Morse Labs ← All products
Morse Mail · Secure Webmail

SwiftLoop

// powering Morse Mail

A modern, security-focused webmail client built on open standards: a standalone implementation built on a Solid.js + strict TypeScript frontend, a strict-typed PHP core, and security-audited Rust cryptography. It delivers real end-to-end encryption that works with anyone, not just users on the same platform. Inspired by SnappyMail and RainLoop, engineered from the ground up.

OpenIMAP · CalDAV · JMAP
Solid.jsTypeScript UI, PHP core
E2EPGP · S/MIME · Autocrypt
AnyDesktop, tablet, phone
YoursSelf-host or managed
SSOYour identity provider
RustAudited crypto core

Mail that talks to the rest of your suite without talking to anyone else: open standards, no proprietary lock-in, and encryption keys that never leave your control.

Built in the United Kingdom on a Controller → Service → Repository architecture, with a Solid.js + Panda CSS frontend and a PSR-4 PHP backend.

Open standards throughout, with a Pro feature tier, deployable on your infrastructure or run for you.

A fast inbox your whole team will like

A complete, modern mail client: read, write, search and schedule. The same inbox on a desktop, a tablet or a phone, with nothing to install on any of them.

The daily experience
01

Read & write, beautifully

  • Redesigned compose and reading views with density modes, avatars and snippets
  • Cross-platform threading that keeps conversations together
  • WYSIWYG HTML editor or plain text, your choice on every message
  • One inbox on desktop, tablet and phone: install it as an app, and drafts you write offline sync when you are back
02

Find anything in seconds

  • Advanced search across folders with a precise query syntax
  • Recent and saved searches, one click away
  • Fast folder sync and caching, so results feel instant
  • Keyboard-driven navigation and selection for power users
03

Every account in one place

  • Multiple accounts and identities from a single, unified inbox
  • OIDC / SSO sign-in (PKCE) and TOTP two-factor authentication
  • Server-side encrypted sessions and an account provisioning API
  • Session management, audit log and anti-abuse rate limiting
04

Calendar & contacts, built in

  • Dual backends: local SQL and CalDAV / CardDAV with auto-discovery
  • iCalendar invites (iTIP / iMIP), attendee responses and reminders
  • Share a calendar with colleagues, read-only or read-write, each with its own colour
  • A scheduling assistant that finds a time everyone is free, showing only busy blocks, never what they're doing

Security that's there when you want it

Strong protection runs quietly in the background, with no jargon and nothing to set up. When you want the reassurance, it is one tap away. When you don't, it stays out of your way.

Effortless by default
01

Genuine, at a glance

  • A simple colour-coded shield shows a message is authentic, no decoding required
  • Tap it only if you want the full detail behind it
02

Signed and trusted, plainly

  • See that a message is signed and trusted without reading anything technical
  • The detail is one tap away, never forced in front of you
03

Encryption without the chore

  • No keys to wrangle: protection can be handled automatically for you
  • The controls are there to adjust only if you want them
04

Yours to switch on

  • Signing and encryption are one optional toggle in the composer
  • Ignore it entirely, or turn it on when a message really matters

Make it unmistakably yours

Ship the client under your own brand, tune every pixel, and extend it to fit how your organisation works.

Whitelabel & extend
01

Your brand, not oursWhitelabel

  • Set your own logo, favicon, accent colour and background from the admin panel
  • Branding overrides always win the cascade and survive theme switches
  • Branded login screen, app title and footer
  • No Morse Labs branding anywhere your users see
02

Themes for every taste

  • Five bundled themes: Default, Dark, Nord, Ocean and Rose
  • Light, dark or system colour scheme, set per user
  • A visual theme picker with live colour swatches
  • Density and layout options to suit any workflow
03

Drop in a custom theme

  • Every colour, border, font and radius is a CSS variable you control
  • Copy the example theme, drop it into themes/, and it appears in the picker
  • Background images and per-theme assets supported
  • No rebuild required to design a complete, bespoke look
04

Build it your way

  • REST v2 API for automation and integration with your stack
  • Account provisioning API to onboard users and domains at scale
  • Open standards throughout: IMAP, CalDAV / CardDAV, JMAP next
  • Self-host the container image with Docker or Kubernetes, or run fully managed: your data, your infrastructure

Security built in, not bolted on

The engineering underneath the experience: audited cryptography on a strictly-typed, test-covered platform.

