Security
Security overview
How DeepDynamic Mail separates public content, authentication and mailbox operations.
Identity & access
The public landing page never handles mailbox passwords. Sign-in happens on the dedicated webmail origin.
The webmail layer can use password and TOTP workflows or OAuth/OIDC integrations, depending on operator policy.
Message protection
The webmail client is designed to sanitize rich content and keep remote message resources controlled.
Signing and encryption workflows can be used where the underlying account and server policy support them.
Operations
Infrastructure ownership, update policy, audit logging and network controls remain operator responsibilities.
This public-site package avoids third-party JavaScript by default and keeps CMS storage outside the public document root.