ZTmail S/MIME Automation Gateway

The Gateway for Enterprise Email Security, Automated S/MIME Encryption for Every Organization.

1. PRODUCT OVERVIEW

ZTmail S/MIME Automation Gateway (Abbreviated as ZTmail Gateway) is an enterprise cryptographic gateway designed to automate S/MIME email security on an organizational scale. It handles the cryptographic functions that conventional email security gateways are not designed to provide, while allowing existing security, anti-phishing, malware, DLP, compliance, and content-inspection systems to remain in place.

Core capabilities:

  • Built-in enterprise CA and Sub CA certificate
  • S/MIME Certificate lifecycle management automation
  • S/MIME encryption and decryption
  • Digital signing and signature validation
  • Trusted identity recognition and policy signals
  • Multi-CA certificate supply and automated failover
  • Local private-key generation and protection
  • Enterprise-scale policy and certificate management

ZTmail handles cryptography. Your existing security infrastructure handles email security.

2. TWO DEPLOYMENT EDITIONS

ZTmail Gateway is offered in two deployment editions. Both use the same core cryptographic gateway architecture, but are optimized for different organization sizes and deployment economics.

Edition
Best For
CA Model
Deployment Model
Hardware Gateway
Medium to very large organizations; high assurance and high mailbox volume
Built-in enterprise CA with ZTmail trusted organizational Sub CA certificate, HSM protection. And public CA certificate automation available.
Dedicated hardware appliance; HA deployment recommended
Software Gateway
Small to medium organizations, typically below 1,000 mailboxes
No built-in enterprise CA; certificate supply through ZTmail ACME service and Public CAs
Software deployment; annual service model available

3. CERTIFICATE TRUST MODELS

One Gateway. One Automated Certificate Strategy. Three Trust Models: ZTmail Trust (ZT), Global Trust (GT) and Hybrid Trust (HT).

Trust Model
Certificate Source
Typical Use
Commercial Logic
ZTmail Trust
ZTmail Trust CA Infrastructure
Internal organizational email, Gateway-to-Gateway communication, ZTmail ecosystem
Included at organizational scale; no per-mailbox certificate charge
Global Trust
Public CAs
External communication requiring Public CA trust in other S/MIME clients
Public CA certificates supplied through ZTmail ACME service
Hybrid Trust
Enterprise CA + ZTmail CA + Public CA
Use ZTmail trust for most mailboxes and Public CA certificates for selected external-facing mailboxes
Optimize cost by using Public CA certificates only where global trust is required

4. HARDWARE GATEWAY

For organizations that require a self-contained cryptographic gateway with an integrated enterprise CA, the Hardware Gateway combines the IMAP and SMTP service, built-in CA services, ZTmail trusted organizational Sub CA certificate, dedicated hardware cryptographic protection (PCIe HSM card), security strategy module and autonomous AI access module.

The built-in CA can automatically issue ZTmail-trusted S/MIME certificates for the organization's mailboxes and manage their lifecycle without per-mailbox & per-certificate limit. This changes the economics for large organizations: the investment is the cryptographic gateway infrastructure rather than an annual fee for every mailbox.

The Gateway deployments are designed around high availability, default using a redundant Gateway pair with load balancing and automatic failover. The organizational Sub CA private key is protected by Gateway’s integrated PCIe HSM card.

Key commercial principle: ZTmail-trusted enterprise S/MIME certificates can be provisioned at organizational scale without a per-mailbox certificate charge, without quantity limit.

Models are differentiated by throughput, concurrent connections, cryptographic performance, storage, and supported mailbox scale, the typical deployment is a redundant HA pair. The certificate trust domains (ZT or GT) composition can be customized by customers.

Model
Recommended Scale
Typical Trust domains
Typical Deployment
EG-1K-H
Up to 1,000 mailboxes
950 ZT + 50 GT
Entry enterprise / departmental HA pair
EG-5K-H
Up to 5,000 mailboxes
95% ZT + 5% GT
SMB / mid HA pair
EG-20K-H
Up to 20,000 mailboxes
95% ZT + 5% GT
Large enterprise HA pair
EG-50K-H
Up to 50,000 mailboxes
95% ZT + 5% GT
Large enterprise / service provider HA pair
EG-100K-H
Up to 100,000 mailboxes
95% ZT + 5% GT
Large-scale enterprise HA pair
EG-100KP-H
100,000+ mailboxes
Customized
High-volume / customized architecture

5. BUILT-IN ENTERPRISE CA

A dedicated organizational Sub CA certificate is built into the Hardware Gateway. The Sub CA operates under the organization's configured ZTmail Trust Root hierarchy and is protected by the Gateway's built-in PCIe HSM card.

The built-in CA can automatically issue and manage ZTmail-trusted S/MIME certificates for employees and mailboxes at organizational scale without certificate type and quantity limit. The organization does not need to purchase a separate certificate for every employee simply to establish trust inside the ZTmail trust domain.

When a mailbox must present a S/MIME certificate trusted by external S/MIME clients outside that trust domain, a Public CA certificate can be supplied automatically through the configured certificate-supply service.

6. GLOBAL CERTIFICATE SUPPLY

For organizations that require Global Trust, ZTmail can automatically supply certificates from eligible Public CAs according to the selected trust model and certificate requirements.

Public CA certificates can be selectively deployed for mailboxes that communicate with external organizations, public-sector entities, international partners, or other environments where globally trusted S/MIME certificates are required.

Use ZTmail Trust at organizational scale. Use Global Trust where it matters.

7. SOFTWARE GATEWAY

The Software Gateway is designed for smaller organizations that need automated S/MIME encryption without the infrastructure and operational complexity of a dedicated hardware appliance. It provides the same core cryptographic gateway functions while automatically supplying ZTmail trust and global trust certificates.

