Skip to content
Back to work
Email DLP gateway2026

SecurePlus

A multi-tenant data loss prevention platform: an outbound email gateway that inspects every message before it leaves, plus a scanner that finds sensitive data in cloud storage.

Role
Solo · design & build
Architecture
Modular monolith + stream workers
Period
2026
Category
Email DLP gateway

Context

Outbound email is one of the most common ways sensitive data leaves an organisation, and India's DPDP Act turns that leak into a compliance problem. I wanted to build the whole path myself: receive the mail, decide whether it is allowed to leave, and deliver it without losing a message if a worker dies halfway through.

Approach

Mail arrives over SMTP or a REST API and is written to a Redis Stream before the sender gets a 250 OK. Workers in a consumer group normalise the text, run a single-pass Aho-Corasick and RE2 inspection, apply the sender's policy, and either block the message with a notice or relay it with DKIM signing. A message is only acknowledged once its outcome is recorded, so a crash means a retry rather than a silent loss.

Architecture

secureplus-delivery // redis-stream
POLICY: PER_SENDERDKIM · STARTTLS

Live inspection pipeline

  • NFKC normalise
  • Aho-Corasick + RE2 scan
  • Policy verdict · relay

Stream metadata

  • group: delivery consumers
  • ack: after outcome recorded
  • recovery: XAUTOCLAIM
  • tenant: scoped per customer

At-least-once delivery

Key decisions

  1. 01

    Acknowledge only what is durable

    The SMTP 250 is returned only after the message is safely in the stream, and the stream entry is ACKed only after the delivery outcome is stored. Messages stuck with a crashed consumer are reclaimed with XAUTOCLAIM.

  2. 02

    One pass over the text, whatever the keyword count

    A hand-built Aho-Corasick automaton matches every keyword in a single scan, and Go's RE2 regex engine runs in linear time so a hostile pattern cannot cause ReDoS. NFKC normalisation runs first to catch Unicode look-alike tricks.

  3. 03

    Token rotation that survives two open tabs

    Refresh tokens rotate atomically in a Redis Lua script. A short grace window returns the already-issued successor to a concurrent request, so normal users are not flagged while genuine token reuse is still rejected.

Implementation

  • SMTP ingress (go-smtp) and REST ingestion into Redis Streams
  • Aho-Corasick + RE2 inspection over NFKC-normalised text
  • Per-sender content, recipient-domain, and attachment policies
  • DKIM signing, MX resolution, opportunistic STARTTLS, per-recipient retry
  • Cloud discovery scanner for S3, Google Drive, and Microsoft 365 with zip-bomb and size guards
  • AES-256-GCM credential encryption with HKDF-derived, versioned keys
  • CSRF double-submit cookies, Redis rate limiting, granular RBAC
  • Next.js console with incident audit, analytics, and EN / JA / ES localisation

Technologies

  • Go
  • Gin
  • Redis Streams
  • PostgreSQL
  • MongoDB
  • Next.js

Outcomes

  • 490+ Go test functions; 440+ run on every push in GitHub Actions
  • Deployed live at secureplus.ryugasystem.online

Hiring for backend or platform work?

I'm looking for backend engineering roles in distributed systems, high-throughput pipelines, or security infrastructure, remote or with relocation. I'm also happy to talk about any of the projects here.

I reply personally, usually within 24 hours.

Good to know

  • Currently a full-time SDE at MiniOrange in Pune.
  • Open to remote roles and to relocation.
  • Comfortable in both Java/Spring and Go codebases.