Security & privacy

Mail you can put your name on.

We hold ourselves to the standards we’d want from a mail provider. Then we publish the proof.

Encrypted at every step

TLS 1.3 in transit (with MTA-STS & DANE), AES-256 at rest. Per-mailbox storage keys.

EU residency, by default

Mail lives in Frankfurt and Stockholm. No US data path. GDPR + Schrems II ready.

Not training data

Your mail isn’t scanned for ads, sold, or used to train any model. Contractual, not just policy.

Auth that holds up

App-specific passwords today. TOTP & WebAuthn (passkeys) rolling out Q3. SSO on Business.

Anti-spoofing built in

DKIM 2048, auto-rotated. SPF, DMARC. Visual reports — see who’s pretending to be you.

Audit, retention, hold

Tamper-evident audit log. Per-domain retention windows. Legal hold on Business.

Compliance

Audited & documented.

SOC 2
Type II · annual
ISO 27001
Certified 2025
GDPR
DPA on every plan
HIPAA
BAA on Business
See the live trust report for current attestations and the subprocessor list.
Disclosure

Found something? Tell us.

We run a coordinated disclosure program with bounty payouts up to €15,000. Email [email protected] — PGP key on the page below.