Security designed in from the start, not added later.
Encryption without exceptions, no content analysis and no data sales. And an advantage no technical configuration can replace: your data never leaves European jurisdiction.
- TLS encryption
- GDPR by design
- No content analysis


Jurisdiction and confidentiality
American law allows access. Professional confidentiality does not survive that.
In the US, national security legislation allows intelligence services to demand data from service providers, a possibility the Court of Justice of the EU found disproportionate and which clashes with the duty of confidentiality of several professions.
FISA Section 702
Allows US intelligence agencies to demand from American providers the data of people outside the US, for foreign intelligence and national security purposes, without those targeted being notified.
CLOUD Act
Requires American companies to hand over data to US authorities regardless of the country where it is stored, including in data centres in Europe.
No effective redress
In the "Schrems II" judgment (2020), the Court of Justice of the EU concluded that these laws do not give Europeans guarantees or means of defence equivalent to those under European law.
Professions bound by confidentiality
Lawyers, doctors, psychologists, accountants, journalists.
When communications live with providers subject to these laws, confidentiality between professional and client no longer depends solely on the professional: it comes to depend on decisions by the authorities of a third country, taken without their knowledge. For anyone bound to confidentiality by law or by a code of professional conduct, it is a risk that is hard to justify. At Sooma, data is subject exclusively to Portuguese and European law: any access is only possible under Portuguese law, with judicial oversight.

Security architecture
Protected at every layer, not just at the entrance.
Email service security is not just about the password. It covers the network, storage and who has access to the data, at each of these points.
Encryption in transit
All communication (webmail, IMAP, SMTP) travels encrypted with TLS. No exceptions, no plan left out.
Protected storage
Messages are stored encrypted on the servers, in Europe. They are not visible to anyone who shouldn't see them.
Anti-spam and anti-malware
Filtering with SPF, DKIM and DMARC applied by default, to protect the domain from spoofing and phishing.
No content analysis
Messages are not read, indexed or used to build advertising profiles. Your email is not the currency.
Backups
Regular backups and redundant infrastructure, so that a server failure does not mean losing data.
GDPR by design, not retrofitted
The platform has been built within the GDPR from day one: traceability, data minimisation and controlled, logged internal access. It is not a compliance layer glued onto an American product.
Defence in depth
Three layers. None is enough on its own.
From network to people: where each layer acts and why none is enough on its own.
Network and transport
Firewalls and filtering at the network edge, with TLS protecting all connections to and from the servers.
Storage
Data encrypted at rest, with backups and redundancy across servers.
People and processes
Team access limited to the minimum necessary, with dedicated authentication and a log of who accesses what. A team in Europe, not outsourced to third-country jurisdictions.
Law before technology
The first layer of privacy is where the data lives.
You can have the best encryption in the world, but if the data is subject to third-country access laws, privacy depends on international agreements that have already collapsed twice and now face a third challenge. At Sooma, data stays in Europe, under the GDPR and European law, with no transfers to the US. Compliance does not depend on any transatlantic agreement.
Why this matters now →Frequently asked questions
Security & privacy
The most common questions about protecting your messages and data.
Are my messages encrypted?
Yes. Communication between the user and Sooma's servers is encrypted with TLS, and messages are protected in storage.
Can Sooma read the content of my emails?
There is no analysis of message content for commercial purposes, profiling or advertising. The technical team's access is limited to what is necessary to provide support.
What personal data does Sooma process, and under which law?
Client data is processed in the EU (Portugal), under the GDPR and Portuguese law, with no transfers outside the European Union. The privacy policy details the categories of data and the retention periods.
How do backups work?
Data is backed up regularly and the infrastructure is redundant, so that a server failure does not mean data loss.
Can a foreign authority demand access to my data?
The data is subject exclusively to Portuguese and European law. Sooma is not covered by third-country extraterritorial access laws such as the US CLOUD Act, unlike any provider subject to US jurisdiction, wherever its servers are.
Does Sooma have security certifications?
Yes, see the Certifications page for the full list and compliance details.
Choose an email built to protect, not to exploit.
60-day money-back guarantee, no questions asked. Assisted migration included.
