Opens in a new tab

Security designed in from the start, not added later.

Encryption without exceptions, no content analysis and no data sales. And an advantage no technical configuration can replace: your data never leaves European jurisdiction.

  • TLS encryption
  • GDPR by design
  • No content analysis
Man with glasses coding on a laptop in an office with glass walls, with a code icon
Woman with glasses, seen from behind, looking at data screens in a server room with blue light

Jurisdiction and confidentiality

American law allows access. Professional confidentiality does not survive that.

In the US, national security legislation allows intelligence services to demand data from service providers, a possibility the Court of Justice of the EU found disproportionate and which clashes with the duty of confidentiality of several professions.

FISA Section 702

Allows US intelligence agencies to demand from American providers the data of people outside the US, for foreign intelligence and national security purposes, without those targeted being notified.

CLOUD Act

Requires American companies to hand over data to US authorities regardless of the country where it is stored, including in data centres in Europe.

No effective redress

In the "Schrems II" judgment (2020), the Court of Justice of the EU concluded that these laws do not give Europeans guarantees or means of defence equivalent to those under European law.

Professions bound by confidentiality

Lawyers, doctors, psychologists, accountants, journalists.

When communications live with providers subject to these laws, confidentiality between professional and client no longer depends solely on the professional: it comes to depend on decisions by the authorities of a third country, taken without their knowledge. For anyone bound to confidentiality by law or by a code of professional conduct, it is a risk that is hard to justify. At Sooma, data is subject exclusively to Portuguese and European law: any access is only possible under Portuguese law, with judicial oversight.

Talk to the team →

Call centre agents with headsets working at computers

Security architecture

Protected at every layer, not just at the entrance.

Email service security is not just about the password. It covers the network, storage and who has access to the data, at each of these points.

Encryption in transit

All communication (webmail, IMAP, SMTP) travels encrypted with TLS. No exceptions, no plan left out.

Protected storage

Messages are stored encrypted on the servers, in Europe. They are not visible to anyone who shouldn't see them.

Anti-spam and anti-malware

Filtering with SPF, DKIM and DMARC applied by default, to protect the domain from spoofing and phishing.

No content analysis

Messages are not read, indexed or used to build advertising profiles. Your email is not the currency.

Backups

Regular backups and redundant infrastructure, so that a server failure does not mean losing data.

GDPR by design, not retrofitted

The platform has been built within the GDPR from day one: traceability, data minimisation and controlled, logged internal access. It is not a compliance layer glued onto an American product.

Defence in depth

Three layers. None is enough on its own.

From network to people: where each layer acts and why none is enough on its own.

1

Network and transport

Firewalls and filtering at the network edge, with TLS protecting all connections to and from the servers.

2

Storage

Data encrypted at rest, with backups and redundancy across servers.

3

People and processes

Team access limited to the minimum necessary, with dedicated authentication and a log of who accesses what. A team in Europe, not outsourced to third-country jurisdictions.

Law before technology

The first layer of privacy is where the data lives.

You can have the best encryption in the world, but if the data is subject to third-country access laws, privacy depends on international agreements that have already collapsed twice and now face a third challenge. At Sooma, data stays in Europe, under the GDPR and European law, with no transfers to the US. Compliance does not depend on any transatlantic agreement.

Why this matters now →

Frequently asked questions

Security & privacy

The most common questions about protecting your messages and data.

Yes. Communication between the user and Sooma's servers is encrypted with TLS, and messages are protected in storage.

There is no analysis of message content for commercial purposes, profiling or advertising. The technical team's access is limited to what is necessary to provide support.

Client data is processed in the EU (Portugal), under the GDPR and Portuguese law, with no transfers outside the European Union. The privacy policy details the categories of data and the retention periods.

Data is backed up regularly and the infrastructure is redundant, so that a server failure does not mean data loss.

The data is subject exclusively to Portuguese and European law. Sooma is not covered by third-country extraterritorial access laws such as the US CLOUD Act, unlike any provider subject to US jurisdiction, wherever its servers are.

Yes, see the Certifications page for the full list and compliance details.

Choose an email built to protect, not to exploit.

60-day money-back guarantee, no questions asked. Assisted migration included.

Talk to the team

Leave us a message

Privacy policy