Business
Privacy for the company, without losing the company's data.
IT gets provisioning, roles, audit and recovery. Employees get software that cannot leak what it never had. The two fit together when the design is clear about who holds which key.
Organisation recovery key
Every shared vault is also sealed to a key the owners hold. Shared data survives every departure. Personal vaults stay personal unless a policy asks members to enrol in recovery.
Single sign-on that adds, not replaces
Sign-in still derives keys from a password nobody else knows. When SSO is on, a fresh assertion from your identity provider is also required, so deprovisioning there ends access here.
Company mail on your domain
Mailboxes for members and shared addresses for the team, delivered sealed to each recipient. An optional compliance key your legal officer holds lets your process read what the law requires; we still cannot.
Team inbox numbers
Main, department and on-call lines delivered to a group, with calls and texts both ways. Number porting and sender registration are handled during onboarding.
Console, audit, policies
Members, seats, invitations, shared collections, audit export, and policies such as required two-step verification and minimum password length, all in the browser.
Paper
A data processing agreement, annual invoicing, and dedicated support.