Ask Secure Message a question. Answers come from this site's docs only. I will cite a page. I will not invent a product claim.
This is encryption-portal vs encryption-portal. Proofpoint’s web reader runs in their cloud. Ours runs on the MX host you run. Recipients enter a one-time code. They do not create a Proofpoint account.
| Proofpoint | Secure Message | |
|---|---|---|
| What this page is | Encryption portal — their web reader | Encryption portal — ours on your host |
| Where the reader runs | Their cloud | On the MX host you run |
| Where keys live | Their service | On the host you run |
| Recipient | A Proofpoint account / their reader | Opens a link, enters a one-time code. No account. |
Proofpoint’s encryption web reader runs in their cloud. Secure Message runs the hold-and-portal reader on the MX host you operate — same job, different host, with keys on your infrastructure.
| Plan / note | Proofpoint | Secure Message (Hub GET 2026-10-01) |
|---|---|---|
| Public list | Public price not verified | Community free (1 domain · 1 administrator) |
| Professional | — | $690 / year |
| Enterprise | — | $1,490 / year |
The cloud SEG split is on the Mimecast page. This page is the encryption portal: their web reader in their cloud, or ours on the host you run. Keys stay on that host.
Recipients do not install a client or create a Proofpoint account. They open a link and enter a one-time code sent to the mailbox they already have.
Enterprise adds Autopilot, eDiscovery, and DLP. The inbound classifier is one Enterprise signal and stays off until you turn it on. Message content is not sent to a vendor model unless you opt into a hosted provider.
TLS-to-inbox vs hold-and-portal is on the Paubox page. The HIPAA framing is on the HIPAA email gateway page.
Check SPF, DKIM, and DMARC with the free email auth checker.