Security
Serious encryption, explained honestly.
Security you can't inspect is just a promise. Here is exactly how fjell.email protects your mail — the cryptography we use, what it defends against, and where the honest limits are.
End-to-end encryption
Messages between fjell.email users are encrypted on your device before they are sent, and only ever decrypted on the recipient's device. The server relays ciphertext it cannot read. Your content is protected with AES-256-GCM, an authenticated cipher that guarantees both confidentiality and integrity — a message that has been tampered with won't decrypt.
How your key is protected
Your private key is guarded by a password only you know. That password is never sent to us as a key; instead we run it through Argon2id, a memory-hard derivation function designed to resist brute-force and GPU attacks. The result unlocks your key locally. Because the whole chain hangs off a secret we never hold, we cannot reconstruct your key or read your encrypted mail — even under pressure, we can only hand over what we can decrypt, which is nothing.
Encrypted at rest
Beyond end-to-end encrypted content, your entire mailbox is encrypted at rest on our servers with AES-256. In the unlikely event of a server breach, stored mail remains unreadable without the keys. Encryption at rest and end-to-end encryption solve different problems, and we use both rather than one as a substitute for the other.
Your recovery phrase
When you enable Easy Encryption you receive a BIP39 recovery phrase — a sequence of ordinary words that backs up your encrypted key. Keep it in a password manager or on paper. It lets you restore access on a new device if you forget your password. It is also the one thing we genuinely cannot recover for you: the price of real end-to-end encryption is that there is no back door, not even for us.
Advanced OpenPGP
If you already manage your own cryptographic identity, import your OpenPGP keys and keep full control. Sign and encrypt with standard PGP and interoperate with the wider ecosystem. Easy Encryption and Advanced mode are two doors into the same room — start simple, take the wheel whenever you're ready.
One-time secure send
To reach someone who isn't on fjell.email, one-time secure send encrypts your message in the browser under a password you share out-of-band. The recipient opens it through a link; the plaintext never reaches our servers, and the message expires. It's the practical bridge between an encrypted network and the ordinary inboxes everyone else still uses.
Encryption is optional — but recommended
User-key encryption (Easy Encryption and Advanced OpenPGP) is yours to switch on or leave off. Either way, your mailbox is always encrypted at rest on our servers and in transit — so your data stays secure whether or not you enable it. Leaving user-key encryption off keeps your mail fully compatible with the broadest range of standard email clients; turning it on adds end-to-end protection that only you can unlock. We recommend enabling it — but the choice is yours.
What encryption can't do
We'd rather be precise than oversell. End-to-end encryption protects the contents of your fjell-to-fjell mail and one-time secure sends. It does not erase the envelope metadata that the email network fundamentally requires to route a message — who it's from and to, and when — especially for mail crossing to or from providers outside fjell.email. We protect what can genuinely be protected, minimise what we log, and never build profiling or advertising on top of any of it. Anyone who tells you encryption hides all of this isn't being straight with you.
Where it all lives
fjell.email is incorporated in Norway, inside the EEA and fully covered by the GDPR, on EU-hosted infrastructure. Strong law and strong cryptography reinforce each other: the math keeps your content private, and the jurisdiction means we answer only to valid, lawful legal process — never informal requests.
Privacy you can verify.
fjell.email is launching in 2026. Join the waitlist and be there from the start.
Join the waitlist