Coldfeet
Security & compliance

How Coldfeet handles your mail

A mail gateway sees everything your organisation writes. This page is what we do with it, in enough detail to be checked.

Where your data lives

The platform is deployed on infrastructure you control, in the region you choose, so residency is a decision you make rather than one you accept.

  • Self-hosted deployment on your own hardware or cloud account
  • Message bodies stored only as long as your retention policy says
  • Storage backend of your choice, including S3-compatible object stores
  • No message content leaves your deployment for third-party analysis

Encryption

Mail is encrypted in transit on every hop we control, and at rest wherever it is written down.

  • TLS 1.2 and 1.3 on SMTP, with MTA-STS and DANE support
  • TLS-RPT reporting so failures are visible rather than silent
  • Secrets and provider credentials sealed with an install-specific key
  • Optional password-protected PDF delivery for external recipients

Access control

Administrative access is scoped, second-factored, and recorded — including support access.

  • Role-based access with tenant-scoped permissions
  • SSO via OpenID Connect, including Microsoft Entra ID and Google Workspace
  • Enforced two-factor authentication for administrators
  • IP allow-listing on administrative and API surfaces
  • Impersonation sessions are explicit, time-boxed and audited

Auditability

Every change and every message decision leaves a record that survives the person who made it.

  • Append-only audit log of administrative actions
  • Per-message trace retained alongside the verdict
  • Signed webhook and SIEM event streams for external correlation
  • Prometheus metrics and health endpoints for independent monitoring

Resilience

Mail is not allowed to be lost because a component was restarting.

  • Queued processing with retry and dead-letter visibility
  • Continuity spool holds mail while a destination is unreachable
  • Multiple relay hosts supported for inbound and outbound paths
  • Backup and whole-tenant export built into the platform

Frameworks and standards the platform is built against

GDPR (self-hosted residency)TLS 1.3DMARC / DKIM / SPFMTA-STS / TLS-RPT

Send us your security questionnaire

We answer it directly, and we will tell you where the honest answer is "not yet".