For enterprises · Self-hosted, sovereign, auditable

Vectis Mail for enterprises.
Email infrastructure on your terms — your servers, your data, your audit trail.

Vectis Mail is self-hosted email infrastructure for enterprises that need data sovereignty, audit trails, multi-domain hosting, and source-available code. The Enterprise tier is live today — from $499 USD/tenant/month, flat, never per seat — adding SAML 2.0 SSO, SCIM 2.0 provisioning, GDPR DSAR export & erasure, and a business-hours support SLA on top of Pro. Clustering, hardened multi-tenancy, and audit-evidence packs remain on the roadmap; we're transparent about what's in the box today and what's coming.

Last updated ·By the Vectis Mail team

What enterprise IT teams get today

Six things in-box on Pro that matter to security, IT, and procurement teams.

1. Full data sovereignty

Vectis Mail runs on your VPS, your sovereign cloud, your on-prem cluster. Email content, metadata, and analytics live in your Postgres. You choose where the data resides (EU, UK, US, ANZ, GovCloud) and who has access. No vendor-side copy of customer email.

2. Source-available, auditable code

BSL 1.1 core. Your security team can read the source, run their own code review, instrument the build, verify what's running matches what's in GitHub. Closed-source vendors can't make that promise.

3. Domain-level isolation from the database up

Every domain has its own DKIM keys, and Pro adds per-domain analytics, advanced spam controls, and per-domain rate limiting. Domain-level isolation is suitable today for trusted-tenant scenarios: internal business units, managed customer brands. Strict cross-tenant isolation guarantees are on the Enterprise roadmap.

4. Atomic updates with rollback

6-phase orchestrator: snapshot, migrate, pull, deploy, health-check, complete. Automatic rollback on any failure. Compose-backup + Postgres dump retained for the rollback window. Change-management trails the audit team can verify.

5. RBAC + MFA + OIDC SSO

Three-tier roles (super_admin, admin, domain_admin), TOTP multi-factor auth required, OIDC SSO with Google, Azure AD, and Keycloak. API keys with domain scoping + per-key rate limits. The access-control posture procurement asks about.

6. Observability built in

Prometheus-format metrics and health alerts built in; optional Grafana dashboards and Loki log aggregation (off by default), alertmanager rule templates. Your SRE / SOC team gets the visibility they expect, not "check the vendor dashboard" hand-waving.

What the Enterprise tier includes today

The Enterprise tier is live now — from $499 USD/tenant/month, flat, never per seat, custom above. Everything in Pro, plus:

SAML 2.0 single sign-on

Enterprise SAML 2.0 SSO for Okta, Microsoft Entra ID, ADFS, and any SAML-compliant IdP — alongside the OIDC SSO (Google, Azure AD, Keycloak) that ships on Pro. Centralise authentication under your existing identity provider.

SCIM 2.0 provisioning

Automated user provisioning and de-provisioning via SCIM 2.0. Wire Vectis Mail into your identity provider so mailbox lifecycle follows your directory — joiners, movers, and leavers handled without manual admin.

GDPR DSAR export & erasure

Data-subject access request tooling: export or erase a subject's personal data on request, with the audit trail to prove it. Built for teams answering GDPR / CCPA requests on a clock. (The config-based data-retention sweeper ships on every tier.)

Business-hours support SLA

First-response targets by severity, 9am–5pm AEST (Mon–Fri, excl. AU public holidays): P1 (production mail flow down) 4 business hours, P2 (major feature degraded) 8 business hours, P3 2 business days, P4 3 business days. These are first-response targets, not resolution times, covering the Vectis Mail software. 24/7 priority response is available as a custom add-on. Because Vectis Mail is self-hosted, there is no uptime SLA — your server's availability is yours to run.

Critical security-patch commitment

We commit to issuing critical security patches promptly and prioritising confirmed critical fixes into the next patch release.

Custom contract terms

Bespoke licensing, indemnification clauses, custom DPA, MSA negotiation. Pro is a click-through; Enterprise is a negotiated contract designed to slot into your procurement framework.

On the Enterprise roadmap

Still ahead, and we publish it so you can plan against it: multi-node clustering with HA failover, hardened cross-tenant isolation for mutually-distrustful tenants on shared infrastructure, pre-built audit-evidence packs (SOC 2 / HIPAA / ISO 27001), and advanced deliverability monitoring. See "Gaps we'll close" below for where each one stands today.

Compliance questions, answered

What procurement and security teams typically ask. Frank answers.

SOC 2 / HIPAA / ISO 27001 reports?

Not as a Vectis Mail vendor today. Self-hosted means you operate the controls and produce the evidence. The Enterprise tier will add evidence packs that slot into your audit work. If you need a vendor-side report on a procurement timeline, contact us and we can scope the path.

Data residency guarantees?

Absolute. Vectis Mail runs on your infrastructure; you choose the region, and that's where the data is. The only outbound dependency is the Pro licence verification call to api.validonx.com, which carries no customer data. For air-gapped requirements, talk to us about offline-licence operation modes.

DPA / GDPR alignment?

Standard DPA available for Pro customers. Because the data stays on your infrastructure, the GDPR controller / processor relationship is yours end-to-end. Vectis Mail is the software, not a data processor. Enterprise contracts add custom DPA negotiation.

