VaultMail

Secure email encryption.
One click in Gmail & Outlook.

Send confidential patient, client, and business information straight from Gmail or Outlook. VaultMail adds one-click encryption, controlled recipient access, and a complete audit trail — without forcing your team into a new inbox.

HIPAASelf-serve BAA on Vault Ledger, signed in 60s
ENCRYPTEDAES-256-GCM, a unique key per message
AUDIT TRAILEvery open logged · 6-year ledger
REVOCABLERecall a mis-sent email any time
Free for individual providers · No credit card · Recipients open in one click, no account
New Message×
Auto-encrypt: ONEncrypt:Entire emailAttachments only
FromDr. Maya Patel <maya@lakesideclinic.com>
Torecords@stmarys.orgCc   Bcc
Patient referral — intake & MRI attached
Hi Dr. Rivera,

Referring Jordan Lee (DOB 03/14/1988) for follow-up. Intake notes and imaging attached — please confirm receipt.

Dr. Maya Patel
Lakeside Family Clinic
📎intake-form.pdf· 210 KB
📎MRI-scan.jpg· 8.2 MB
↶ ↷Sans Serif ▾tT ▾BIUA ▾
Aa🔗
Patient referral — intake & MRI attached SENT · ENCRYPTED
to records@stmarys.org · just now
AES-256 encryptedBody & attachments sealed with AES-256-GCM
U2FsdGVkX1+8fK2vQ9mZLw3hR4tN2kCc8DpXaGqYb7JprM4nE6sVzT0iWuHxAdOfKgQe5RyBl1cS9mP2vNwXjZrTk3LhY8fDqUoCa6BiIeGnV0MxRsW4tJzKpN7yQdHbAvErTgCmXil5oZuFwSD2kNqP…
View secure message
2 encrypted files· 8.4 MB
filenames sealed too — metadata is confidential
● LOGGEDvaultmailapp.com/v/8fK2… · every open recordedRevoke access
Ordinary email behavior — confidential documents leaving an inbox unprotected
§ The cost of plaintext

The cost of not encrypting is documented.

$4.88M
Average cost of a data breach, 2024
src · IBM Cost of a Data Breach Report

Email is the initial attack vector in 35% of breaches. Per-record costs run highest in healthcare ($408) and finance ($217).

$1.5M
Annual HIPAA penalty cap, per violation category
src · HHS / 45 CFR §160.404

Tiered fines start at $137 per record for unknowing violations. Willful neglect tops out at $71,162 per record — and a single misdirected email can include thousands.

2.6B
Personal records exposed in publicly-disclosed leaks, 2024
src · ITRC Annual Data Breach Report

Most weren't sophisticated attacks. They were forwarded attachments, replied-to threads, and unsecured forwarders — ordinary email behavior, doing what email does.

§ Pricing

Pick your retention posture.

No credit card to start. Vault Zero forgets everything at 30 days; Vault Ledger keeps a 6-year audit trail with a signed BAA. Cancel anytime.

Individual
Free

For solo practitioners, founders, and anyone whose inbox carries a few critical messages.

Start free
  • 10 encrypted messages / month
  • 25 MB per attachment
  • 30-day expiry & instant recall
  • Audit log (last 30 days)
  • Email support
Most popular
Vault Zero
Business · Legal · Privacy
$5/ user / mo, billed annually

Leave no trace. Unlimited encrypted email for any team that doesn't want data lingering after it's delivered.

Choose Vault Zero
  • Unlimited encrypted messages
  • 30 MB per secure message
  • Gmail & Outlook extension
  • Recall a mis-sent email — revoke the link so it can't be opened
  • Zero-retention — content & metadata purged at 30 days
  • Instant manual purge — burn a message on demand
  • Priority email + chat support
Vault Ledger
Healthcare · HIPAA
$18/ user / mo, billed annually

Every disclosure, on the record. For clinics and hospitals that need an audit trail and a signed BAA.

Choose Vault Ledger
  • Unlimited encrypted messages
  • 30 MB per secure message
  • Gmail & Outlook extension + recall
  • Signed BAA included
  • 6-year audit ledger — accounting of disclosures
  • One-click §164.528 disclosure export
  • Content auto-shredded at 30 days
Volume discounts at 50+ seats · Annual billing saves up to 37% · Need custom residency, BYOK, or an SLA? Talk to sales →
§ How it works

Three steps. No software for your recipients to install.

New message · Gmail— ⤢ ×
Toalex@protonmail.com
SubjectQ3 financials — signed
Attaching the signed Q3 statements plus the appendix Marcia asked about. Treat as confidential.
STEP 01

Write like you always do

Open Gmail or Outlook. Address the recipient, attach files, type your message. The extension lives in your compose window; you don't change anything about how you write email.

Compose window · bottom bar
VAULTMAIL INJECTION
STEP 02

Hit Encrypt & Send

One extra button next to Send. Optionally set expiry, password, or forwarding rules before clicking. Your draft travels over TLS 1.3 and is encrypted with AES-256-GCM on receipt — stored only as ciphertext.

