Security

How we protect your data, what we could technically see, and where the limits are.

Principles

  • Memory-safe languages for our own components (Rust), no home-made cryptography.
  • Least privilege and four-eyes principle for every access to production systems.
  • No content in logs. Logs contain neither message bodies nor subject lines.
  • Open code for everything that runs on your devices or handles your keys.

Encryption

Transport

TLS 1.3 preferred, TLS 1.2 as the minimum. When sending to other servers we use DANE and MTA-STS where the other side supports them.

Disks

The servers of the mail service store data only on encrypted disks (LUKS2). Anyone who gets hold of a disk cannot read it without the key. On top of that, every mailbox is encrypted with its own key.

Compatible (default)

Every account has its own key pair. Incoming mail is encrypted with your public key, even while you are not logged in. The private key is protected by your password and is only decrypted in memory during your session.

What we could technically do: during delivery and while you are logged in, the server processes plain text. An attacker with full access to the running server could read along at those moments. Access controls, signed deployments and audit logs are how we counter that.

Sealed (zero access)

Folders in Sealed mode are encrypted with OpenPGP (RFC 9580). The private key never leaves your device unencrypted. We cannot read this content and therefore cannot hand it over.

Sign-in

  • Passkeys (WebAuthn) and one-time codes (TOTP) serve as a second factor. No SMS.
  • Every mail app gets its own app password, which can be revoked individually.
  • You receive recovery codes during setup. We have no master key.

How we work ourselves

Security and privacy are our first rule. That also applies to our own devices and access.

  • Encrypted laptops. Every laptop we work with is fully encrypted.
  • A kill cord. Our laptops are tethered with a BusKill cable. If the connection breaks, for example because someone takes the device, it secures itself at once.
  • Long passwords. We use very long passwords throughout.
  • Servers by key only. Our servers can only be reached with a cryptographic key. Signing in with a password is switched off there.

Reporting vulnerabilities

We welcome reports. Please disclose vulnerabilities privately; we reply within 72 hours and publish together with you after the fix. Contact, scope and rules are listed under Report a vulnerability.

Encryption only after external review

The encrypted storage of your mail goes into operation only after an external party has reviewed it, in Compatible mode and in Sealed folders alike. Every year a penetration test and a restore and disaster-recovery test follow. We publish the results of audits and penetration tests on this page.

Questions about security

Can you read my mail?

In the default mode, Compatible, technically yes, as long as you are signed in: the server then processes plain text. In Sealed folders, no. Details are under Compatible and Sealed.

Is the default mode zero access?

No. Compatible is neither zero access nor end-to-end encryption. Zero access applies to Sealed folders.

Is there a second factor by SMS?

No. Passkeys and one-time codes serve as the second factor; there are no SMS codes, and a phone number is not required. More under Signing in and your account.

Can you recover my account if I lose my password and codes?

No. We have no master key. Without a recovery code there is no way to the stored content.

Does mail content appear in your logs?

No. Logs contain neither message bodies nor subject lines.