A secure email workspace for every client room.

SkyeMail Vault is a secure “public inbox” for your brand: anyone can send you a message from your public page, you get an instant email alert, and the full message content stays end-to-end encrypted in your vault. Only the unlocked workspace can read it, unless recovery is explicitly enabled during setup.

End‑to‑end encrypted
Sender encrypts subject + body in their browser using your public key. Server stores ciphertext only.
Inbox + notification
Neon stores encrypted vault data while SkyeMail powers the hosted inbox, send lane, and delivery receipts.
Recovery is opt‑in
At signup you can allow admin recovery. If you don’t, nobody can recover the vault.
kAIxuGateway13 ready
Optional AI assistant panel uses only kAIxuGateway13 endpoints and fetch+ReadableStream SSE parsing.
Public address format: /u/<handle>
Example: https://your-site.netlify.app/u/yourbrand
Messages are encrypted on the sender side, stored encrypted, and decrypted locally after you unlock with your Vault Passphrase.
What is the vault key?
Your workspace creates a public/private key pair. The public key receives encrypted mail. The private key is what opens it.
Why the passphrase matters
Your private key is stored only after being wrapped by your Vault Passphrase. SkyeMail can hold the locked key, but it cannot read messages without your unlock step.
What Resend does
Resend delivers inbound and outbound email events. SkyeMail then encrypts inbound content into the vault before saving the inbox record.
What recovery means
If recovery is off and you lose the passphrase, encrypted content may be unrecoverable. If recovery is on, a separate admin-recovery copy is stored encrypted.
Powered by Skyes Over London LC • Execution-first systems
Use this as your “public email front door” — without turning your inbox into a spam landfill. Your vault becomes the place where messages are accountable, searchable, and private.
Inbox laneClient replies land as encrypted workspace records.
Compose laneOutbound mail runs through the verified send path.
Vault key cardSetup, recovery policy, and mailbox identity travel together.
0S handoffThe workspace can connect back into the client operating system.