Website online. Mail service in development; launch follows security reviews.Current status

Security

How we protect your data, what we could technically see, and where the limits are.

Status: The service is in development. This page describes the architecture we are building. Audits and penetration tests will take place before launch and will be published here.

Principles

  • Memory-safe languages for our own components (Rust), no home-made cryptography.
  • Least privilege and four-eyes principle for every access to production systems.
  • No content in logs. Logs contain neither message bodies nor subject lines.
  • Open code for everything that runs on your devices or handles your keys.

Encryption

Transport

TLS 1.3 preferred, TLS 1.2 as the minimum. When sending to other servers we use DANE and MTA-STS where the other side supports them.

Compatible (default)

Every account has its own key pair. Incoming mail is encrypted with your public key, even while you are not logged in. The private key is protected by your password and is only decrypted in memory during your session.

What we could technically do: while you are logged in, the server processes plain text. An attacker with full access to the running server could read along at that moment. Access controls, signed deployments and audit logs are how we counter that.

Sealed (zero access)

Folders in Sealed mode are encrypted with OpenPGP (RFC 9580). The private key never leaves your device unencrypted. We cannot read this content and therefore cannot hand it over.

Sign-in

  • Passkeys (WebAuthn) and one-time codes (TOTP) as a second factor. No SMS.
  • Separate app passwords for mail apps, each revocable on its own.
  • Recovery codes during setup. We have no master key.

Reporting vulnerabilities

We welcome reports. Please disclose vulnerabilities privately; we reply within 72 hours and publish together with you after the fix. Contact address and OpenPGP key will be in /.well-known/security.txt once the service launches.

Planned reviews

WhenReview
before encryption goes liveexternal cryptography review
before Sealed launchesexternal cryptography audit
before public launchexternal penetration test, data protection impact assessment
yearlypenetration test, restore and disaster-recovery test