FROM11:42
You shared a vault
vaultmailapp.com/v/8fK2-…
Vault opened
● LOGGED
STEP 03

Recipient opens in one click

A regular-looking email arrives in their inbox with a View secure message button. Click → verify ownership of their address → decrypt in the browser. No app, no signup. Every open is logged.

§ Built for

The verticals where a leaked email gets expensive.

We're an encryption layer, not a vertical SaaS — but compliance is industry-shaped. Each plan ships with the audit posture, certifications, and contracts your category requires. Pick yours; we'll send the paperwork.

Healthcare & clinics

Patient records, imaging, intake forms, treatment plans, referrals. Signed BAA included on Vault Ledger.

HIPAA · 45 CFR §164.312

Law firms

Privileged correspondence, draft pleadings, discovery, e-signed engagement letters, M&A working papers.

NDA-grade · revocable

Finance & accounting

K-1s, term sheets, board materials, audit working papers, KYC packets, IRS notices.

AES-256-GCM · Audit log

Founders & operators

Trade secrets, investor decks under embargo, exec correspondence, severance, board minutes.

NDA-grade · revocable

HR & talent

Offer letters, compensation packets, performance reviews, separation agreements, immigration paperwork.

Per-recipient expiry

IT & security teams

Credentials, vendor contracts, recovery codes, incident response — the internal email category most likely to leak the company itself.

Revocable · fully audited
§ Where we land

Honest about what we are. (And what we aren't.)

We're not trying to replace your inbox. We're the encryption layer for the messages your inbox shouldn't be carrying in plaintext.

VaultMail
● THIS PRODUCT
Plain email
Generic E2E mail
Enterprise suite
AES-256-GCM encryption
Recipient opens without an account
Per-message expiry & revocation
Append-only audit log
Signed BAA (HIPAA)
Self-serve, on Vault Ledger
$$$ add-on
Works inside Gmail / Outlook Web
Outlook only
File attachments up to 30 MB
25 MB cap
25 MB
Varies
Time to send your first encrypted message
< 60s
instant
10-20m setup
weeks
Per-seat cost, 10-seat team
$5/mo
Free
$25/mo
$25-60/mo
Comparisons reflect published feature sets as of May 2026. "Generic E2E mail" averages ProtonMail / Tutanota. "Enterprise suite" averages Virtru / Paubox / Zix.
§ Questions

Specifically asked, specifically answered.

If your security or legal team has a question we don't cover here, write to admin@spriggan.ai — we answer within one business day, often with the actual engineer on the thread.

No. The Chrome extension injects directly into Gmail and Outlook compose — you write the email the way you always do, then click Encrypt & Send instead of Send. The recipient gets a normal-looking email with a 'View secure message' link. For Apple Mail, Yahoo, Proton, and other clients, use the standalone Chrome popup.

§ How it lives in your inbox

We don't replace your inbox. We add one button to it.

The VaultMail Chrome extension injects directly into Gmail and Outlook compose. Write your email exactly the way you always do — then click Encrypt & Send instead of Send.

● PRIMARY SURFACE

One orange button. Same Gmail.

Write your message in Gmail like you always do. Address it, attach files, hit Encrypt & Send. The extension encrypts everything through VaultMail — AES-256-GCM, a unique key per message, stored only as ciphertext.

  • Auto-encrypt toggle for entire conversations
  • Per-message expiry from 24h to 30d
  • AES-256-GCM with a unique key per message — stored only as ciphertext
  • Force-install via Google Workspace / Microsoft 365 Admin
New Message×
Auto-encrypt: ONEncrypt:Entire emailAttachments only
FromJohn Chen <john@spriggan.ai>
Tosupport@google.comCc   Bcc
Account recovery — verification & backup codes attached
Hi team,

Per your request, I'm attaching the verification documents and backup recovery codes for the workspace audit (ticket #SR-4982). Please treat as confidential — sending via VaultMail.

Let me know if anything else is needed before the call on Thursday.
John Chen
Head of Security · Spriggan
📎recovery-codes.pdf· 28 KB
📎verification-ID.jpg· 1.4 MB
↶ ↷Sans Serif ▾tT ▾BIUA ▾≣ ▾
Aa🔗🗑
VaultMail
mankarisagar@gmail.com
Vault unlocked
Drop files here
or browse
alex@protonmail.com
Expires30d
ForwardingOff
Encrypt & generate link
SECONDARY · FOR EVERYTHING ELSE

Not in Gmail? Use the popup.

For Apple Mail, Yahoo, Proton, internal webmail, or sharing a file outside of email entirely — the standalone Chrome popup gives you the same encryption with a drag-and-drop interface. Same backend, same audit log, same keys.

  • Drag files up to 25 MB into the popup
  • Copy a share link straight to clipboard
  • Works in any browser tab — no email client required
  • Same recipient experience as the Gmail flow