Gateway Models are differentiated by supported mailbox volume. The certificate type mix and trust domain allocation shown below are typical configurations provided as a reference for customers. Certificate types and trust domain allocation can be customized according to the customer's requirements.

Models
Supported Mailboxes
Typical Certificate Composition
Typical Trust Domain Allocation
Positioning
EG-100-S
Up to 100
85 MV + 10 OV + 5 SV
90 ZT + 10 GT
Small organization / pilot
EG-250-S
Up to 250
200 MV + 40 OV + 10 SV
230 ZT + 20 GT
Small business
EG-500-S
Up to 500
430 MV + 50 OV + 20 SV
470 ZT + 30 GT
Growing organization
EG-1K-S
Up to 1,000
910 MV + 60 OV + 30 SV
960 ZT + 40 GT
Medium organization
EG-1KP-S
1,000+ mailboxes
Customized
Customized
Large organization

For organizations with over 1,000 mailboxes can negotiate bulk custom pricing, but strongly recommend using a hardware gateway, as there are no longer any certificate fees or mailbox number limits.

8. WHAT IS INCLUDED

Capability
Hardware Gateway
Software Gateway
S/MIME encryption / decryption
Included
Included
Digital signing / validation
Included
Included
Trusted identity recognition
Included
Included
Certificate lifecycle automation
Included
Included
Multi-CA certificate supply
Included
Included
Automatic failover
Included in HA architecture
Depends on the deployment method
Built-in enterprise CA / SubCA
Included
Not included
Dedicated HSM protection
Included
Not included
Public CA certificate supply
Available
Available
Existing email security gateway integration
Included
Included

9. CERTIFICATE AUTOMATION

You Buy Encryption. ZTmail Manages the Certificates.

ZTmail automates the complete certificate lifecycle:

Request → Validate → Issue → Deploy → Renew → Replace

For Hardware Gateway deployments, the built-in enterprise CA can issue ZTmail-trusted organizational certificates at scale. For Public CA certificates, ZTmail Cloud coordinates certificate supply and the applicable CA validation and issuance process.

The Gateway can combine multiple certificate sources without forcing administrators to manually manage individual certificates.

10. DECRYPT FIRST. INSPECT NEXT. ENCRYPT LAST.

Two Gateway Models. One Secure Email Architecture.

Inbound
Encrypted Email → ZTmail Gateway → Decrypt & Verify → Existing Security Gateway → Inspect & Protect → Recipient

Outbound
Sender → Existing Security Gateway → Inspect & Protect → ZTmail Gateway → Sign & Encrypt / Sign → Recipient

ZTmail handles cryptography. Your existing security gateway handles email security. Each does its own duty.

11. TRUSTED IDENTITY

ZTmail Gateway can recognize the identity assurance represented by an S/MIME certificate and make it available as a configurable security policy signal.

MV: Mailbox Validated      IV: Individual Validated      OV: Organization Validated      SV: Sponsor Validated (Individual + Organization Validated)

Organizations can use these signals in policy decisions such as allow, prioritize, inspect, warn, alert, or quarantine, subject to their own security policies.

The Gateway complies with the CA/Browser Forum defined certificate identity types. Global Trusted and ZTmail Trusted S/MIME certificates are issued according to the applicable CA's policies and the current S/MIME Baseline Requirements.

12. PRIVATE KEY SECURITY

For Hardware Gateway deployments, the organizational Sub CA private key is protected by the integrated hardware cryptographic module. User private keys are generated and managed within the Gateway environment according to the organization's configured key-management policy.

The ZTmail Cloud Cryptographic Service is used for certificate supply and lifecycle management automation only; end user’s private key is securely stored in local device only.

High-availability Gateway deployments are designed so that the cryptographic service remains available during a node failure. Enterprise key-retention and historical-key requirements can be addressed according to the customer's architecture and key management policy.

13. EXISTING SECURITY GATEWAY INTEGRATION

Don't Replace. Complete. Each does its own duty.

Keep your existing email security gateway or system for threat detection, anti-phishing, malware detection, DLP, content inspection, and compliance. Add ZTmail Gateway for the cryptographic operations required to safely process S/MIME email.

Protect Your Existing Security Investment. Let Security Gateways Do What They Do Best. Let ZTmail Do Cryptography Best.

14. HARDWARE VS. SOFTWARE

Decision
Hardware Gateway
Software Gateway
Best fit
1,000+ mailboxes / high assurance
Typically <1,000 mailboxes
Built-in enterprise CA
Yes
No
SubCA hardware protection
Yes
No
ZTmail-trusted certificates
Organizational scale
Through cloud certificate service
Public CA certificates
Optional / selective
Available
HA
Dedicated redundant pair
Software deployment architecture
Primary value
Long-term enterprise investment, large scale saves
Lower entry cost / faster deployment

15. PROPOSED COMMERCIAL STRATEGY

Hardware Gateway:

  • One-time infrastructure investment
  • Capacity-based product models
  • Built-in enterprise CA
  • ZTmail-trusted certificates at organizational scale
  • Optional annual support / SLA
  • Public CA certificates charged by actual requirement or included allocation

Software Gateway:

  • Annual subscription
  • Mailbox-count based
  • No built-in enterprise CA
  • Automated certificate supply through ZTmail Cloud, ZTmail-trusted and Global trusted certificate mixed
  • Public CA certificates included according to the selected plan or charged as an add-on

16. Close the Cryptographic ability Gap

Don't let encrypted email create a security blind spot. Deploy ZTmail Gateway to decrypt and verify inbound encrypted email before security inspection, and sign and encrypt outbound email only after it has passed your existing security controls.

REQUEST PRICING
Tell us your organization size and deployment requirements. We will recommend the appropriate Gateway model and certificate configuration strategy.