Is Tifamail Secure? Encryption, Two-Step Sign-In and Backups Explained
What "encrypted at rest" actually means for your company mail, how two-step sign-in works, and the security habits every Kenyan business should pair with it.
Email holds a business's most sensitive information: contracts, payroll, client data, bank details. Under Kenya's Data Protection Act, businesses are also responsible for how that personal data is protected. So before moving company mail anywhere, it is fair to ask: how secure is it? Here is how Tifamail approaches security, explained without the jargon.
Encryption at Rest, With a Key Per Company
Tifamail encrypts stored data with AES-256-GCM, the same standard used by banks and governments. Crucially, it is not just message bodies: names, addresses, subjects, previews, attachments, AI documents, prompts and settings are all encrypted. Each company's data is encrypted under its own derived key, so one company's data cannot be decrypted with another's.
A common question is how search works if everything is encrypted. Tifamail builds keyed search tokens for each mailbox rather than storing readable words, so you get fast, even typo-tolerant search — "davd" still finds "david" — without the server keeping a plain-text index of your mail.
Two-Step Sign-In
Passwords are stored using Argon2id, a modern password-hashing algorithm designed to resist cracking. On top of that, users can turn on two-step sign-in using an authenticator app such as Google Authenticator, or SMS codes for Kenyan phone numbers. Admins can require two-step sign-in company-wide, which is one of the most effective protections against stolen passwords.
Safe Reading and Delivery Protection
Incoming messages are displayed in a sandboxed frame that blocks scripts, which neutralises a whole class of malicious-email tricks. Outgoing mail is authenticated with SPF, DKIM and DMARC, which makes it much harder for fraudsters to send convincing fake email "from" your domain. Other protections include request-forgery tokens on every action, rate limiting, strict security headers and an audit log of sign-ins, settings changes and admin actions.
Backups
Tifamail takes automatic daily encrypted backups, keeps them for seven days and stores them off-site. If something goes wrong on a given day, data can be restored from a recent copy.
Your Side of the Bargain
No platform can protect a business that shares passwords. Pair Tifamail's controls with simple habits: require two-step sign-in for everyone, remove staff accounts the day someone leaves, never confirm bank-detail changes by email alone, and train staff to recognise phishing. If your business processes personal data at scale, check whether you need to register with the ODPC as a data controller.
Staying Signed In Safely
Tifamail keeps users signed in for up to 30 days on a trusted device, using a secure "stay signed in" token stored in hashed form. If the server-side session is lost, the token restores it, so staff are not logged out unexpectedly. Signing out, changing a password or an admin resetting a password revokes those tokens, which immediately cuts off any device that should no longer have access — important when a phone is lost or an employee leaves.
Security Checklist for Admins
- Require two-step sign-in for every user.
- Remove leavers immediately and reset shared mailbox passwords.
- Review the audit log for unusual sign-ins or settings changes.
- Use separate API keys for each integration and revoke unused ones.
- Set AI limits per user so a compromised account cannot drain the wallet.
- Verify SPF, DKIM and DMARC so fraudsters cannot easily spoof your domain.
- Train staff to report suspicious emails, especially requests to change bank details.
How Tifamail Compares to Typical Shared Hosting Email
| Protection | Tifamail | Typical shared-hosting mailbox |
|---|---|---|
| Encryption of stored mail | AES-256-GCM with per-company keys | Often not encrypted at rest |
| Two-step sign-in | Authenticator app or SMS (Kenya), enforceable company-wide | Often unavailable on webmail |
| Sandboxed message display | Yes | Varies |
| Daily encrypted backups | Yes, kept for 7 days off-site | Varies by host and plan |
| Audit log | Yes | Rarely |
Tifamail Security -- FAQ
Is my email encrypted on Tifamail?
Yes. Stored messages, attachments, documents and settings are encrypted with AES-256-GCM under a key unique to your company.
Does Tifamail support two-factor authentication?
Yes. Users can use an authenticator app or SMS codes for Kenyan numbers, and admins can make two-step sign-in mandatory for the whole company.
How long are Tifamail backups kept?
Daily encrypted backups are kept for seven days and stored off-site.
What happens to my data if I stop using Tifamail?
Speak to Tifamail about exporting your mail before closing your workspace. As with any provider, plan your exit and download what you need before cancelling.
Can Tifamail staff read my email?
Mail is encrypted at rest under company-specific keys, and access is designed to be restricted. As with any provider, review the terms and privacy policy for details of support access.
Final Thoughts
Tifamail's security model is unusually thorough for an SME email product: encryption of nearly everything with per-company keys, strong password hashing, mandatory two-step sign-in options, sandboxed reading, authenticated sending and daily backups. Combined with sensible staff habits, it gives Kenyan businesses bank-style protection for their mail at a small-business price. Learn more at tifamail.com.
