Why it matters for email specifically
Email is the most complete record an organisation keeps: decisions, contracts, personnel matters, customer correspondence, and the password resets for every other system. When it is hosted abroad it is subject to foreign disclosure orders and foreign outages as well as domestic law. Zambia's Data Protection Act 2021 places obligations on organisations that process personal data, including knowing where it is processed and by whom; the Cyber Security Act 2025 adds obligations for operators of critical systems. Where your mail sits is now a question auditors ask.
Five things people mean by "sovereign"
These are different, and a platform can only give you some of them. Being precise avoids a false sense of security.
| Claim | What it means | ontechmail |
|---|---|---|
| Hosting location | Where the servers physically are | Hosted service: Ontech-operated infrastructure in Zambia. Self-hosted: wherever you put it. |
| Technical capability | Can the platform run entirely under your control? | Yes: deployable on-premise, including air-gapped, with a relay for blocked inbound ports. |
| Security feature | Controls that protect the data | TLS everywhere, 2FA, bcrypt hashing, DKIM signing, sandboxed rendering, audit log. |
| Compliance support | Evidence and controls that help you meet obligations | Audit trail of admin actions, data residency, exportability over IMAP, per-tenant isolation. |
| Legal compliance | Your organisation meets the law | Not something any product can claim for you. It depends on your policies, contracts, training and processes. |
How ontechmail supports sovereignty
Residency by default
The hosted service stores mail, attachments and DKIM keys on infrastructure Ontech operates in Lusaka. Traffic for users in Zambia stays on regional networks. See email hosting in Zambia.
Full control when required
The same platform runs self-hosted: your servers, your database, your object storage, your backups. Ontech never holds the data. For isolated networks it runs air-gapped.
Auditability
Every administrative and provisioning action, and every SMTP submission, is recorded with actor, target and timestamp. Per-mailbox and per-tenant usage is reported. This is the evidence an auditor or regulator asks for.
Isolation and exit
Each organisation is a separate tenant; mailboxes are never shared across tenants. Because access is over standard IMAP and the API, every message can be exported at any time with ordinary tools. Sovereignty without an exit is just a different lock-in.
What remains yours
- Deciding which data may leave the country, and documenting it.
- Contracts with processors, including Ontech, that set out roles and obligations.
- Access control: who administers the tenant, and enforcing 2FA.
- Retention and deletion policy, applied through mailbox and folder management.
- Staff training against phishing, which no hosting location prevents.
A note on claims
You will find hosting providers who say their product "makes you compliant". Treat that with caution. ontechmail is designed to support the technical and residency side of compliance with Zambian data protection and cyber security obligations; whether an organisation is compliant is a legal determination about that organisation, not about its software. If you need help mapping controls to your obligations, Ontech's team in Lusaka can walk through the platform's evidence with your compliance officer or auditor: info@ontech.co.zm.
Frequently asked questions
What is data sovereignty?
Data sovereignty is the principle that data is subject to the laws of the country where it is stored and processed. For email it means knowing which jurisdiction your mailboxes, backups and signing keys sit in, and who can be compelled to hand them over.
Does ontechmail make my organisation compliant with the Data Protection Act?
No product can guarantee legal compliance on its own. ontechmail provides capabilities that support compliance work: mail stored in Zambia or on your own premises, an audit log of administrative actions, two-factor authentication and encryption in transit. Your policies, contracts and processes complete the picture.
Who holds the encryption and signing keys?
On a self-hosted deployment, you do; the DKIM keys and stored mail never leave your infrastructure. On the hosted service, keys are generated per domain and held on Ontech infrastructure in Zambia.
Can I get my data out?
Yes. Mailboxes are accessible over IMAP, which any standard client or migration tool can use to copy every message out, and attachments and raw messages are stored in open formats.