Internal email that goes out
from your mailbox, not ours.

We are never the sender. Your own Gmail or Microsoft 365 account delivers it — which changes the deliverability, the price, and what anyone is able to find out about your staff.

01

This is the whole argument,
and it fits in one screenshot.

A campaign built in SlipperySign, delivered by the sender's own mailbox, as the recipient sees it.

An inbox showing an internal email from Anna Lindqvist to all@company.com: a branded Q3 all-hands campaign with a header, three summary sections and her signature, marked as sent from Anna's own mailbox with replies going to Anna.
01 / SENDER Anna's name. Anna's address.

No relay address, and no “via” line beside her name. It is her mailbox, so it is simply her email.

02 / REPLIES Answers go back to Anna.

Into her inbox, in the same thread. If IT would rather they landed in a shared mailbox, a Reply-To address sends them there instead.

03 / DELIVERY Your domain's reputation, not a shared IP.

It travels the same path as every other internal mail, so it arrives where internal mail arrives.

04 / RECORD It's in her Sent folder.

Because she sent it. There is no separate system of record to reconcile at audit time.

02

Six things a marketing tool
structurally cannot offer you.

Not a feature list — every other tool has an editor and an approval step. These six follow from one decision: the mail leaves your mailbox instead of ours. A vendor who relays your mail cannot copy them without rebuilding their product.

Sending

It leaves your mailbox, not our relay

Gmail API and Microsoft Graph, from the user's own account, under a revocable gmail.send or Mail.Send grant. Your domain, your SPF and DKIM, your reputation — and a copy in her Sent folder.

Recipients

Your staff list never leaves your tenant

No upload, no import, no directory sync. Campaigns are addressed to the distribution lists and group aliases you already run, and your mail provider expands them at send time. We never see who is on them.

Measurement

Per-person tracking is impossible, not switched off

Opens are one counter per campaign, clicks one counter per link, plus a daily total. No tracking table has a recipient column, so the report a manager asks for cannot be produced — by us either.

Custody

The send token never reaches our servers

It is held in the browser for the duration of the send, then discarded. There is no password field and no password store anywhere in the product — Google or Microsoft authenticates and hands us a verified address.

Residency

EU or US, per customer, not per deployment

Set against your company record rather than the region we happen to run in. EU storage is pinned to EU jurisdiction at the storage layer, so the bytes stay in the EU rather than merely being described that way.

Cost

We do not charge by volume

Not per contact, not per send, not per open. Send to everyone, twice a week, at no extra cost. One flat monthly rate, and the only number that decides it is how many people work at your company.

03

One address. A thousand people.

Every other tool in this category begins by asking you to hand over your people, one row at a time. This one begins from the list you already have. You send to all@company.com — one address — and your mail provider opens it at delivery and fans it out to everyone your directory says belongs there.

Membership stays where it should be: in your directory, maintained by the people whose actual job that is. We only ever see the fruit. We never count the seeds.

Nothing to uploadThe list already exists, and it stays where it is.
Nothing to syncSomeone joins or leaves, and the next campaign is simply correct.
Nothing to leakWe hold one address, not a thousand.
Nothing to meterPricing cannot be per contact when there are no contacts.
04

What we cannot see —
and, openly, what we do store.

The number is a property of the database schema, not a promise. The second half is the honest half: this is not a zero-data tool, and selling it as one would not survive your first security review.

0

recipients we can name Across every campaign, every open, every click, for every customer.

No recipient column exists

Opens are one counter per campaign. Clicks are one counter per link. There is a per-day rollup, and that is all. There is no table a per-person report could be built from.

Your staff directory is never uploaded

Campaigns are addressed to the distribution lists and group aliases you already have. Your mail provider expands them at send time — we never see the membership.

No password is ever held

There is no password field and no password store. Google or Microsoft authenticates the person and hands us a verified email address.

