2 ms·
It's been confirmed in independent audits, and our code and cryptography are open-source, so they can be inspected (https://proton.me/community/open-source http
by protonmail 2y ago
It's been confirmed in independent audits, and our code and cryptography are open-source, so they can be inspected (https://proton.me/community/open-source https://proton.me/community/open-source). It's also been confirmed in court, as we were never able to provide any of our users' email content to the law enforcement (when presented with legal data requests that we have no grounds to contest). Basically, we protect users' data by having no access to it.
Your encryption keys are encrypted with your password (which we don't have access to), so we cannot access or use your keys. Therefore, the server doesn't in fact have access to your private encryption key. Once the files are encrypted with the user’s public encryption key they are no longer accessible to the server or the server’s owner: https://proton.me/blog/zero-access-encryption https://proton.me/blog/zero-access-encryption. For more resources on PGP encryption we recommend this one too: https://proton.me/blog/what-is-pgp-encryption https://proton.me/blog/what-is-pgp-encryption.