Security architecture
Built to be unable
to betray you.
We designed the system so that trusting us isn't required. This page says what we hold, what we can refuse, and what we can't do, including the parts most vendors leave out.
The guarantees
Sealed on your device
Keys are generated and used in your browser. What travels to us, and what rests on our servers, is sealed data we have no way to open.
Post-quantum in the critical path
Every message is sealed with ML-KEM-1024, the NIST-standardised post-quantum key encapsulation algorithm (FIPS 203), paired with AES-256-GCM for the message itself. Archives harvested today stay sealed against future computers.
Identity before unsealing
A recipient proves who they are (via bank credentials through the Finnish Trust Network, a one-time SMS code, or an agreed PIN) before any key is released to their browser.
Access is revocable
Expiry, view-once and withdrawal all take effect because we can refuse our half of the unlock. We still can't read the message.
Honest about the split
Why we hold half of every unlock.
Yes, it is end-to-end encrypted, and we are specific about the one thing we do hold.
Your message key never reaches us in full
The message is sealed on your device with a key we never possess complete. Neither half opens anything alone.
Our half is what makes withdrawal possible
We hold a separate half that gates access. That is what lets you withdraw a message, set an expiry, or open-once, and it is useless to us for reading.
Unsealing takes a moment on purpose
Every unlock runs an intentionally expensive calculation (Argon2) on the recipient's device, so nobody holding the sealed file can grind through guesses. The pause is a lock working, not a page hanging.
What a compulsion produces
We can be compelled to hand over what we hold: sealed data and delivery metadata. We hold no means of opening your messages, so there is nothing readable to produce. We'd publish what we receive.
Where your data lives
Under Finnish law,
on European infrastructure.
Message content and encryption keys are stored exclusively on European infrastructure, operated under Finnish and EU law. Jurisdiction follows who owns the provider, not only where the racks sit.
Hosting provider
PLACEHOLDER: name the EU-owned operator, the city, and the datacentre once confirmed.
Legal entity
Suoja Email Oy, a Finnish limited company (business ID 3658119-3(opens in a new tab)), domiciled in Ulvila, Finland.
Report a vulnerability
Write to security@suoja.email. We will respond within two working days.
Control after sending
Withdraw
Pull access and the message stops opening for everyone, immediately.
Expiry
A lifetime in hours or days. When it lapses, it stops opening on its own.
View once
It unseals a single time, and then it's done.
Reviewing us for your organisation?
We're happy to walk a security or procurement team through the architecture in detail.