Trust

Where your data is, and who sees it.

Stored data, meaning accounts, mailboxes, content and databases, sits on our own servers at European providers in Switzerland, Germany, the Netherlands and France. The few services that differ from this are named below.

The US CLOUD Act

Since 2018, a provider subject to US law has to hand data it possesses or controls to US authorities, even when it is stored in Europe. What decides is therefore not where a data centre stands but who owns it. That is why your stored data sits only with European providers here.

The CLOUD Act, in detail

What is missing

We hold no ISO 27001 or SOC 2 certification and have had no independent security audit. What we disclose instead: where every server stands, who sees which data, how passwords are stored, and every incident at its real length. When the audit happens, we publish the result, whatever it is.

The path of an email at EMX

Where an email arrives, where it is kept, who can read it and how it leaves. Drawn from the sketch EMX started with.

How the diagram was made
The path of an email at EMXAn email comes from a sender on the internet to mx.emxmail.ch, where SPF, DKIM and DMARC are checked and the spam filter runs. Messages and attachments are stored encrypted in Geneva, sealed if you want; the database is in Frankfurt, with copies in Nuremberg and Paris. Mail is read in the web client and the app with sign-in through EAuth, in Outlook, Apple Mail and on the phone over IMAP with an app password, and by your software through the API with a token. Our own servers deliver outgoing mail, signed with DKIM, to recipients on the internet.StoredGenevamessages and attachments,stored encryptedsealed, if you wantFrankfurtdatabaseNurembergcopyPariscopyReceivedSenderanywhere on the internetmx.emxmail.chchecks SPF, DKIM, DMARCspam filterReadWeb client and appsign-in with EAuthOutlook, Apple Mail, phoneIMAP, app passwordYour softwareAPI with a tokenSentOur servers deliversigned with DKIMRecipientanywhere on the internet The path of an email at EMXAn email comes from a sender on the internet to mx.emxmail.ch, where SPF, DKIM and DMARC are checked and the spam filter runs. Messages and attachments are stored encrypted in Geneva, sealed if you want; the database is in Frankfurt, with copies in Nuremberg and Paris. Mail is read in the web client and the app with sign-in through EAuth, in Outlook, Apple Mail and on the phone over IMAP with an app password, and by your software through the API with a token. Our own servers deliver outgoing mail, signed with DKIM, to recipients on the internet.StoredGenevamessages and attachments,stored encryptedsealed, if you wantFrankfurtdatabaseNurembergcopyPariscopyReceivedSenderanywhere on the internetmx.emxmail.chchecks SPF, DKIM, DMARCspam filterReadWeb client and appsign-in with EAuthOutlook, Apple Mail, phoneIMAP, app passwordYour softwareAPI with a tokenSentOur servers deliversigned with DKIMRecipientanywhere on the internet

The exceptions, by name

We still use four services from outside the EU or from a US group, for narrowly limited jobs.

Service What for What it sees
Resend, United StatesNotification mails: an address confirmation, a password reset, invitations, replies to an enquiry.The recipient's address and the content of that one mail. Sent from the EU, stored in the United States.
Stripe, Ireland (a US group)Payment for EMX Team.The payment details. No mail, no accounts of your users.
Cloudflare, United StatesHolds the DNS zones of our domains.Names and addresses of our servers, no traffic. Cloudflare does not pass requests through.
Spamhaus, United KingdomBlock lists for the EMX spam filter.Addresses and domains of sending servers, no messages.

Being able to leave

With EAuth you export every account with the password hashes in their original form. With EMX every mailbox, over IMAP or the API. With a website all text, pictures, enquiries and data. At any time, without asking us.

Reporting security issues

Write to security@elchi.dev, in German or English. Every host names the address in /.well-known/security.txt. You get an answer within three working days. Whoever keeps to the rules has no legal action to expect from us; there is no reward programme.

security@elchi.dev

The rules for reports

Sub-processors

The complete list, with the place and job of every provider. When it changes, we announce it 30 days ahead.

To the list

Incidents

What is running is on status.elchi.dev, measured from several places. Every incident is recorded there at its real length.

status.elchi.dev

Imprint, privacy policy, terms, data processing agreement and the terms for EAuth and EMX. Every version stays published, with the day it applied from.

All legal documents

Infrastructure

Eight servers at Hetzner, UpCloud, Infomaniak, Scaleway and Tavuru in Switzerland, Germany, the Netherlands and France, with three copies of every database.

How the cluster is built