Engineered for trust
01

CryptographyCore strength

  • rPGP backend built on security-audited Rust modules for server-side OpenPGP
  • OpenPGP.js v6 for browser-side PGP, keeping private keys on the device
  • S/MIME via PKI.js for certificate-based encryption and signing
  • User-selectable browser-vs-server crypto provider with automatic fallback
  • Autocrypt Level 1 opportunistic encryption, with key gossip and setup messages
  • Key & certificate trust management with deny-list, plus SPF / DKIM / DMARC trust badges
02

Architecture & platform

  • Solid.js fine-grained signals with strict TypeScript throughout; Vite build
  • Panda CSS + Ark UI with design-token theming and accessible components
  • REST v2 API, DI container, a full automated test suite, full lint and static analysis
  • File / Redis / PDO storage backends; Docker multi-stage build; Controller → Service → Repository
  • Open protocols cross domains: a security gateway can only pass what it can inspect, so mail on open standards can traverse one where a proprietary format never will. We test for it

Classification, built in

Apply and enforce protective markings at the message level, with standards-based headers that travel with the mail across systems.

Government & defence · Implemented
UK GSC Government Security Classifications OFFICIAL, SECRET and TOP SECRET markings for UK public-sector correspondence.
PSPF Protective Security Policy Framework Australian government protective markings applied and preserved on every message.
NATO Allied marking scheme NATO classification markings for secure correspondence between allied organisations.
SIO-Label Standards-based headers Machine-readable SIO-Label headers carried on each message for downstream enforcement.

Markings render in compose and reading views and are written as headers, so policy travels with the message.

AI that can't quietly read your mail

Every mail client is bolting on an assistant, so the interesting question isn't whether it drafts your replies. It's who else sees the message. Ours is off until you switch it on, and it can run entirely in your own environment.

Designed · Not yet shipped
01

The tedious parts, written for you

  • Drafted replies you always read and approve before anything sends
  • Summaries of a long thread, so you can pick it up without reading all of it
  • Triage: what actually needs you, and what can wait
  • Rewrite and tone, action items pulled into your calendar, and translation
02

Your model, or nobody'sYour choice

  • Run it in your own environment, so no message ever leaves your infrastructure
  • Or bring your own provider account, with no-training modes enforced
  • Or none at all: that's what ships by default
  • The choice is the admin's, and it's a setting, not a rebuild
03

Off until you say otherwise

  • Off by default, for the whole instance and for every user, with no silent switch-on at upgrade
  • An admin kill switch: no AI interface, no routes, no credentials loaded
  • Each capability toggles independently: summaries on doesn't mean drafting on
  • Nothing is sent to a model without you confirming it first
04

Classified mail simply can't goThe guarantee

  • Mail at or above a classification you choose is never sent to an outside provider
  • Restrict it to a local model, or block AI on it entirely
  • Every request goes through a server-side gateway, so the rules hold even if a client misbehaves
  • Anything AI wrote is marked as such, and every request lands in the audit log

Where it's going

A clear trajectory toward government- and defence-grade secure mail.

Roadmap

Now

  • A complete, modern mail client: read, write, search, thread and schedule
  • Shared team inboxes: work a mailbox together, with assignment, status, internal comments and send-as
  • Classification labels live: UK GSC, PSPF, NATO and SIO-Label headers
  • Shared calendars: CalDAV sharing and ACLs, with a share dialog, per-user colours and read / read-write roles
  • Scheduling assistant: find a time that works before you send the invite, showing busy blocks only, never what anyone is actually doing
  • Metrics & observability live across the platform
  • End-to-end encryption interoperable beyond the platform
  • Works on every device: responsive throughout, installable as an app, usable offline
  • Open standards throughout, with Pro feature gating

In progress

  • Metrics & observability enhancements: StatsD export, frontend MetricsService, DNT / GPC and alert webhooks
  • QR provisioning tokens for mobile / DeltaChat clients
  • Org-wide availability: see free/busy for colleagues who haven't shared a calendar, and interoperate with external calendars and tools

Secure, private, and integrated. All three.

Request a demo Deployed on-premises, in your cloud,
or fully managed via Mailjam.
Not even we can read your data.