Security

Security and privacy by design.

Privacy isn't a feature we bolted on โ€” it's the reason Tilomail exists. Here's a plain, concrete look at how your mailbox is encrypted, authenticated and kept isolated, with no marketing badges we can't stand behind.

๐Ÿ”’ AES-256 at rest ๐Ÿ” TLS 1.3 in transit ๐Ÿ›ก๏ธ Zero-access architecture ๐ŸŒ EU data residency
Privacy by design

Your mail is nobody else's business

We make money from subscriptions, not from reading your inbox. Tilomail is engineered so that your messages are locked to keys only you control โ€” the system is built so that even we can't mine your mail to sell you anything.

Zero-access encryption

Your stored mailbox is encrypted with a key derived from your credentials. Locked by default, readable by you.

Verified senders

Every inbound message is checked against SPF, DKIM and DMARC, then scored by an anti-abuse engine that quarantines phishing.

You stay in control

Export or delete everything at any time. No lock-in, no shadow profiles, no selling data to third parties.

Under the hood

The standards every Tilomail mailbox runs on.

Encryption at restโœ“ AES-256
Encryption in transitโœ“ TLS 1.3 enforced
Mailbox accessโœ“ Zero-access
Password storageโœ“ Argon2id hashing
Two-factor authโœ“ TOTP & passkeys
Sender validationโœ“ SPF ยท DKIM ยท DMARC
Transport policyโœ“ MTA-STS
Data residencyโœ“ European Union
Backupsโœ“ Encrypted, redundant
Defense in depth

How we protect your mail

Layered controls, from the moment a message arrives to the moment you read it โ€” and every backup in between.

Encryption everywhere

Messages and attachments are encrypted with AES-256 while stored, and every connection is protected with TLS 1.3. Older, weaker ciphers are refused.

Zero-access architecture

Your mailbox key is unlocked by your login and never stored in the clear. Our operators and infrastructure work with encrypted blobs, not readable mail.

Strong authentication

Protect your account with two-factor authentication (TOTP) or passwordless passkeys built on WebAuthn. Suspicious sign-ins are challenged automatically.

Sender authentication

Inbound mail is validated with SPF, DKIM and DMARC, and outbound mail is signed so recipients can trust it came from you. MTA-STS keeps delivery on encrypted paths.

Anti-abuse & anti-phishing

A real-time risk engine scores every message for spoofing, malware and impersonation, quarantines the dangerous ones, and rate-limits abusive senders.

Infrastructure & isolation

Services run in hardened, network-isolated environments with least-privilege access, encrypted internal traffic, and audit logging on administrative actions.

Data residency & resilience

Where your data lives

Your mailbox stays in the European Union, and it's backed up so a bad day never becomes a lost inbox.

EU data residency

Mail, calendars and contacts are stored and processed on servers located in the European Union, under strong data-protection law. We don't quietly move your data offshore.

Encrypted backups

Backups are encrypted and kept redundantly within the EU, so your mailbox can be recovered from hardware failure โ€” without ever exposing readable contents at rest.

Responsible disclosure

Found a vulnerability? Tell us.

Security is a shared effort, and we're grateful to researchers who report issues responsibly. If you believe you've found a vulnerability in Tilomail, email us with enough detail to reproduce it and we'll work with you in good faith to confirm and fix it. Please give us a reasonable window before any public disclosure, and don't access, modify or delete other people's data while testing.

In scope

  • Authentication, session and account-takeover issues
  • Injection, access-control and data-exposure bugs
  • Mail spoofing or encryption-handling flaws

Please avoid

  • Denial-of-service, spam or load testing against production
  • Social engineering of our team or customers
  • Accessing data that isn't yours to test with

We aim to acknowledge reports within a few business days. We don't run a paid bounty program yet, but with your permission we're glad to credit you once a fix ships. Prefer encrypted email? Ask and we'll share a key.

Honest about what we are

Tilomail is a focused, independent service. We describe the controls we actually run and the standards we actually follow โ€” nothing more. You won't find certification badges here that we haven't earned; when our practices are independently assessed, we'll say so plainly and link the evidence. Until then, the specification above is the real thing, and you're welcome to test it.

Private by default.

Start with an encrypted inbox that treats your mail as yours alone. Read exactly what we collect in our Privacy Policy, then make the switch.