Security & Privacy

GDPR email archive security: how Evermail protects your data

Evermail is built on the principle that your email is your business — not ours. EU-hosted, AES-256 encrypted, and available in three security modes so you can match the protection level to the sensitivity of each archive.

Our security approach

Security is an architecture decision, not a feature

Most SaaS products add security as a layer on top. We designed Evermail with security as a constraint from the start. Every data model decision, every API endpoint, every storage choice was made with one question in mind: what is the minimum access Evermail needs, and how do we give customers control over everything beyond that minimum?

The result is a three-tier security model where you choose — per archive — how much access Evermail has to your content. No one-size-fits-all encryption. No mandatory trust in our infrastructure. Your HR archive and your personal email archive can have different security levels on the same account.

Security levels

Three security modes. One per archive.

Choose the level that matches your sensitivity requirements. You can change the mode for any archive at any time.

Default

Full Service

Your archive is encrypted at rest using AES-256. Evermail holds the encryption key and can decrypt your content to power full-text search, AI summaries, and MCP queries.

  • ✓ AES-256 encryption at rest
  • ✓ Full-text search across content
  • ✓ AI summaries and MCP integration
  • ✓ Attachment indexing and preview
Best for most archives
Premium

Confidential (BYOK)

Your archive content is encrypted under your own key, stored in your Azure Key Vault. Evermail requests access to decrypt content for search and AI — but you can revoke that access instantly by removing the key grant. Evermail never stores your master key.

  • ✓ Customer-controlled encryption key (BYOK)
  • ✓ Instant revocation — remove key access, Evermail goes dark
  • ✓ Full-text search and AI while key is active
  • ✓ Offline passphrase-derived key generation supported
For sensitive archives
Maximum privacy

Zero-Access

Your encryption key never leaves your device. Evermail stores only ciphertext — it is mathematically impossible for Evermail to read your email content, even in response to a legal order. Server-side search is limited to metadata (sender, recipient, subject, date).

  • ✓ Client-side key generation and storage
  • ✓ Evermail only stores ciphertext
  • ✓ Metadata search (sender, recipient, subject, date)
  • ✗ Full-text content search not available
  • ✗ AI summaries not available (no server-side decryption)
For maximum privacy

All modes support BYOK including offline passphrase-derived key generation. EU-hosted. Tenant-isolated. Encrypted at rest.

Infrastructure

EU-hosted infrastructure for GDPR compliance

🇪🇺
Azure EU data centres

All Evermail data is stored exclusively on Microsoft Azure in EU regions. Your email archive never leaves the EU. This is a hard architectural guarantee, not a configuration option.

🔐
AES-256 encryption at rest

All stored data is encrypted using AES-256. In Full Service mode, Evermail manages the key. In Confidential and Zero-Access modes, you control the key — Evermail only ever holds ciphertext.

🔒
TLS 1.2+ in transit

All data in transit between your browser and Evermail's servers is encrypted with TLS 1.2 or higher. There is no unencrypted communication path.

🏠
Strict tenant isolation

Every customer's data is isolated at the storage level. No customer's archive is accessible to another customer's account. Isolation is enforced by architecture, not by access control policy alone.

🗑️
Right-to-erasure support

You can permanently delete any archive or individual email at any time. Deletion is hard deletion with audit trail. Evermail supports GDPR Article 17 (right to erasure) for all plans.

📋
Data Processing Agreement

Evermail provides a standard Data Processing Agreement (DPA) for customers who require one for GDPR Article 28 compliance. Download the DPA →

GDPR compliance

Built for GDPR from day one

Evermail is a GDPR-compliant email archive platform. All personal data processed by Evermail is stored within the EU and handled in accordance with GDPR requirements. Here is what that means in practice:

📍
Data stays in the EU

All data is stored on Azure infrastructure in EU regions. We do not use sub-processors that transfer personal data outside the EU. This is documented in our DPA.

🎯
Purpose limitation

Evermail processes email content solely to provide the email archiving and search service you subscribed to. We do not analyse, monetise, or share your email content for any other purpose.

🤖
No AI training on your data

Evermail never uses your email content to train machine learning models. AI features operate on your data in real time and the results are not retained for model improvement.

🗑️
Erasure on demand

Delete any archive or individual email permanently at any time. Deletion is hard deletion — data is removed from primary storage and backup within 30 days. We provide deletion confirmation on request.

Encrypted email archiving that meets your compliance requirements

EU-hosted, GDPR-compliant, three security levels. Start with the free plan — no credit card required.

Get started free → Download DPA →
FAQ

Security and privacy questions

Where is my email data stored?
All Evermail data is stored on Microsoft Azure infrastructure in EU data centres. Your email archive never leaves the EU. We use Azure Blob Storage with server-side AES-256 encryption for all stored data.
What is BYOK (Bring Your Own Key) encryption?
BYOK means you supply the encryption key used to protect your archive. In Confidential mode, your key is stored in your own Azure Key Vault. Evermail requests access to decrypt content for in-app search and AI, but you can revoke that access instantly by removing the key grant. Evermail never stores your master key. In Zero-Access mode, your key never leaves your device at all.
Is Evermail GDPR compliant?
Yes. Evermail is GDPR compliant by architecture. All data is hosted in Azure EU regions with strict tenant isolation. We support right-to-erasure and publish a Data Processing Agreement (DPA) for customers who require one under GDPR Article 28.
Does Evermail train AI models on my emails?
No. Evermail never uses your email content to train AI models, improve algorithms, or share with third parties. AI features (summaries, MCP search) operate on your data in real time and are not used for training. Your emails are yours.
What encryption standard does Evermail use?
Evermail uses AES-256 encryption at rest for all stored data, and TLS 1.2+ in transit. In Confidential and Zero-Access modes, content is additionally encrypted with customer-controlled keys before storage, so Evermail's infrastructure only ever holds ciphertext.
Can Evermail be compelled to hand over my emails to law enforcement?
In Zero-Access mode: no. Evermail only stores ciphertext and does not hold decryption keys, so there is nothing to hand over beyond encrypted data. In Full Service mode, like any cloud service, we could be subject to a valid legal order. In Confidential mode with BYOK, you can revoke our key access before any such order is executed, preventing decryption.
Do you have a Data Processing Agreement (DPA)?
Yes. Evermail provides a standard DPA for customers who require one for GDPR Article 28 compliance. Download the DPA →