Automate the cryptographic operations of enterprise email:
A dedicated organizational Sub CA (S/MIME Issuing CA) is built into the Gateway, enabling automatic issuance and lifecycle management of ZTmail-trusted email certificates for your organization, without quantity limits.
Each organization can have its own ZTmail Trust Domain, providing trusted email digital identities across the organization on scale.
Sign, encrypt, decrypt, verify, renew, and revoke automatically, without requiring every employee to manage certificates themselves.
S/MIME certificates do more than enable encryption. A digitally signed email can carry a trusted digital identity, validated through Global Trust or an organizational trust domain according to applicable standards and policies.
ZTmail Gateway can validate that identity and turn it into an actionable security signal.ZTmail Gateway can recognize the identity assurance represented by the sender's certificate and apply organizational policies accordingly (Go or block directly).
The ZTmail Gateway's built-in enterprise CA automatically issues and manages ZTmail-trusted S/MIME certificates for employees across your organization. For a small number of mailboxes that need global trust for external communication, Gateway can automatically obtain globally trusted MV certificates from Public CAs.
One Gateway. Two Certificate Sources. Multiple Trust Models. One Optimized Certificate Strategy.ZTmail S/MIME Automation Gateway is delivered as a dedicated hardware cryptographic appliance, providing a secure foundation for your organization's email trust domain. With built-in enterprise CA capabilities and hardware-protected CA keys, the Gateway automatically issues and manages organizational trusted and global trusted S/MIME certificates for your organization.
Enterprise deployments use redundant dual gateway architecture to ensure continuous cryptographic services: Dual Gateway Cluster, High availability, Load balancing, Service continuity
The Gateway integrates hardware security modules (HSMs) to protect critical CA keys and support secure certificate issuance and lifecycle management.
Client-Cloud based certificate automation for growing organizations that do not require dedicated hardware CA infrastructure, ZTmail Software Cryptographic Gateway provides automated S/MIME certificate management through ZTmail Cloud Cryptographic Service including certificate application, issuance, renewal, revocation etc.
The Organization Sub CA private key is protected by integrated hardware security modules (HSMs), providing a secure foundation for your organization's email trust domain.
Private keys and CSRs for employee S/MIME certificates are generated locally within Gateway and securely managed throughout the certificate lifecycle. Gateway performs encryption, decryption, digital signing, and certificate operations without requiring certificate deployment to every email client.
In enterprise deployments, dual Gateway architecture provides secure key synchronization and operational continuity, ensuring continued access to encrypted email and cryptographic services.
Threat Detection · Anti-Phishing · Malware Detection · DLP · Content Inspection · Compliance
Certificate Automation · S/MIME Encryption · Decryption · Digital Signature · Signature Validation · Trusted Identity
Protect Your Existing Security Investment.AI security is optional. If your organization already has an email security gateway, keep using its security and AI capabilities. If you do not have one, ZTmail Gateway can optionally integrate AI-powered email analysis using your preferred AI provider and your own API key.
Build your own organizational email trust domain with built-in CA capabilities, while using public CA certificates only when global trust is required.
ZTmail helps organizations automate S/MIME encryption, trusted identity, and certificate management with flexible Gateway deployment options.
From dedicated hardware cryptographic infrastructure to cloud-based certificate automation, build the trusted email environment your organization needs.