Simplify email compliance with
classification labels

Standardize how your team handles sensitive emails with classification labels that automatically apply encryption and protection rules directly in Gmail.

Built on Digify — trusted by 800,000+ users
ISO 27001 Certified
AES-256 Encryption
SOC 2 Compliant
GDPR Compliant

Reduce manual effort and compliance gaps with auto-labelling

Automatically apply classification labels and log email activity to reduce human error, support compliance, and keep evidence ready for audits.

Automatically protect sensitive emails

Apply encryption and access controls based on classification labels, helping ensure sensitive emails receive the appropriate protection without employees configuring security settings each time.

Maintain consistent compliance

Automatically apply classification labels based on your company’s policies, helping employees follow labelling requirements consistently without having to remember each step.

Provide audit evidence with confidence

Automatically log email activity and keep records organised, so your team spends less time gathering evidence for compliance reviews and audits.

Reduce the risk of human error

Use centrally configured defaults to reduce missed labels and inconsistent classification, helping prevent manual oversights that could lead to compliance gaps.

Automatically apply protection based on classification in three steps

01

Set what each label enforces

Decide the encryption, recipient domains, watermarking, and usage rules that go with each classification.

02

Give each role the right labels

Choose which labels a role can reach, which one is selected by default, and whether classifying is mandatory.

03

Your team picks a label and sends

The label applies its own rules before the email leaves, and every open is recorded afterwards.

Support compliance with consistent classification and email protection

Requirements that usually run on training and goodwill start running on configuration instead.

ISO 27001

Classifying, labelling, and protecting information in transfer stop being three things you evidence separately. One action by the sender marks the information and applies the handling rules.

SOC 2

You answer "how do you restrict confidential information" with a configuration instead of a policy quote. Roles show who could classify what, and access records show where it went.

GDPR

Encryption for personal data stops being a sender decision, which is the gap between having an appropriate technical measure and being able to demonstrate one.

*PPAD supports the controls behind these requirements. Certification and compliance depend on your wider programme, not on any single tool.

Everything you need to classify and protect email in one place

What each label carries, and what your administrators control.

Custom labels and colours

External, Internal, and Confidential ready on day one. Add your own.

Dynamic watermarking

Stamp the label name and viewer identity on every page opened.

Print, copy, and expiry controls

Block printing and copying, add screenshot protection, set expiry.

Access records after delivery

See who opened a protected email, and cut off access at any time.

Allowed recipient domains

Emails to domains outside a label's list are blocked before sending. 

Labelling in subject and body

Show the label in the subject line, the email body, or both.

Locked protection settings

Sent emails keep the settings that applied at the time.

Centralized label management

Create, edit, delete, and reorder labels centrally, with consistent ordering across all label pickers.

Protect regulated information across the teams that handle it

Classification schemes differ by industry. The enforcement behind them works the same way.

Financial services

Client records, statements, and deal material leave the bank every day. Labels keep encryption and recipient limits on that traffic, with a record of who opened what.

Healthcare and life sciences

Patient and trial information stays protected after it reaches a referral partner or research collaborator, with access you can withdraw when a relationship ends.

Legal and professional services

Matter files and client deliverables carry the classification your engagement terms require, with watermarking that ties any leaked page back to a viewer.

HR and recruitment

Candidate records, identity documents, and employee files go to client companies and screening vendors daily. Labels keep that personal data encrypted, logged, and away from the wrong domains.

FAQ for Classification Labels

What is a classification label in PPAD?

A classification label marks the sensitivity of an outgoing email and carries the protection rules that go with it. When a sender picks a label, PPAD applies the encryption, recipient restrictions, watermarking, and display settings an administrator attached to that label.

How is this different from a label that only tags an email?

A tag records a judgement. A PPAD label enforces one. Each label carries settings for encryption, allowed recipient domains, watermarking, printing, expiry, and subject-line display, so the protection applies automatically instead of depending on the sender remembering to switch it on.

Can we use our own classification scheme?

Yes. The three default labels can be renamed, reconfigured, reordered, or removed, and you can create your own. Order is set once and applies everywhere the labels appear, including the picker your senders see.

Can we stop a sensitive email from reaching the wrong domain?

Yes. A label can carry a list of allowed recipient domains. The sender sees the permitted domains while composing, and a message addressed outside that list is blocked before it is sent, with an error naming the recipient causing the block. Domain restriction applies on labels that enforce encryption.

Can we require people to classify every email?

Yes. Label selection is set per role. With enforcement on, the send is blocked until the sender chooses a label. With enforcement off, a no classification option is available alongside the labels the role can use.

What happens to emails already sent if we change a label later?

Emails keep the classification and the protection settings that were in force when they were sent. Editing or deleting a label changes what future emails get, not what has already left.

Does using classification labels make us ISO 27001, SOC 2, or GDPR compliant?

No single tool does that, and anyone telling you otherwise is selling. Labels give you the classification, labelling, and transfer controls those frameworks ask for, applied automatically rather than left to individual judgement, plus records of what was applied and who accessed it. Certification still rests on your wider programme.

What can we actually show an auditor?

Your label configuration shows what each classification enforces. Your role configuration shows which people could apply which labels and whether classification was mandatory for them. PPAD's access records show who opened protected content, when, and what happened to it after delivery.

Make email compliance easier for your team

Use classification labels to apply your protection rules consistently and reduce manual security setup in Gmail.