Skip to content
Home Features Email security
Email security

End-to-end encrypted email for the inbox you already use.

One product, three deployment points. The Outlook plug-in, the Gmail Chrome extension, and the Serverless Email Gateway. Every outbound attachment is encrypted with OpenPGP before it leaves the device. No recipient account required.

Three deployment points

Encrypt outbound email three different ways pick what fits.

A native plug-in for Outlook, a Chrome extension for Gmail, and a policy-driven gateway that encrypts traffic automatically. All three share the same split-key encryption, audit log, and recipient experience.

Native plug-in
SendSafely for Outlook & Office 365

Encrypt files and messages from the compose window. Files are encrypted on the sender's machine before they ever reach Exchange or Microsoft 365.

  • Files up to 100 GB per file
  • Outlook desktop (Windows + Mac), OWA, and Microsoft 365
  • Background upload — email auto-sends on completion
  • SMS verification option per recipient
Plug-in details
Chrome extension
SendSafely for Chrome & Gmail

Adds an “Attach with SendSafely” button to the Gmail compose window. Files and messages are encrypted in the browser before they touch any Google server.

  • Files up to 10 GB per file
  • Gmail in Chrome — consumer and Workspace
  • Standalone popup mode for non-Gmail sends
  • Optional full-message encryption
Extension details
Server-side — Enterprise
Serverless Email Gateway (SEG)

An AWS Lambda gateway that automatically intercepts and encrypts inbound and outbound email based on policies you define. Users don't have to remember anything; keys stay in your own AWS account.

  • Policy-based encryption — automatic, not opt-in
  • Office 365, G-Suite, Salesforce, Zendesk, Freshdesk
  • Runs in your AWS account — no extra infrastructure to host
  • Inbound and outbound coverage
Enterprise pricing
How it works

Four steps your senders never have to think about.

Admin installs the Outlook or Gmail plug-in or deploys the gateway once. End users compose email the way they always have. Files are encrypted, replaced with a secure link, and logged — in the background.

01
Sender installs (or admin pushes)

The Outlook plug-in installs from Microsoft AppSource; the Gmail extension from the Chrome Web Store. Tenant admins can push it centrally. The SEG deploys to your AWS account.

02
User composes normally

Drag a file into Outlook or Gmail. The plug-in encrypts client-side with OpenPGP and uploads in the background. The user keeps typing.

03
Attachments swapped for a secure link

The recipient gets your email with a one-time SendSafely link in place of the raw file. The Client Secret lives in the URL fragment — never sent to any SendSafely server.

04
Recipient verifies & decrypts

Recipient clicks the link, verifies identity (PIN, SMS, or SSO), and the file decrypts locally in their browser. No SendSafely account required. Every access is logged.

outlook.office.com / compose
New message
SendSafely encrypted
Toaccounting@example.com
Cccompliance@example.com
Signed Q1 financial package

Please find the signed Q1 financials attached. Files have been encrypted with SendSafely — you'll be asked to verify your identity with a one-time PIN before downloading.

Q1_financials_signed.pdf Encrypted · 8.4 MB · Expires in 7 days
Sealed
board_packet.zip Encrypted · 142 MB · SMS verification on
Sealed
End-to-end encrypted Split-key Send
What end users see: the same compose window, with an encrypted-attachment chip.
The encryption layer is invisible

The compose window stays exactly the same. The attachment doesn't.

SendSafely intercepts standard attachments and replaces them with end-to-end encrypted SendSafely links the moment your sender hits send. The decryption key is split between a token in the URL and a server-side fragment — neither half can decrypt the file on its own.

  • Files encrypted before they leave the device
  • No recipient account needed
  • Bypass attachment limits
  • Identity verification on every download (PIN, SMS, or SSO)
  • Auto-expiration on a schedule you configure

The encryption controls regulated industries need.

No pre-shared keys. No infrastructure to host. No retraining for senders or recipients. The same controls you'd build in-house, configured in the admin console.

No attachment size limit

Files encrypted with our plug-ins never touch your email server, so you're not stuck at the Exchange or Gmail attachment ceiling. Up to 100 GB per file on Outlook, 10 GB on Gmail.

No pre-shared keys

SendSafely generates encryption keys dynamically per message. Nobody has to publish a public key or manage a keyring.

End-to-end encryption

Plug-in encryption is applied client-side, before data is uploaded. SendSafely stores customer content as ciphertext only and cannot decrypt it.

Nothing to install for recipients

Recipients open encrypted email in any modern web browser. One click, identity verification, decrypt in-browser. Done.

Automatic expiration

Encrypted files and messages auto-delete on the schedule you set. The audit trail is preserved after deletion for compliance reporting.

Verification for recipients

Specify a mobile number per recipient for SMS-based one-time-password verification before a file unlocks. PIN and SSO are also supported.

Download tracking & alerts

See exactly who viewed an item, when, and from where. Every download is timestamped for compliance reporting.

No infrastructure to host

A managed cloud service. The Serverless Email Gateway runs in your AWS account when you need server-side rules — everything else is managed.

Split-key architecture

Email attachments are encrypted before they reach any server

Every plug-in attachment is encrypted on the sender's device using the OpenPGP message format. Microsoft, Google, and SendSafely all see ciphertext only. The decryption key is split between a Client Secret in the URL fragment and a Server Secret released only after recipient verification.

Audited annually. SendSafely maintains the certifications regulated industries require.

Compliance & certifications
SOC 2 Type 2 HIPAA PCI DSS GDPR CCPA
Client-side OpenPGP
Files are encrypted on the device before they ever leave it.
Split-key architecture
The decryption key is split so no single party—including SendSafely—can decrypt file contents on its own.
Full audit trail
Every send, recipient open, identity check, and download is logged with timestamps for compliance reporting.
Get started

Encrypt the email your team is already sending.

Install the Outlook plug-in or the Gmail Chrome extension in minutes. Add the Serverless Email Gateway when you need automatic, policy-driven encryption.