and member invite is recorded in a secure global audit registry with timestamps and actor attribution logs.

Multi-Tenant Data Isolation

Each client organization is provisioned with separate logic layers and tenant constraints to prevent cross-contamination or unauthorized access leaks across active workspaces.

Scope-Bounded API Security

API keys are generated with granular read/write permissions (e.g. messages:write, domains:read). You can revoke keys instantly to isolate compromised apps without stopping other relays.

Sangi Compliance Roadmap

We are actively designing Sangi Mail infrastructure around global security standards to offer validated security assessments.

GDPR ComplianceFull data exportability and zero-retention logging options.
ISO 27001 PrepUndergoing internal audit processes and control mapping.
SOC 2 Type IIRoadmapped to establish operational controls checks.