Know exactly who read it.
For law firms, clinics, accountants and public authorities: sealed messages and documents where the recipient proves their identity with their own bank credentials, giving you a record of delivery.
Bank ID verification · Post-quantum encryption · EU-only hosting · Nothing for your client to install
New Secure Message
Frictionless workflow
Enter your recipient’s email, write the message, and send. They get a one-click link in the inbox they already use, no app to install, and no account required to open it.
Granular security controls
Choose how they verify (bank credentials, SMS, or a PIN), set an expiry, and limit where the message can open. Defaults are sensible; tighten them when the document needs it.
Three questions ordinary email can't answer.
Did the right person receive it?
Email delivers to an address, not to a human. An address can be shared, forwarded, mistyped, or still monitored by an assistant who left last year. You've been assuming identity this whole time.
Did they actually read it?
A read receipt is a courtesy that most clients decline. When a deadline or a legal consequence hangs on it, "I sent it" is not the same as "they received it", and you know which one matters.
Could you prove any of it?
When a supervisory authority, an insurer or opposing counsel asks how a document was transmitted and to whom, a line in your sent folder is not evidence. It's a claim.
The flagship difference
Identity, not just an address.
Before anything unseals, your recipient proves who they are: not merely that they access an inbox, but that they are the exact person you intended.
Bank credentials, through the Finnish Trust Network
Your client authenticates the way they already authenticate for their taxes, their health records and their bank: with their own bank ID. There is nothing to teach them, and nothing for you to support.
Or a lighter method, when that fits
For lower-stakes messages you can require a one-time code by SMS, or a PIN you've agreed with the recipient in advance. You choose the level per message, or your organisation chooses it for you.
What you get back
A record of which verification method was used, and when the message was opened. That record is the difference between believing something arrived and being able to show it.
Verified before it unseals
Possession of the link is not authorisation. The verification step is what releases the key.
Bank ID
Strongest option: Finnish Trust Network.
SMS one-time code
When the stakes are lower.
Agreed PIN
A secret you've already shared offline.
Payment details, protected
Account numbers that arrive exactly as you sent them.
When payment details go by ordinary email, they can be intercepted, altered by one digit, and forwarded on — and your client has no way to tell. Suoja seals the message on your device and opens it on theirs, so the numbers that arrive are the numbers you typed, from the organisation they expect.
Sealed, so it can't be altered in transit
The message is sealed on your device and opened on theirs. Nothing between the two can read it, let alone change a digit in it.
Verified, so your client knows it's really you
They identify themselves with their bank credentials to open it, and they can see the message came from your organisation, not from an address that looks almost right.
Recorded, so the question of who said what has an answer
If the payment is ever disputed, you can show what you sent, to whom, and when they opened it.
Where this happens
Three moments where account numbers move by email and large sums follow close behind.
Property transactions
Completion payments to a seller's or solicitor's account.
Changed invoice details
"Our bank details have changed" is the most copied fraud email in circulation.
First payment to a new supplier
No previous account number to check the new one against.
Secure intake
Let clients send to you, securely, from your own website.
Most confidential information arrives the wrong way round: a client emails you their ID scan, their financials, their medical history, or their account details typed straight into the body of a message, unprompted and unprotected. By the time it's in your inbox the damage is done, and it's your liability.
Free for the person sending
Your clients never pay and never subscribe. Removing that barrier is the point, so that a nervous first-time enquirer will actually use it.
Nothing embedded in your site
It's a link, not a widget or an iframe. Nothing to maintain, nothing that can break your page, and no third-party script on your website.
The recipient can't be changed
The address is locked into the link. A client can't accidentally send their file somewhere else, and nobody can repurpose your link to impersonate you.
Your name and colours from the first screen
On the branded tier, your organisation's identity appears the moment the page loads, before anyone logs in. To your client it reads as your secure channel, not a generic tool you happen to use.
New Secure Message
Frictionless workflow
Enter your recipient’s email, write the message, and send. They get a one-click link in the inbox they already use, no app to install, and no account required to open it.
Granular security controls
Choose how they verify (bank credentials, SMS, or a PIN), set an expiry, and limit where the message can open. Defaults are sensible; tighten them when the document needs it.
It's still yours after you've sent it.
Withdraw access
Wrong wording, wrong file, wrong recipient, or a client relationship that ended. Pull access to a sent message and it stops opening for everyone, immediately.
Set an expiry
Give a message a lifetime measured in hours or days. When it lapses, it stops opening without you having to remember to do anything.
Open once, then close
For the most sensitive material: it unseals a single time, and then it's done.
Compliance
Evidence, not assurances.
