Security you can audit.
Pulsar Mail is built for people who read the fine print. This page is the fine print, written in the plain style we wish everyone would use. If you need a full SOC 2 or ISO 27001 report, or a signed DPA, write to .
Encryption at rest
AES-256-GCM on every stored message and attachment. Per-tenant keys derived via HKDF from a hardware-rooted master. Keys never leave the HSM boundary.
Encryption in transit
TLS 1.3 only, HSTS preload, modern cipher suites, MTA-STS + DANE where the recipient supports them. Certificate transparency monitored.
S/MIME and OpenPGP
First-class message-level encryption. Import your S/MIME certificate or generate an OpenPGP key inside Pulsar. Autocrypt-friendly.
Zero telemetry, zero trackers
No page analytics. No pixel loading. Remote images proxied through our resizer to strip trackers. Read receipts blocked by default.
GDPR, DPA, ISO 27001 roadmap
GDPR compliant by design. Full data-processing agreement available on request. ISO 27001 audit in progress; report expected in 2027.
EU-hosted infrastructure
Customer data lives on our own hardware in France and the Netherlands. We are pursuing an AS number so you can pin traffic to Pulsar-operated network too.
Own your archive
Full mbox export on demand. Bring your own S3-compatible bucket (Backblaze B2, Cloudflare R2, MinIO, AWS S3). Portable by design.
Vulnerability reporting
Email — PGP key on our security.txt. Safe-harbour terms and bug-bounty details published as we scale the program.