Security you never switch on.

Zero-access storage and post-quantum encryption, on every plan. Here is what they protect.

Can Secria read your mail? Follow one message, start to finish.

  1. 1It arrives

    We don't read your mail, show ads or build a profile. Mail from other providers passes our spam filter as it arrives, then it's locked to your key.

  2. 2It's stored

    Your mailbox is stored with zero-access encryption, locked with a key made from your password on your device.

  1. 3It's sealed for later

    Mail between Secria users, and all mail stored in your mailbox, is sealed with a post-quantum key exchange. Every VPN connection is too.

  2. 4You open it

    Tracking pixels are removed automatically, and senders never see your IP address.

Post-quantum encryption, on every plan. Free included.

Two locks, not one
Keys are exchanged with ML-KEM-1024 and X25519. ML-KEM-1024 is the post-quantum standard NIST published in 2024. X25519 is the proven key exchange used across the web. Someone would have to break both.
A new key for every message
Message bodies and attachments are sealed with AES-256, with a fresh key for each message.
Mail with other providers
When you write to someone on Gmail or another provider, the message travels over TLS, the standard encryption between mail servers. Your own copy is sealed in your mailbox.

What is harvest now, decrypt later?

It is an attack our key exchange is built to stop. Someone copies encrypted mail or traffic today and keeps it. They wait for a quantum computer strong enough to break today's keys. No one knows the year it will come. ML-KEM-1024 is made to hold against it.

When could Q-Day come?

Your connection. And exactly what we keep.

Never recorded
  • Browsing
  • DNS queries
  • Traffic contents
Held while you're connected
  • Your account and device
  • The server in use
  • The time it started

That record is removed when the session ends. Servers run RAM-only, so there is nothing to hand over and nothing persists if a server is powered off.

Every connection starts with a new key, sealed with ML-KEM-1024 and mixed into WireGuard.

No activity logs: we do not record browsing, DNS queries or traffic contents.

How the VPN works

Downloads you can check. Signed post-quantum, every file.

  1. The list

    Every download is listed with its SHA-256 in SHA256SUMS.

  2. The signature

    That list is signed with SLH-DSA, a post-quantum signature (FIPS 205). The signature is SHA256SUMS.sig.

  3. The key

    Check the signature against our public key. On Linux, install.sh checks the key, the signature and the file for you, and stops if any check fails.

release-slhdsa.pub158 bytes
-----BEGIN SLH-DSA PUBLIC KEY-----
IJcg3Bd3khXywaVW8yoUA4UfOCTMMHSmdGd2dnx9Nhvioz4WJ7atEBdDuOmG1Sdx
j0c243rrrnQ2vI48Mp32/Q==
-----END SLH-DSA PUBLIC KEY-----

SHA-256 of this keya4660918748c980dc00b935ed2ede5ef18722a384f15a932e7246e9427b2eddb

Found a security problem? Please tell us first.

Report it

Write to hq@secria.me with what you found and how to repeat it. It is the contact in our security.txt.

This website

No ad trackers, no third-party analytics and no cookies on this website. Our forms are sent through EmailJS.

Who runs Secria

Secria, Inc., a Delaware corporation. Our privacy policy says what we keep and why.

Private from your first email.

Get Secria free