We spent years telling clients to use someone else's secure email while knowing exactly what was wrong with every option we recommended. Eventually that became untenable. Here's what we built instead, and why.
The recommendation problem
As a security company, one question came up in nearly every engagement: *what email should we actually use?*
Every answer had a caveat. The big providers are excellent products with business models built on data. The privacy-focused providers are genuinely better on privacy but often thin on the workspace tools businesses need, so clients bolted on Google Docs anyway — which defeated the point. And self-hosting email in 2026 is a full-time job that ends in a deliverability nightmare for most who attempt it.
We were recommending compromises. So we built the thing we kept describing.
What we actually built
Encryption at rest with AES-256-GCM. Received message bodies are encrypted on our storage. We'll say plainly what isn't: subjects, attachments and sent mail aren't encrypted at rest yet, and we don't offer end-to-end encryption where you alone hold the key. Both are on the roadmap, and we'd rather under-claim than have you rely on something we don't do.
No advertising, ever. No ad network, no tracking pixels, no profiling pipeline, no content scanning for model training. We charge for the product, which is what makes that sustainable rather than aspirational.
Email authentication treated as a first-class concern. SPF, DKIM and DMARC guidance is built into domain setup rather than left as an exercise. We've cleaned up enough client deliverability disasters to know most of them start here.
Layered inbound scanning. Several independent scanning layers run on inbound mail, and the anti-virus layer fails closed — if it can't scan, the message waits rather than being delivered uninspected. That's the opposite of the usual default, and it's deliberate.
A complete workspace in the same login. Docs, Sheets, Slides, Drive, Calendar, Chat, Meet video calls and a PDF editor. Because the alternative is clients moving their documents back to a provider they left, and losing most of the benefit.
Australian owned and operated. A different legal framework applies to your correspondence than with a US-headquartered provider. Whether that matters depends on your situation — we cover the nuance in data sovereignty rather than overselling it.
What we deliberately didn't do
We don't claim to be unhackable. Anyone who does is either naïve or selling something. We claim specific, checkable things: what's encrypted, with what, who can read it, and what our business model requires of us.
We don't claim end-to-end encryption. Standard SMTP mail arrives readable — that's how email works. We offer PGP key management on Business and Enterprise plans, but it is not end-to-end encryption: the key doesn't live solely on your device, so we can still decrypt. We'd rather say that plainly than blur the distinction the way some marketing does.
We didn't build a walled garden. Full IMAP and SMTP access, so any standard client works and you can sync your mail out whenever you want. We don't yet have a one-click archive export — that's a real gap and it's on the list. A product that has to trap you isn't one we'd want to run.
We don't pretend to out-filter Google on spam. They have visibility across billions of mailboxes. Our filtering is layered and good; theirs sees more. We'd rather be honest about that than have you discover it yourself.
Who it's for
Businesses handling client-confidential information — legal, medical, financial, professional services. Teams that want a workspace without an advertising company attached. Anyone who wants their provider's incentives pointed away from reading their mail.
It's not for everyone. If your team lives inside Google Workspace collaboratively and that's working, the migration cost may exceed the benefit. We'd rather say that than sell you something you'll regret.
Where it goes from here
We're a security company that runs an email service, which means the roadmap leans toward threat detection, authentication and hardening rather than another AI writing assistant. If you want to see what we're working on — or tell us what's missing — we read every message.
Try Tobava Mail free
Encrypted email, a private inbox, and a full workspace — built by a cybersecurity company. No ads, no tracking, no message scanning.
Create your free account