Security and privacy
We would rather tell you exactly what we do than make big promises. This page lists the protections that are switched on today, what is and is not encrypted, and where the limits are.
Your account
Passkeys
Sign in with your fingerprint, face or device PIN. Passkeys cannot be phished or guessed, and we only keep their public keys.
Two-step verification
Codes from an authenticator app, single-use backup codes, and devices you choose to trust for 30 days.
Sign-in alerts and history
You are told about new sign-ins and failed attempts, can see the last 90 days of sign-ins, and can sign out any device.
Breached password check
New passwords are checked against known breaches using only the first five characters of a hash, so the password itself never leaves our server.
Shared computer mode
Tick "This is a shared or public device" when you sign in, and Viremail keeps no mail or keys on that computer and does not keep you signed in.
End-to-end encrypted email
OpenPGP is built in. Mail to anyone with a public key is encrypted in your browser, and only they can read it. Your private key is encrypted with your password before it reaches us.
Shield
Checks incoming mail for phishing, look-alike links and risky attachments, and warns you in plain words before you open them.
Tracking pixels blocked
Pictures from outside an email are blocked by default, so senders cannot see when you open their mail.
Disposable addresses
Keep your real address out of shop and sign-up databases, and switch an address off the moment it gets spam.
Vire and calls
Calls
Calls go directly between devices where the network allows, are encrypted in transit and are never recorded.
You choose who reaches you
Decide who can message you, call you, add you to groups and see your stories. Strangers wait in Requests.
Files
Files encrypted on our servers
Every file in Drive, and every photo and file sent in Vire, is sealed with AES-256-GCM before it is written to disk. Each Drive file has its own key.
Links with limits
Share links can carry a password and an end date, and can be replaced to switch the old one off.
How we run the service
No ads, no tracking
We do not show ads, sell data or use third-party analytics. Our own dashboard keeps only totals, such as how many people are online.
Encrypted connections
Connections to the app use HTTPS, with a strict content security policy that only lets our own scripts run. Mail to other providers uses TLS where their server supports it.
Sealed sessions
While you are signed in, your mailbox password is held in a server-side session encrypted with AES-GCM, and the session cookie cannot be read by scripts.
Report a problem
Found a weakness? Our disclosure policy and security.txt say how to reach us.
What is encrypted, and how
| What | How it is protected |
|---|---|
| Email to someone with an OpenPGP key | End to end End to end with OpenPGP. Only they can read it. |
| Other email | In transit In transit, where the other mail server supports TLS |
| Vire messages | In transit In transit. Not end to end yet. |
| Photos and files in Vire | Encrypted at rest In transit, and stored encrypted on our servers |
| Voice and video calls | In transit In transit, often straight between devices. Never recorded. |
| Files in Drive | Encrypted at rest In transit, and stored encrypted with a key for each file |
- Is my email end-to-end encrypted?
- Email can be. Viremail has OpenPGP built in, so mail to people who have a public key is encrypted in your browser and only they can read it. Mail to people without a key is sent as normal email.
- Are Vire chats end-to-end encrypted?
- Not yet. Vire messages travel over encrypted connections, and photos and files are stored encrypted on our servers, but message text is not end-to-end encrypted yet.
- Are calls end-to-end encrypted?
- Calls are encrypted in transit. Where the network allows, they go directly between your devices without passing through our servers, and we never record them.
What we do not claim
- Unless you use end-to-end encryption, your mail, chats and files are stored in a form our systems can read, so they can be searched, filtered and delivered.
- Encrypting mail with OpenPGP protects the message and its attachments, not the subject line, and not who wrote to whom or when.
- In a web browser you rely on the code we send each time you open the app. That is true of every web app.
- We do not currently claim any independent security certification.
- No online service can be perfectly secure. A unique password, a passkey and up-to-date devices make the biggest difference.
Found a problem?
If you think you have found a security weakness in Viremail, please tell us before telling anyone else. Our responsible disclosure policy explains what to include, and security.txt lists our current security contact.