September 11, 2026, Shenzhen China — Today, ZoTrus / ZTmail today announced that ZTmail App will enter global public beta. The first public-beta release includes only Free Edition and will be available to all global users looking for a simple way to adopt S/MIME. Paid editions, which are designed for higher levels of identity validation and broader trust requirements, remain in internal testing and are not part of this public-beta release.
The most important point about the launch is not that the first edition is free. It is what ZTmail means by “free.” The Free Edition is not designed as a feature-limited version intended merely to demonstrate the product. Instead, the public beta is intended to test a broader proposition: whether complete S/MIME cryptographic capabilities can become part of an ordinary email application, with the application automating the operational work that has historically required specialized PKI knowledge.
In conventional S/MIME deployments, certificate enrollment, identity validation, certificate installation, key management, email-client configuration, signing and encryption, and certificate renewal often sit across separate responsibilities involving the CA, IT administrators, mail systems, and end users. The underlying technology is mature, but the workflow connecting these components has remained fragmented. The result is an application gap between what the certificate infrastructure can provide and what an ordinary email user can actually use.
ZTmail App approaches that gap by bringing S/MIME certificate lifecycle automation and email cryptography into one application workflow. Users do not need to treat certificate enrollment, certificate configuration, and encrypted email as three separate projects. The application connects the certificate service with the email client and automates the relevant certificate-management workflow. On the email-communication layer, the Free Edition provides the full core S/MIME capabilities: encryption, decryption, digital signing, signature verification, certificate management, and trusted-identity UI display. The result is a complete cryptographic communication workflow rather than a collection of limited free features.
This direction also reflects the evolution of the S/MIME standards ecosystem. RFC 8823 defines ACME extensions for end-user S/MIME certificates and explicitly considers ACME-aware mail user agents that can automate certificate management. The CA/Browser Forum's S/MIME Baseline Requirements subsequently incorporated ACME-based mailbox-control validation into the requirements framework, moving S/MIME certificate automation from a technical possibility toward deployable infrastructure. And the draft Chinese commercial cryptography standard “Automated Certificate Management Protocol,” led by ZoTrus Technology, has entered the national public consultation stage. The public beta supports automated enrollment of both RSA and SM2 algorithm S/MIME certificates, allowing users to choose either algorithm or enroll certificates for both according to their needs. The automated enrollment of SM2 algorithm S/MIME certificates represents a practical implementation of the draft standard in the S/MIME email communication context.
ZTmail is not positioning Free Edition as a reduction in cryptographic capability. Instead, it starts with a lower identity-validation threshold so that more users can access complete email-encryption automation. The Free Edition uses T1/MV (Mailbox Validated) with ZTmail Trust. Its core validation question is whether the user controls the corresponding mailbox address. That is different from organizational or stronger identity validation, and ZTmail therefore does not describe mailbox control as organizational identity authentication or blur the boundaries between trust levels.
This distinction keeps cryptographic capability and identity trust level as two related but separate dimensions. The Free Edition can perform S/MIME encryption, decryption, signing, and verification, while it does not claim the higher identity-validation levels or broader Global Trust intended for future paid editions. Those paid editions are being designed for users that require stronger identity validation, higher levels of trusted identity, or broader external communication trust, not simply unlock basic cryptographic functions that were intentionally removed from the Free Edition.
From a product-strategy perspective, that distinction matters. S/MIME can move from a specialist technology toward an ordinary Internet communication capability only if users can first access the complete cryptographic workflow. When users require stronger organizational or personal identity assurance, or broader global trust, those requirements can then map to higher-value paid services rather than being used as a reason to make the underlying encryption experience incomplete.
The ZTmail App launch continues the company's broader view of the S/MIME scaling problem. S/MIME has not become a default enterprise capability primarily because of immature cryptography. The harder problems have been deployment models, certificate lifecycle operations, and usability. Organizations need a way to connect certificates, keys, email clients, security systems, and organizational trust infrastructure at scale. Individuals and SMBs need something further: the complexity has to disappear from the user's workflow.
That is why ZTmail has two complementary product paths. ZTmail Gateway addresses organizational deployment through an infrastructure model for S/MIME automation across large numbers of mailboxes. ZTmail App addresses the individual and SMB side at the email-client level. The deployment boundaries are different, but the objective is the same: email encryption should not depend on whether a user understands PKI, nor should every organization have to build a complex manual operating process to use it.
If S/MIME becomes scalable only inside enterprises while large numbers of individual and SMB mailboxes remain unable to use complete encryption capabilities, email encryption will still struggle to achieve broad Internet coverage. ZTmail therefore views individuals and SMBs not as an optional market outside the enterprise solution, but as an essential part of making encrypted email communication broadly available across the Internet. Therefore, ZTmail App must be launched first, followed by the S/MIME Automation Gateway.
The history of HTTPS shows that digital certificate technology became broadly usable not because users learned more PKI, but because enrollment, validation, deployment, and renewal were progressively moved into automated infrastructure. S/MIME faces a similar challenge. The standards exist, the cryptography is mature, and what remains missing is an application layer that connects CAs, certificate lifecycle management, email clients, and user experience.
The ZTmail App Free Edition public beta is intended to test exactly that proposition. An ordinary user should not need to learn certificate management to send an encrypted email, and a free service should not have to mean a demonstration product with its core cryptographic capabilities removed. The Free Edition provides free S/MIME certificates and the full set of core S/MIME cryptographic capabilities, with a commitment to remain free permanently. Higher levels of identity validation and broader trust scopes will be reserved for future paid editions, keeping the free entry point aligned with ZTmail’s long-term goal of making S/MIME automation broadly accessible.
Today’s launch is therefore more than the public beta of another email client. It is a public test of a different application model for email: complete cryptographic capability can become part of an ordinary email application, while automation lowers the operational barrier for both users and organizations. S/MIME does not need to be reinvented. It needs to be automated.
ZTmail App, S/MIME Encryption for Everybody, Automated. AI, Your Key.
Welcome ZTmail to the world today, welcome to the world of ZTmail today.