Skip to content
Security & Privacy

Zero-knowledge architecture. Your data is yours.

Airfree Mail was designed from the ground up with security as a first-class requirement. End-to-end encryption, hardware key support, and infrastructure built to the ISO 27001 standard — because privacy should be the default, not a premium add-on.

Standards we build to — ISO 27001 and SOC 2 Type II certification in progress.

ISO 27001

Information security · in progress

GDPR

EU data protection

SOC 2 Type II

Security & availability · in progress

HIPAA Ready

Healthcare compliance

Security features

Defence in depth, not security theatre

Eight layers of protection — from encrypted transport to zero-knowledge storage to audit trails.

End-to-end encryption

OpenPGP support across all plans. Messages and attachments are encrypted before they leave your device.

2FA — TOTP & hardware keys

Secure your account with TOTP apps (Authy, Google Authenticator) or hardware keys (YubiKey, Passkeys).

SPF, DKIM & DMARC

Automatic SPF, DKIM, and DMARC configuration for all custom domains. Protect your domain from spoofing.

Anti-phishing

Real-time link scanning, display name impersonation detection, and visual warnings on suspicious messages.

Zero ad tracking

No pixel tracking. No link rewriting. No behavioural profiles built from your inbox. Complete reading privacy.

GDPR right-to-erasure

Request complete account deletion under GDPR Article 17. All data permanently erased within 30 days.

Audit logs

Full audit trail of login events, IP addresses, device access, and admin actions on Enterprise plans.

ISO 27001 (in progress)

We are working toward ISO 27001 certification for our infrastructure, with regular penetration testing and independent security reviews.

Security that comes standard

Every plan includes end-to-end encryption, 2FA, SPF/DKIM, and anti-phishing — not just enterprise tiers.

Create secure account →