The Future of Encrypted Email

Paperclip Cmail is a pioneer in email encryption. Originally launching in 2007 as eM4, the solution has protected hundreds of millions of emails with compliance-mandated encryption.

Cmail leverages a proven email encryption algorithm and Paperclip SAFE® technology to elegantly solve the complexity, affordability and resource challenges that organizations face.

Buy Cmail

Cmail Features

Backed by AES 256 Encryption
Supports both B2B and B2C Instruction
Supports large attachments; up to 100 MB
Disinterested third party auditing (D3P)
Proof of Delivery using Wallet Authentication to confirm identity
Proof of Readability ensures attachments can be opened and read
Easily scalable to thousands of users
Low annual cost; as little as $8 per month per user

Advantages

Visibility

- Centralized auditing with dashboard visibility to validate the end-to-end encrypted
- Proof of delivery
- Proof of readability

Simplicity

- No logins or passwords for B2B users
- No code integration
- Access via easy-to-download cloud client
- No user training required

Security

- Backed by AES 256 encryption
- Tamper-proof records
- Fully encrypted replies even for nonsubscribers

Compliance Mandates

Encrypted Email is required by a number of compliance bodies and is a recommended security measure for even more. Find the compliance framework that applies to your industry to learn more.

HIPAA

HIPAA

Health Insurance Portability and Accountability Act

Applies to: HIPAA applies to healthcare organizations, including healthcare providers, insurers, and business associates.

Encryption Requirement: Under HIPAA’s Security Rule, electronic Protected Health Information (ePHI) must be safeguarded during transmission, and encryption is considered an “addressable” safeguard. Encryption is strongly recommended when sending ePHI via email to ensure it meets the confidentiality and security requirements.

GDPR

GDPR

General Data Protection Regulation

Applies to: GDPR applies to organizations that process personal data of EU citizens, regardless of where the organization is based.

Encryption Requirement: While GDPR does not mandate encryption explicitly, it does require data controllers and processors to implement appropriate technical measures to ensure the security of personal data. Encrypting emails that contain personal data is a good practice to comply with GDPR’s requirements of data protection.

PCI DSS

PCI DSS

Payment Card Industry’s (PCI) Data Security Standards (DSS)

Applies to: PCI DSS applies to any organization that processes, stores, or transmits credit card information.

Encryption Requirement: PCI DSS requires the encryption of cardholder data during transmission across open, public networks. While PCI DSS does not specifically mandate encrypted email, it would be considered a valid method of ensuring that payment card information is protected when sent over email.

FISMA

FISMA

Federal Information Security Modernization Act

Applies to: FISMA applies to U.S. federal agencies and contractors.

Encryption Requirement: FISMA mandates that federal agencies implement appropriate security controls, which often include email encryption when transmitting sensitive or classified information. Email encryption is part of the broader requirement to protect federal information systems.

NIST

NIST

The National Institute of Standards and Technology

Applies to:  NIST guidelines are followed by federal agencies and many private-sector organizations.

Encryption Requirement: NIST recommends using encryption to protect sensitive data during transmission, including emails. It is a key component of the NIST cybersecurity framework, which is followed to ensure data protection.

Schedule a Demo

Learn more about our encrypted Cmail solution and meet with our technical team.