How can email2 be both secure and fully auditable?

How can email2 be both secure and fully auditable?

All secure messages stored on a Private Email Network (PEN) are encrypted using a Master Key. This Master Key is entered at the time of the PEN Certification either by the PEN Administrator or a trusted member of your organization. This Master Key is the basis for all data-at-rest encryption.

Depending on the security settings of your PEN, PEN Administrators may have access to managing message metadata (message subject, dates, recipients, etc.) but not the actual content of the secure messages - unless they have the Master Key.

So if administrators don't have the Master Key, who does?
This Master Key can be kept by whoever the PEN owner (your organization) deems acceptable. A PEN Manager may be designated, or a third party data security company may be able to hold the Master Key private from all company personnel until it is needed for an audit or legal investigation.

//Edited June 2009