Practice
Compliant encrypted email for a single regulated practice
195 / mo base + £15/seat/mo
Annual base £1,872 (£156/mo equiv, save 20%) · seats remain pass-through.
£395 one-time — covers DNS audit, migration runbook, scheduled out-of-hours cutover for up to 15 mailboxes, 14-day dual-delivery monitoring, MFA rollout session, and an offboarding kit.
Compliant, encrypted email infrastructure for a single regulated UK practice on one domain.
Best for: Single-site UK regulated practice, 5-15 staff, one apex domain.
- EU-sovereign
- Up to 15 mailboxes
- DMARC p=reject within 30d
Included
- DNS config of 1 apex domain (SPF hardfail -all, DKIM 2048-bit annual rotation, DMARC p=quarantine → p=reject within 30 days, MTA-STS, TLS-RPT)
- Up to 15 EU-sovereign real mailboxes on Proton Mail Business (full IMAP/SMTP, calendar, contacts, 30-day deleted-item recovery)
- Migration from incumbent (M365 / Workspace / GoDaddy / cPanel) including content, calendars, contacts, distribution lists
- Monthly deliverability report (DMARC aggregate parsed, top sending sources, spam-folder rate)
- Quarterly compliance evidence pack tailored to one regulator (DCB1596 for healthcare / SRA's encrypted-transmission requirement for law / ICAEW client-data guidance for accountancy)
- Cloudflare Email Routing for unlimited additional aliases
- MFA enforcement + password policy baseline
- Encrypted attachment delivery flow
- Same-business-day SLA on email incidents
- Annual DKIM key rotation + MTA-STS refresh + TLS verification + DNSSEC verification
- Offboarding-on-cancellation kit (mbox/EML exports, DNS zone file, DMARC archive, evidence pack)
Explicitly excluded
- DMARC on multiple sending subdomains (Sovereign-bundle uplift)
- Dedicated transactional outbound subdomain or warm-up campaign
- BIMI / VMC issuance
- Fractional CTO time / architecture review
- Clinical-software SMTP integration
- Phishing simulation programme
- Mailbox content recovery beyond 30 days
- Additional domains
Upgrade trigger: Seats cross 15 OR a 2nd domain enters scope OR practice starts sending automated transactional email OR DMARC needs reconciliation across shadow senders → Sovereign-bundle uplift (+£100/mo). Any of those + multi-regulator burden + >30 seats → Enterprise.