Built to keep your email private
Business email carries contracts, client data, and financial records. We treat that seriously — with strong encryption, Indian data residency, and no advertising business model to tempt us into reading your mail.
End-to-end encryption in transit
All connections to our servers use TLS 1.3. Email exchanged with other providers uses opportunistic TLS (STARTTLS) and we enforce strict MTA-STS for incoming mail.
Encrypted at rest
Every mailbox is encrypted at rest using AES-256. Encryption keys are managed in a separate key management service and are never co-located with the data they protect.
Data stays in India
All customer data is stored on servers located in India, operated by Sagasoft. We do not transfer personal data outside India without explicit consent.
No advertising, no scanning
We do not read, scan, or analyse your email content for advertising purposes. Your email is yours — we access it only to deliver it.
IT Act & DPDP ready
Our practices are aligned with India's Information Technology Act 2000 and the Digital Personal Data Protection Act 2023 (DPDP). We maintain a Data Processing Agreement for enterprise customers.
Anti-spam & anti-phishing
Inbound mail is scanned for spam and phishing. Outbound mail uses DKIM signing, SPF, and DMARC enforcement to protect your domain's reputation.
Security checklist
What we have in place today
A non-exhaustive list of controls that protect your mailbox. We update this page as we add or change controls.
- TLS 1.3 for all SMTP, IMAP, and web connections
- DKIM, SPF, and DMARC configured for every hosted domain
- MTA-STS and TLSRPT published
- AES-256 encryption at rest
- Automated daily backups retained for 30 days
- Two-factor authentication available for all accounts
- Dedicated abuse and security reporting contact
- Responsible disclosure programme
- GSTIN-registered Indian company — no offshore data routing
Responsible disclosure
Found a vulnerability?
If you have discovered a security issue in our platform, we appreciate responsible disclosure. Please send details to security@sagamail.in and we will respond within two business days. We do not pursue legal action against good-faith researchers.
Report a vulnerability