SwiftLoop
// powering Morse MailA modern, security-focused webmail client built on open standards: a standalone implementation built on a Solid.js + strict TypeScript frontend, a strict-typed PHP core, and security-audited Rust cryptography. It delivers real end-to-end encryption that works with anyone, not just users on the same platform. Inspired by SnappyMail and RainLoop, engineered from the ground up.
Mail that talks to the rest of your suite without talking to anyone else: open standards, no proprietary lock-in, and encryption keys that never leave your control.
Built in the United Kingdom on a Controller → Service → Repository architecture, with a Solid.js + Panda CSS frontend and a PSR-4 PHP backend.
Open standards throughout, with a Pro feature tier, deployable on your infrastructure or run for you.
A fast inbox your whole team will like
A complete, modern mail client: read, write, search and schedule. The same inbox on a desktop, a tablet or a phone, with nothing to install on any of them.
Read & write, beautifully
- Redesigned compose and reading views with density modes, avatars and snippets
- Cross-platform threading that keeps conversations together
- WYSIWYG HTML editor or plain text, your choice on every message
- One inbox on desktop, tablet and phone: install it as an app, and drafts you write offline sync when you are back
Find anything in seconds
- Advanced search across folders with a precise query syntax
- Recent and saved searches, one click away
- Fast folder sync and caching, so results feel instant
- Keyboard-driven navigation and selection for power users
Every account in one place
- Multiple accounts and identities from a single, unified inbox
- OIDC / SSO sign-in (PKCE) and TOTP two-factor authentication
- Server-side encrypted sessions and an account provisioning API
- Session management, audit log and anti-abuse rate limiting
Calendar & contacts, built in
- Dual backends: local SQL and CalDAV / CardDAV with auto-discovery
- iCalendar invites (iTIP / iMIP), attendee responses and reminders
- Share a calendar with colleagues, read-only or read-write, each with its own colour
- A scheduling assistant that finds a time everyone is free, showing only busy blocks, never what they're doing
Security that's there when you want it
Strong protection runs quietly in the background, with no jargon and nothing to set up. When you want the reassurance, it is one tap away. When you don't, it stays out of your way.
Genuine, at a glance
- A simple colour-coded shield shows a message is authentic, no decoding required
- Tap it only if you want the full detail behind it
Signed and trusted, plainly
- See that a message is signed and trusted without reading anything technical
- The detail is one tap away, never forced in front of you
Encryption without the chore
- No keys to wrangle: protection can be handled automatically for you
- The controls are there to adjust only if you want them
Yours to switch on
- Signing and encryption are one optional toggle in the composer
- Ignore it entirely, or turn it on when a message really matters
Make it unmistakably yours
Ship the client under your own brand, tune every pixel, and extend it to fit how your organisation works.
Your brand, not oursWhitelabel
- Set your own logo, favicon, accent colour and background from the admin panel
- Branding overrides always win the cascade and survive theme switches
- Branded login screen, app title and footer
- No Morse Labs branding anywhere your users see
Themes for every taste
- Five bundled themes: Default, Dark, Nord, Ocean and Rose
- Light, dark or system colour scheme, set per user
- A visual theme picker with live colour swatches
- Density and layout options to suit any workflow
Drop in a custom theme
- Every colour, border, font and radius is a CSS variable you control
- Copy the example theme, drop it into themes/, and it appears in the picker
- Background images and per-theme assets supported
- No rebuild required to design a complete, bespoke look
Build it your way
- REST v2 API for automation and integration with your stack
- Account provisioning API to onboard users and domains at scale
- Open standards throughout: IMAP, CalDAV / CardDAV, JMAP next
- Self-host the container image with Docker or Kubernetes, or run fully managed: your data, your infrastructure
Security built in, not bolted on
The engineering underneath the experience: audited cryptography on a strictly-typed, test-covered platform.
CryptographyCore strength
- rPGP backend built on security-audited Rust modules for server-side OpenPGP
- OpenPGP.js v6 for browser-side PGP, keeping private keys on the device
- S/MIME via PKI.js for certificate-based encryption and signing
- User-selectable browser-vs-server crypto provider with automatic fallback
- Autocrypt Level 1 opportunistic encryption, with key gossip and setup messages
- Key & certificate trust management with deny-list, plus SPF / DKIM / DMARC trust badges
Architecture & platform
- Solid.js fine-grained signals with strict TypeScript throughout; Vite build
- Panda CSS + Ark UI with design-token theming and accessible components
- REST v2 API, DI container, a full automated test suite, full lint and static analysis
- File / Redis / PDO storage backends; Docker multi-stage build; Controller → Service → Repository
- Open protocols cross domains: a security gateway can only pass what it can inspect, so mail on open standards can traverse one where a proprietary format never will. We test for it
Classification, built in
Apply and enforce protective markings at the message level, with standards-based headers that travel with the mail across systems.
Markings render in compose and reading views and are written as headers, so policy travels with the message.
AI that can't quietly read your mail
Every mail client is bolting on an assistant, so the interesting question isn't whether it drafts your replies. It's who else sees the message. Ours is off until you switch it on, and it can run entirely in your own environment.
The tedious parts, written for you
- Drafted replies you always read and approve before anything sends
- Summaries of a long thread, so you can pick it up without reading all of it
- Triage: what actually needs you, and what can wait
- Rewrite and tone, action items pulled into your calendar, and translation
Your model, or nobody'sYour choice
- Run it in your own environment, so no message ever leaves your infrastructure
- Or bring your own provider account, with no-training modes enforced
- Or none at all: that's what ships by default
- The choice is the admin's, and it's a setting, not a rebuild
Off until you say otherwise
- Off by default, for the whole instance and for every user, with no silent switch-on at upgrade
- An admin kill switch: no AI interface, no routes, no credentials loaded
- Each capability toggles independently: summaries on doesn't mean drafting on
- Nothing is sent to a model without you confirming it first
Classified mail simply can't goThe guarantee
- Mail at or above a classification you choose is never sent to an outside provider
- Restrict it to a local model, or block AI on it entirely
- Every request goes through a server-side gateway, so the rules hold even if a client misbehaves
- Anything AI wrote is marked as such, and every request lands in the audit log
Where it's going
A clear trajectory toward government- and defence-grade secure mail.
Now
- A complete, modern mail client: read, write, search, thread and schedule
- Shared team inboxes: work a mailbox together, with assignment, status, internal comments and send-as
- Classification labels live: UK GSC, PSPF, NATO and SIO-Label headers
- Shared calendars: CalDAV sharing and ACLs, with a share dialog, per-user colours and read / read-write roles
- Scheduling assistant: find a time that works before you send the invite, showing busy blocks only, never what anyone is actually doing
- Metrics & observability live across the platform
- End-to-end encryption interoperable beyond the platform
- Works on every device: responsive throughout, installable as an app, usable offline
- Open standards throughout, with Pro feature gating
In progress
- Metrics & observability enhancements: StatsD export, frontend MetricsService, DNT / GPC and alert webhooks
- QR provisioning tokens for mobile / DeltaChat clients
- Org-wide availability: see free/busy for colleagues who haven't shared a calendar, and interoperate with external calendars and tools
Secure, private, and integrated. All three.
or fully managed via Mailjam.
Not even we can read your data.