Security and data location
Where your mail is, and who can read it.
EMX runs on servers we rent from providers in Switzerland and the EU. Here is what is where, what is encrypted, and the exceptions, by name.
The path of an email
Where an email arrives, where it is kept, who can read it and how it leaves.
What is where
| Messages and attachments | Geneva, Switzerland, stored encrypted |
|---|---|
| Database (mailboxes, folders, settings) | Frankfurt, Germany; copies in Nuremberg and Paris |
| Outgoing mail | our own servers, unless you choose your own Resend account |
| Payment on Team | Stripe; EMX stores no card data |
| Block lists for the spam filter | queries to Spamhaus, United Kingdom, with the address of the sending server |
Every sub-processor with its location and task is in Annex A of the EMX terms. EMX terms
How EMX protects your mail
Stored encrypted
Every message is encrypted in storage; the keys are not with the storage provider.
Sealed mailboxes
Where allowed, EMX encrypts messages, subject, sender and recipients included, to a key the person's passkey unlocks. Then we cannot read them either.
Passkey sign-in
Through EAuth with a passkey or a password and a second factor. Mail apps get app passwords of their own, revoked one by one.
Encrypted on the way
TLS to browsers and mail apps, MTA-STS for your domain, and DKIM signatures on every outgoing message.
Senders checked
SPF, DKIM and DMARC on every incoming message; forgeries of your own domain stand out.
Keeping little
Full IP addresses in logs for 90 days only, then the network alone.
What we do not claim
- No independent auditEMX has had no external security audit, and no ISO 27001 or SOC 2 certification.
- No virus scan yetPrograms as attachments are refused, but a scan for known viruses runs only once a scanner is connected.
- No legal archiveEMX is not an archive for the records the law makes a business keep.
A mailbox at your own domain, today.
Private is free and starts at once. Switch to Team when more people join.