<!-- Envolt Mail · https://envoltmail.com/status · Markdown version of this page for AI agents. Status: in development (https://envoltmail.com/status). -->

Status · updated October 2, 2026

# What runs today

Envolt Mail is in development. This page is generated from the same status file as every badge on this site, so the two can't disagree.

- **[Live]**: Public and running in production.
- **[Running in staging]**: Built and running on our staging environment, on synthetic test mail only.
- **[Designed]**: Specified in detail, not built or not switched on yet.

## Capabilities

### Public

- **This website** [Live] envoltmail.com, with a strict content security policy, no cookies and no analytics.
- **Authenticated, signed domains** [Live] Our own domains publish Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) records and are signed with Domain Name System Security Extensions (DNSSEC).

### Inbound

- **Airlock quarantine** [Running in staging] Parses each message in isolation, converts HTML to plain text, removes and counts hidden content and invisible characters (including Unicode tag characters), and inspects attachments.
- **Rules-first triage** [Running in staging] Duplicates, bulk mail and notifications are recognized by rules before any model runs.
- **Agent Seal verification** [Running in staging] Incoming mail that carries an Agent Seal header is checked against the sender's published keys.
- **Quarantined reader** [Running in staging] A reader with no tools turns each message into a structured case. It redacts card, bank account and US Social Security numbers first, can only raise attention, and fails closed to a person. It runs on a no-cost synthetic stand-in; no real model is switched on.

### Storage

- **Per-message encryption** [Running in staging] Raw mail and attachments are encrypted with a key per message, wrapped under a per-customer key, with versioned keys.

### Record

- **Tamper-evident ledger** [Running in staging] Every event is hash-chained and anchored daily. Conversation threads are re-verified before each anchor, and a broken chain is sealed and recorded, never anchored.
- **Isolation canaries** [Running in staging] Every staging check plants unique markers in separate synthetic test customers and confirms neither can see the other's.

### Mailboxes

- **Mailbox connections** [Designed] Read-only connections beside your existing mail, never in its delivery path. A read-only connector is built and tested but not connected to any mailbox.

### Agents

- **Agent drafting** [Designed] Agents read a conversation and propose a plan: a reply, an action, or a question for a person.
- **Seal policy** [Designed] A policy engine that checks every plan's recipients, content, rate and approval needs against rules your team owns.

### People

- **Approval queue** [Designed] One card per decision: the ask, a recommendation, alternatives, the risk, and one-tap approve, edit or hold.
- **Earned autonomy** [Designed] An agent can earn routine sends from its measured track record, and loses them automatically on any serious mistake.
- **Kill switch** [Designed] Halts every agent, one persona or a single agent instantly.
- **Accounts and sign-in** [Designed] Invited accounts with passkeys. There are no accounts yet.

### Outbound

- **Labeled, sealed sending** [Designed] Each approved message gets a single-use capability and goes out with the AI agent label, a signed Agent Seal header and a plain-language disclosure.
- **Public receipts** [Designed] A verify link that shows who the agent is, who it works for and whether a person approved, never the message content.

### Builders

- **API, webhooks and MCP** [Designed] A REST API, signed webhooks and a Model Context Protocol (MCP) server for agents. Specified, not built.

## Latest release evidence

Every release runs through a gated lane and leaves a receipt. These are the most recent ones.

### Service release `slice-14.0`

October 2, 2026 · commit `7b75d6968172`

- ✓ Full test suite
- ✓ Security gate tests
- ✓ Bundle leak scan
- ✓ Domain settings match the recorded posture
- ✓ Database migration tests
- ✓ Staging smoke checks, including live attack samples
- ✓ Production health verified

### Website release

October 2, 2026 · commit `a274d4c8c636`

- ✓ Site build
- ✓ Site leak scan
- ✓ Site tests
- ✓ Staging, then production, verified page by page
- ✓ Home page Largest Contentful Paint (LCP) 1,736 ms against a 1,800 ms target; other pages 1,688 ms or less. Layout shift 0. Measured on emulated slow 4G.

## What comes next

The planned order, without dates. It may change, and this page will change with it.

### Now

- The inbound pipeline in staging: Airlock, reader, ledger and integrity checks
- This website, built in the open

### Next

- The Seal policy engine and agent drafting
- A first read-only mailbox connection in shadow mode
- An approval console for the accountable human

### Later

- Labeled, sealed sending with single-use capabilities
- Public receipts and earned autonomy
- Early access for outside teams

History: [the changelog](https://envoltmail.com/changelog) (also as an [Atom feed](https://envoltmail.com/changelog.xml)). Agents: this page is at [/status.md](https://envoltmail.com/status.md).
