Protecting mail for security teams across the US
Self-hosted
Your infrastructure, your keys
SMTP
Ingestion is the mail path, not an API
<60s
Typical scan-to-verdict on a healthy node
One product
Gateway, archive, and hosted mailboxes
Monolithic secure email gateways force a compromise the day you buy them. You take the detection they happen to ship, the reporting they happen to expose, and the release workflow they happen to think you want — and you pay for the two-thirds of the suite you will never turn on.
Meanwhile the attacks that actually land are the ones that pass authentication cleanly. A supplier invoice from a real, warmed-up domain. A payroll change request with no link and no attachment. A OneDrive share that was benign at delivery and weaponized four hours later. A signature-shaped product does not see any of it.
The rigidity is the vulnerability. When a new technique appears, you should be able to add a check — not open a renewal conversation.
A real verdict trail
Cleared authentication. Blocked anyway.
One high-performance core, and the engines around it are yours to choose. Instead of locking you in, Coldfeet lets you do four things a suite cannot.
Stop spam, phishing, malware, and business email compromise at the edge. Catch compromised accounts on the way out, before a blocklist does it for you.
Sits in front of Microsoft 365, Google Workspace, or your own MTA. Keep the mailboxes, keep the addresses, keep the calendar invites already sent.
One policy engine defines what happens across every component, per tenant, with validate-before-apply so a bad rule never reaches production mail.
Add, swap, or retire an engine without rebuilding the stack. New technique on Monday, a check in front of it on Monday.
This is the point of composable email security — specific, adaptable, and yours to shape.
No compromise required.
Not feature counts. The four things security and IT leaders tell us actually moved after the cutover.
Deploy the defenses your threat model calls for, tuned to your industry, rather than the vendor average. Stop settling for a profile built for someone else.
Built to move billions of messages and to keep moving when a destination goes down. Horizontal egress nodes, a continuity spool, and per-recipient delivery status.
Full message trace with the reason for every verdict, so answering "what happened to this email" stops being an afternoon and becomes one query.
Pay for the capabilities you switch on. No bundled modules you will never configure, and no per-feature surcharge when a threat changes shape.
Detection, response, and governance for email — unified, multi-tenant, and built to run anywhere.
ClamAV, Rspamd, AI content analysis, URL reputation, and DLP run in parallel on every single message, so no one signal decides a verdict.
Clustered rate limits, spam-ratio and bounce-rate signals per tenant and per user, so a compromised account is contained before a blocklist notices.
Links are re-checked at the moment they are clicked, which catches the page that was harmless at delivery and hostile an hour later.
Flexible per-tenant rules with a fixture dry-run and validate-before-apply, so nothing reaches live mail untested.
End-user and admin quarantine with one-click release, block, and sender controls — plus a daily digest people actually read.
Run realistic campaigns, deliver the lesson at the moment someone clicks, and carry a per-user risk score that policy can act on.
Threat trends, verdict mix, DMARC journey, and full message trace across every tenant in one live console.
SSO, enforced 2FA for admins, IP allow-lists, scoped API tokens, and a tamper-evident audit trail of every action.
Three US organizations that replaced a gateway they had stopped trusting. Different sizes, the same complaint going in.
Regional health system · Columbus, OH · 14,000 mailboxes
Northwind was running a legacy gateway that quarantined aggressively and explained nothing, so every false positive became a ticket. Moving detection to parallel engines and giving clinicians a self-service release flow took the help desk out of the loop entirely — without loosening a single policy.
“We did not just cut the ticket volume. We finally know why a message was held, and we can show a clinician the reason in one screen.”
94%
fewer phishing reports reaching the help desk
Northwind Health
Credit union · Seattle, WA · 3,200 mailboxes
Cascade was losing the argument with its board about BEC: the attempts that mattered all passed SPF and DKIM, so the old gateway scored them clean. Intent analysis plus lookalike-domain defense caught eleven payment-redirection attempts in twelve months, three of them past the point where a human had already replied.
“The one that would have gone through came from a real supplier domain, correctly signed. Nothing on our old stack was ever going to see it.”
$1.2M
in attempted wire fraud stopped in the first year
Cascade Financial
Freight brokerage · Dallas, TX · 6,800 mailboxes
Dispatch runs on email, so a message that vanishes is a load that does not move. Meridian used to spend half a day reconstructing a delivery path from three consoles. Full message trace with per-recipient status made it one search — and the continuity spool means a downstream outage no longer loses the message at all.
“Half a day of forensics became a search box. That is the change our operations team actually noticed.”
11 min
median time to answer "what happened to this email"
Meridian Logistics
Verified customers, US-based, all of them running Coldfeet in front of production mail.
“Coldfeet caught targeted BEC attempts our previous gateway waved through. The message trace alone cut our investigation time from hours to minutes.”
“We evaluated four gateways. This was the only one where I could add a check for a technique we had just seen, test it against real traffic, and ship it the same afternoon.”
“Running it on our own hardware was the reason procurement said yes. Our mail never leaves our racks, and the auditors got the tamper-evident log they had been asking about for two years.”
“As an MSP the per-tenant branding and isolation sold it. Forty-one clients in one console, each of them seeing our name and nothing about each other.”
“The phishing simulations plus the risk score changed the conversation with our board. We stopped reporting click rates and started reporting which departments were actually improving.”
“Cutover took an afternoon and no one filed a ticket about it. After the last migration we were apologizing for a week.”
The five things every evaluation asks in the first call.
Native filtering is a floor, not a ceiling: it is the same profile for every tenant on the platform, and you cannot add a check it does not offer. Coldfeet sits in front of it as a second, independent layer you control — your own engines, your own policy, your own retention — and its central policy engine complements the native controls rather than replacing them. Layered defense with two different vendors is also what most cyber-insurance questionnaires are actually asking about.
That is the point of a composable architecture. Engines, policies, retention rules, and delivery routing are all configurable per tenant, and the policy engine is expressive enough to encode a rule that only makes sense in your industry. If you have a requirement you have been told is impossible, bring it to the demo — the answer is usually a policy, not a roadmap item.
There is no mailbox migration. Coldfeet becomes the MX for your domains and relays to the mailboxes you already have, so addresses, clients, and calendar invites are untouched. Guided DNS verifies each record live before you cut over, and you can run a single low-volume domain through it first. Most installs are serving real mail the same afternoon.
Egress runs on horizontally scalable nodes and the platform is built to move billions of messages. When a destination stops accepting mail, the continuity spool holds the message and retries with backoff instead of bouncing it, and per-recipient delivery status tells you exactly what is queued and why. Queue depth, spool size, and node health are all alertable.
It is self-hosted, so residency is the host you run, not a region we sell. Encryption at rest is optional and off in the code default (fresh installs opt in). There is no SOC 2 or ISO 27001 attestation in this product — what assessors get is the tamper-evident audit log, per-message trace, configurable retention, and eDiscovery export. HIPAA readiness is the same: the controls exist; a BAA is not something this software issues.