Every delivery carries a record: who it went to, how they verified, when it opened, whether it was withdrawn. Exportable, and written in language a non-technical colleague can read.
Under GDPR Article 32, controllers must implement technical measures appropriate to the risk. Encryption in your device, verified recipient identity, and a retained access record is a straight answer to that requirement, produced automatically every time without anyone needing to remember.
Access records for your file
Who, how they verified, when it opened, whether it was withdrawn.
Data minimisation on its own
Expiry and withdrawal mean documents don't quietly accumulate in places you no longer control.
A DPA, and answers to your questionnaire
Standard data processing agreement, a published security architecture, and a named contact for procurement.
For larger organisations
Set your security rules once. Every team inherits them.
Decide how strictly your organisation works (which verification methods are permitted, how long messages live, what may be attached) and then lock it. Departments and subsidiaries inherit your rules and cannot loosen them.
Structured the way you are
A ministry above a municipality above a school. A firm above its offices. Each level can tighten what it inherits, and tune whatever the level above left open.
Nobody can quietly weaken it
An employee cannot lower a locked standard for one convenient message. That is the whole point of a standard.
Every change is recorded
When someone asks who changed a policy last quarter and why, the answer is retrievable with the person, the time, and the previous value.
How it cascades
Each level inherits the one above it and can only tighten.
Ministry
Locks the floor for everything beneath it.
Municipality
Tightens further; cannot loosen what it inherited.
School
Tunes whatever the levels above left open.
Your client won't need help using it.
No app, no account, no new password
They open a link in the inbox they already use and verify with credentials they already have. First-time recipients don't have to set anything up.
On the phone, in the waiting room
It runs in a mobile browser. No download between your client and whatever you need them to read.
It takes a moment to open, on purpose
Unsealing runs a deliberately expensive calculation on the recipient's device, so that nobody holding the sealed data can grind through guesses. We tell your client that while they wait, so the pause reads as a lock working rather than a page hanging.
If they lose their phone
A printed recovery phrase restores access to their own messages. Losing a device doesn't mean losing the messages.
The architecture, in short.
Sealed on your device
Keys are generated and used in your browser. Sealed data goes to us; we hold no means of opening it.
Post-quantum in the critical path
ML-KEM-1024 (FIPS 203), paired with AES-256-GCM for the message itself. Archives harvested today stay sealed against future computers.
Published, not asserted
Our full encryption design is public, including what we hold, what we can refuse, and what we can't do. Read the security architecture →
Built around work like yours.
Law firms
Engagement letters, settlement drafts and case files to clients who may be opening them on a phone. High-assurance verification when the matter demands it, and a record for the file.
Clinics and practices
Referrals, results and treatment plans to patients, plus an intake link on your website so new patients can send you their history without emailing it in the clear.
Accountants and advisors
Request identity documents, financials and KYC packs from clients, and return completed filings, without either direction travelling by ordinary attachment.
Public authorities
Decisions, support plans and case correspondence to citizens who don't have and shouldn't need an account. Parent organisations set the policy the whole structure inherits.
Jurisdiction
Under Finnish law,
on European infrastructure.
Content and keys are stored exclusively in the EU. For public authorities and regulated professions, the jurisdiction your documents sit in is not a detail; it is a requirement, and often a procurement condition.
Pricing coming soon.
We are finalizing our seat and verification packages for organizations. Get in touch to discuss your requirements.
Questions your colleagues will ask.
Do we have to leave Outlook or Gmail?
No, and to be clear, this isn't a plugin for them either. Suoja.email is a separate secure channel you use for the messages that warrant it, while ordinary mail carries on being ordinary mail. Most organisations send a handful a week this way, not everything.
What if a client refuses to use another tool?
There is nothing for them to adopt. They open a link and verify with their bank credentials with no signup, no app, and no password. In practice the friction sits with the sender, not the recipient.
Can you be compelled to hand over our messages?
We can be compelled to hand over what we hold, which is sealed data and delivery metadata. We hold no means of opening your messages, so there is nothing readable to produce. We'd publish what we receive.
Is it really end-to-end encrypted if you hold part of the key?
Yes, and we're specific about it. Your message is sealed on your device with a key we never possess in full. We hold a separate half that gates access, which is what makes withdrawal and expiry possible. Neither half opens anything alone, and ours is useless to us.
How many people can receive one message?
As many as you address it to. Each recipient gets their own sealed copy and verifies separately, so one person opening it tells you nothing about the others.
Request access.
We're onboarding organisations in stages so that each one gets set up properly. Tell us a little and we'll come back with a date and a walkthrough.