Status: The service is in development. This page describes the architecture we are building. Audits and penetration tests will take place before launch and will be published here.
Principles
- Memory-safe languages for our own components (Rust), no home-made cryptography.
- Least privilege and four-eyes principle for every access to production systems.
- No content in logs. Logs contain neither message bodies nor subject lines.
- Open code for everything that runs on your devices or handles your keys.
Encryption
Transport
TLS 1.3 preferred, TLS 1.2 as the minimum. When sending to other servers we use DANE and MTA-STS where the other side supports them.
Compatible (default)
Every account has its own key pair. Incoming mail is encrypted with your public key, even while you are not logged in. The private key is protected by your password and is only decrypted in memory during your session.
What we could technically do: while you are logged in, the server processes plain text. An attacker with full access to the running server could read along at that moment. Access controls, signed deployments and audit logs are how we counter that.
Sealed (zero access)
Folders in Sealed mode are encrypted with OpenPGP (RFC 9580). The private key never leaves your device unencrypted. We cannot read this content and therefore cannot hand it over.
Sign-in
- Passkeys (WebAuthn) and one-time codes (TOTP) as a second factor. No SMS.
- Separate app passwords for mail apps, each revocable on its own.
- Recovery codes during setup. We have no master key.
Reporting vulnerabilities
We welcome reports. Please disclose vulnerabilities privately; we reply within 72 hours and publish together with you after the fix. Contact address and OpenPGP key will be in /.well-known/security.txt once the service launches.
Planned reviews
| When | Review |
|---|---|
| before encryption goes live | external cryptography review |
| before Sealed launches | external cryptography audit |
| before public launch | external penetration test, data protection impact assessment |
| yearly | penetration test, restore and disaster-recovery test |