My understanding is that you can use split mode to only have the load balancer decrypt the server name section, and forward the actual session and key exchange down to the backend without doing double layer encryption.
Most people ditch GAFAM because they want to own their digital identity and not just trade one gatekeeper for another, even if it's "hassle free" to start off with.
And with the setup of Happymail renting out individual email addresses under the same domain to different users, it makes it impossible for them to leave the platform. Have you considered letting people own their domains?
I work for a government agency (not in the US). Working in private would have certainly made me more money but I really love the ample time off (4 extra weeks compared to a similar private-sector role) that we get which allows me to focus more on family and personal persuits. Additionally deadlines are pretty much non-existent as projects can drag on for years.
I realise that this might not be a good environment for ambitious people, however it pays the bills and I get to do whatever I want with my time.
Going to leave this here for shady practices. A pull request was declined by the CEO since they were planning to build an OIDC feature into the enterprise plan.
The reality for a product at this scale is that nobody is going to spend the time or money to copy it.