(I sent this as an email to helm's support but since the founders are responding here I am duplicating this here)
Your technology page mentions that you provide an mx gateway (presumably for inbound email for home networks that don't usually have a static IP address). You also mention that emails forwarded to the helm server via your gateway are encrypted end-to-end and your gateway cannot read the contents of that email.
I am unable to understand how this happens. TLS is not end-to-end -- since the sending mail server will establish a TLS connection with your gateway it means that you necessarily have to decrypt the incoming email before forwarding it to the helm server.
Can you explain to me how I am wrong here?