Skip to content

Security architecture

Built to be unable
to betray you.

We designed the system so that trusting us isn't required. This page says what we hold, what we can refuse, and what we can't do, including the parts most vendors leave out.

The guarantees

  • Sealed on your device

    Keys are generated and used in your browser. What travels to us, and what rests on our servers, is sealed data we have no way to open.

  • Post-quantum in the critical path

    Every message is sealed with ML-KEM-1024, the NIST-standardised post-quantum key encapsulation algorithm (FIPS 203), paired with AES-256-GCM for the message itself. Archives harvested today stay sealed against future computers.

  • Identity before unsealing

    A recipient proves who they are (via bank credentials through the Finnish Trust Network, a one-time SMS code, or an agreed PIN) before any key is released to their browser.

  • Access is revocable

    Expiry, view-once and withdrawal all take effect because we can refuse our half of the unlock. We still can't read the message.

Honest about the split

Why we hold half of every unlock.

Yes, it is end-to-end encrypted, and we are specific about the one thing we do hold.

  • Your message key never reaches us in full

    The message is sealed on your device with a key we never possess complete. Neither half opens anything alone.

  • Our half is what makes withdrawal possible

    We hold a separate half that gates access. That is what lets you withdraw a message, set an expiry, or open-once, and it is useless to us for reading.

  • Unsealing takes a moment on purpose

    Every unlock runs an intentionally expensive calculation (Argon2) on the recipient's device, so nobody holding the sealed file can grind through guesses. The pause is a lock working, not a page hanging.

What a compulsion produces

We can be compelled to hand over what we hold: sealed data and delivery metadata. We hold no means of opening your messages, so there is nothing readable to produce. We'd publish what we receive.

Where your data lives

Under Finnish law,
on European infrastructure.

Message content and encryption keys are stored exclusively on European infrastructure, operated under Finnish and EU law. Jurisdiction follows who owns the provider, not only where the racks sit.

  • Hosting provider

    PLACEHOLDER: name the EU-owned operator, the city, and the datacentre once confirmed.

  • Legal entity

    Suoja Email Oy, a Finnish limited company (business ID 3658119-3(opens in a new tab)), domiciled in Ulvila, Finland.

  • Report a vulnerability

    Write to security@suoja.email. We will respond within two working days.

Control after sending

  • Withdraw

    Pull access and the message stops opening for everyone, immediately.

  • Expiry

    A lifetime in hours or days. When it lapses, it stops opening on its own.

  • View once

    It unseals a single time, and then it's done.

Reviewing us for your organisation?

We're happy to walk a security or procurement team through the architecture in detail.