Don't take our word for it — here is the schema

A promise about a database is worth nothing unless you can check it. So on the left is every place in the system where a person's address is stored, by column. On the right are the three tracking tables printed in full, every column, nothing omitted.

Every column that holds an address

  • campaigns.user_idWhoever created the campaign.
  • campaigns.from_email · from_nameWho it is sent as.
  • campaigns.reply_to · bccOnly if you fill them in.
  • grants.email · granted_byColleagues you shared it with, and who shared it.
  • email_groups.emailThe distribution list addresses you save for reuse.
  • companies.adminsYour own administrators.
  • audit_log.actorWho performed an administrative action.

The three tracking tables, in full

campaign_stats
campaign_idopenslast_open recipient — does not exist
campaign_clicks
campaign_idurl_hashurlclickslast_click recipient — does not exist
daily_opens
campaign_iddayopens recipient — does not exist

That is all three tables. A report naming who opened your email would have to join against a column in one of them, and there is no such column to join against — so the report cannot be written, by us or by anyone who compels us.

05

And it is, of course,
a real tool as well.

None of this is a reason to switch — every serious tool in this category has it. It is a reason not to have to compromise when you do switch.

Drag-and-drop components Text, image, button, section, poll. Dropped onto the canvas, not typed into a box.
Contents list maintains itself Mark a section and the list reorders. Long updates stop being a scroll.
Locked regions Freeze the masthead, the footer, the legal line. Everyone edits around them.
MJML underneath What you assemble is what Outlook renders, tables and all.
Approval blocks the send Locked until the named reviewer signs off. Any edit afterwards voids it.
Roles and a check-out lock Share as viewer or editor, so nobody overwrites anyone mid-sentence.
Central brand management Palettes and heading styles per company. The standard brand can be duplicated, never edited.
06

One rate, by company size.
Then send as much as you like.

Count the people who work there. That is the whole pricing model — there is no second axis, because there is nothing on our side that gets more expensive when you send more.

Up to 100 people $9/ month A team, a startup, one office.
Up to 1,000 people $29/ month Big enough that someone owns internal comms.
Up to 10,000 people $99/ month Big enough that an announcement needs sign-off first.
More than 10,000 $299/ month Enterprise, with data residency set per company record.
No limit from us Unlimited campaigns, unlimited recipients, unlimited opens. Your own provider's sending limits still apply, because your own provider is doing the sending.
Every feature in every tier Approval, locked regions, roles, brand management and residency are not held back for a higher plan. The tier only reflects how many people work there.
No contact list to count There is nothing to reconcile at renewal, because we never held a list of your staff in the first place.
07

The rest of what security
asks before they say yes.

Sending, recipients, measurement, token custody and residency are above. These are the four that are left.

Identity
Federated to Google Workspace or Microsoft 365. No credential is seen or stored, and a domain must be registered by us before anyone on it can sign in — an unknown company domain cannot self-serve its way into the product.
Retention
Per-customer policy for campaign content and tracking detail, applied on a nightly schedule. Zero means keep, and any other number means delete after that many days.
Audit
Sent campaigns are immutable. Administrative actions are logged, including any occasion a platform administrator acts on behalf of one of your users.
Availability
Served from a global network, so the editor opens at the same speed in Zurich, São Paulo and Singapore — and stays open when one region has a bad day.

Built on independently certified infrastructure

SlipperySign runs on enterprise cloud infrastructure that is audited and certified against the standards your security team will ask about — so the foundation under your internal communications is held to the same bar as the rest of your stack.

SOC 2 Type II ISO 27001:2022 ISO 27701:2019 ISO 27018:2019 PCI DSS

To be precise, because it matters in a review: these certifications are held by the infrastructure provider operating the platform we run on, not by SlipperySign itself. We are telling you what the foundation is certified to — we are not claiming the certificates as our own.

Send the next one from your own address.

Sign in with the Google or Microsoft account you already have. Nothing to install, and no contact list to upload.

Open the app

SlipperySign Mail — first of a family. Tools for learning experiences follow.