Your digital
registered letter.
Some things are too important for ordinary email. Send them sealed end to end (a message, a document, or both), opened only by the person you meant and verified with their own bank credentials. You'll know exactly who opened it, and when.
Suoja is Finnish for shelter. A place you put something valuable so it arrives intact.
- Opened with bank credentials
- Encrypted before it leaves your device
- Held only in the EU
- Nothing to install
You already know which messages these are.
At work
An engagement letter, a lab result, a case decision, the account number a client is about to pay into. It leaves your outbox and then you're guessing. Did the right person get it? Did they read it? If someone asks you to prove it next year, what exactly would you show them?
At home
A will after a parent dies. The bank details for a house sale. A passport copy for a relative helping with forms. The household passwords. Things you'd never leave face-up on a table in a café, yet they get typed into an ordinary email and sent.
Same problem, same answer: it should be sealed before it leaves you, and the person opening it should have to prove who they are.
Two ways in.
For organisations
Law firms, clinics, accountants, municipalities and authorities. Verified delivery, records you can hand to a compliance officer, a secure intake link for your own website, and one security policy that every office and team inherits.
See it for organisations →For individuals
For the things you'd otherwise send by registered letter. Free to start, no subscription, and the person receiving it doesn't need an account.
See it for individuals →
Built to be unable to betray you.
We designed the system so that trusting us isn't required.
Encrypted on your device
Keys are generated and used in your browser. Your words and your attachments are sealed before they travel, and what rests on our servers is data we have no way to open.
Post-quantum by default
Every message is sealed with ML-KEM-1024, the NIST-standardised post-quantum algorithm (FIPS 203). Encrypted archives stolen today can't be unlocked by tomorrow's computers.
Honest about what we hold
We keep one half of each message's unlock, deliberately. That's what lets you withdraw a message after you've sent it, and it's useless on its own without your recipient's half.
What the person on the other end experiences.
A message arrives in their normal inbox
No new app, no invitation to accept, no account to create. Just a message with a link, which arrives wherever they already read their email.
They prove who they are
You choose how: their bank credentials, a code by SMS, or a PIN you've agreed with them. For a Finn, the bank option needs no explanation at all.
It unseals in their browser
Decryption happens on their device, not on our servers. It takes a moment by design: every unlock runs an intentionally expensive calculation, so nobody can sit and guess their way in, even holding the sealed data.
Designed, built and hosted in Finland
Designed, built and
hosted in Finland.
Your most private correspondence shouldn't sit under someone else's jurisdiction. Message content, attachments and encryption keys are stored exclusively on European infrastructure, operated under Finnish and EU law.
Stored in the EU
Message content, attachments and encryption keys stay on European infrastructure.
Finnish jurisdiction
A Finnish company under Finnish and EU law. Jurisdiction follows who owns the provider, not only where the racks sit.
Named, not asserted
We publish the operator, the location and the legal entity rather than asking you to assume them. Where your data lives →