For a team or a company
Where the value actually is, what to tell colleagues, and the decisions to take before you start.
Where the value is concentrated
This is worth most between two parties who write to each other regularly about money or
obligations: a company and its bookkeeper, a client and their lawyer, a board and its
members, a business and its three largest suppliers.
It is worth least as a broad rollout to everybody, because most of the mail most people
receive is from parties who will never install anything, and those messages will simply read
as not protected — which is correct, and which teaches nobody anything.
So start narrow. Pick the correspondence where being wrong costs real
money, get both sides on it, and let that prove itself before going wider.
Decisions to take first
1. The data protection question
Protecting a message publishes a permanent public record containing the sender address,
the recipient address, the subject line and the time. The body is not published — only an
unreadable fingerprint of it.
Under the GDPR those addresses are personal data, the record is distributed, and it cannot
be withdrawn. That is a decision to take with whoever is responsible for data protection
before you roll anything out. Please read what is
stored in full and take it to them.
2. Who holds the recovery phrases
Each person's identity is twelve words that only they have. Nobody can reset them. Decide
in advance what happens when somebody leaves, loses a laptop, or is unavailable — because the
answer "we will sort it out then" means mail sealed to them becomes unreadable.
Reasonable approaches: keep phrases in the company password manager under the individual's
own entry; or accept that a lost phrase means a new identity and a thirty-day key-change
warning to correspondents, which is survivable for signing and fatal for anything sealed.
3. Shared mailboxes
An address like invoices@ read by four people can hold one identity, shared by
giving all four the same recovery phrase. Understand what that means: a signature from that
address proves the message came from the shared mailbox, not from which person. For anything
where the individual matters, use individual addresses.
What to tell colleagues
Keep it to three sentences. Longer training is not read.
The message you send them:
"You will start seeing a line at the top of e-mails saying whether we can prove who sent
them. Most mail will say 'not protected' — that is normal and not a warning. If one ever
turns red, do not act on that message and tell me."
The two things worth adding, once:
- A green badge means the message came from that mailbox unaltered. It does not mean the
request in it is sensible. Payment changes still get a phone call.
- A "new key" warning means a colleague set up a new computer — or somebody took over
their account. Ask them in person.
How to roll it out
- One person first, for a week, on their own mail. Usually whoever handles
invoices, because that is where the risk is.
- Then their counterpart at the other organisation. One pair correctly
set up is worth more than fifty people half-configured.
- Turn on automatic protection for those two. Protection you have to
remember is protection you will forget on the day it matters.
- Widen to the next relationship where money moves.
Things that will come up
- Mailing lists and internal newsletters rewrite messages, which breaks
the fingerprint. Expect those to read as altered, and do not sign list traffic.
- Corporate mail filters that append disclaimers do the same thing. If
yours does, signing outbound mail through it will not work until the disclaimer is
applied before the signature rather than after.
- Shared workstations. The desktop app holds your key while unlocked.
On a machine several people use, lock it when you step away.
What to check before relying on it
Read the honest limits and
what you have to trust in full. The short version for a
decision-maker: this has had no independent security audit, the downloads are not
code-signed, and there is no mobile version. Those are real, and they are the reasons to
start with one relationship rather than an organisation.
← All documentation