Penetration test reports?

The BSL 1.1 source is on GitHub, so your security team can run their own static analysis, fuzzing, or manual review. Third-party pen-test reports as a vendor deliverable land with the Enterprise tier. Until then, we're transparent about the surface area: the architecture overview at /architecture/overview is the starting point.

Disaster recovery posture?

Scheduled backups with AES-256-GCM encryption, off-site replication via standard tooling (rclone, rsync, S3), atomic rollback during updates. Your DR plan slots in cleanly: Vectis Mail is one Compose stack, one Postgres, and one maildir tree, all standard formats.

Pricing for enterprise volume?

Pro is $39 USD/tenant/month. Enterprise starts at $499 USD/tenant/month — flat, never per seat — with custom pricing for larger organisations, sized by deployment (SLA tier, support depth, custom terms). Talk to us with your environment details; we'll scope a quote.

Gaps we'll close

What we don't yet do, but you might need.

Vendor-side SOC 2 report

Not available today. The Enterprise roadmap adds compliance evidence packs that slot into your own audit work. If a vendor-side SOC 2 is a hard procurement gate today, factor in the roadmap timeline.

Cluster mode + HA failover

Today's deployment is single-node. For 99.95%+ uptime targets you'd architect with a hot-standby pattern (replicated Postgres + duplicate Vectis Mail install on a secondary host) until the Phase 4 native clustering ships.

Strict cross-tenant isolation

Today's tenancy isolation is suitable for trusted-tenant scenarios. For mutually-distrustful tenant pairs on shared infrastructure, the safe answer today is one Vectis install per tenant boundary. Hardened isolation for shared-tenancy use cases is on the Enterprise roadmap.

Calendar / contacts (CalDAV / CardDAV)

Not yet; Phase 4 roadmap. If you need Exchange-replacement scope (mail + calendar + contacts in one stack), Vectis Mail covers mail today and the rest later. Pairing with a separate CalDAV/CardDAV server in the interim is workable.

Frequently asked questions

What's available today vs the planned Enterprise tier?

Vectis Mail ships three tiers today, all self-hosted with BSL 1.1 source available: Starter (free), Pro ($39 USD/tenant/month), and Enterprise (from $499 USD/tenant/month, flat, never per seat). Pro adds unlimited domains, per-domain analytics, advanced spam controls, OIDC SSO, and priority support. Enterprise adds SAML 2.0 SSO, SCIM 2.0 provisioning, GDPR DSAR export & erasure, a business-hours support SLA, and a critical security-patch commitment. On the roadmap: multi-node clustering with HA, hardened cross-tenant isolation, audit-evidence packs, and deliverability monitoring.

Can I run Vectis Mail on-premise or in an air-gapped environment?

Yes. Vectis Mail is a Docker Compose stack that runs on any Linux host you control: your own data centre, sovereign cloud, air-gapped network. The Pro licence verification call (the only outbound dependency) callsapi.validonx.com once per licence refresh; that's the only network requirement. For fully air-gapped deployments, contact usabout offline licence operation modes.

Do you offer SOC 2 / HIPAA / ISO 27001 reports?

Not as a Vectis Mail vendor today. Because Vectis Mail is self-hosted, the compliance posture is yours: you operate the controls, you produce the evidence. The Enterprise tier will add audit-evidence packs (logs, configuration attestations, change-management trails) designed to slot into your own SOC 2 / HIPAA / ISO 27001 audit work. If you have a procurement timeline requiring a vendor-side SOC 2 report, talk to us. We can scope the right path for you.

Do you offer enterprise support / SLAs?

Yes. Pro includes priority email support. Enterprise (from $499 USD/tenant/month) adds a business-hours support SLA with first-response targets by severity — P1 (production mail flow down) 4 business hours, P2 8 business hours, P3 2 business days, P4 3 business days (9am–5pm AEST, Mon–Fri, excl. AU public holidays). These are first-response targets, not resolution times, and 24/7 priority response is a custom add-on. Because Vectis Mail is self-hosted, there is no uptime SLA. Need it scoped? Get in touch.

How does Vectis Mail handle multi-tenancy at enterprise scale?

Vectis Mail isolates at the domain level — every domain has its own DKIM keys, analytics, and spam controls. Today's domain-level isolation is suitable for trusted-tenant scenarios (multiple internal business units, multiple managed customer brands under one operator). Strict cross-tenant security isolation guarantees (the level you'd want before running mutually-distrustful tenants on shared infrastructure) are on the Enterprise roadmap. Until then, the safe answer for security-sensitive tenant pairs is one install per tenant boundary.

How do I get started with a pilot or proof of concept?

Two paths. (1) Self-serve: install Vectis Mail on a sandbox VPS, and evaluate the platform, including Pro features, before committing to billing. (2) Guided: contact uswith your environment details, compliance requirements, and timelines; we'll scope a pilot that addresses your specific procurement gates. Some enterprise teams prefer to validate the architecture first, then layer compliance work on top.

Let's talk about your environment

Enterprise procurement isn't self-serve. Tell us what you need; we'll scope the right path: pilot, Pro evaluation, or Enterprise onboarding.

Source-available · Self-hosted · No lock-in · Pro is self-serve today

Last updated

Occasional email on new releases and self-hosting guides. No spam, unsubscribe anytime.