Q3 board pack (final)
Hi all,
Attaching the revised deck ahead of Thursday. The revenue section now reflects the updated forecast, and I've folded in the infrastructure notes from Amir.
Happy to walk through it beforehand if that's useful.
Maya
Fose encrypts every message on your device before it is sent. We host the mailbox and run the infrastructure, and we still cannot read a word of it.
Free plan with 2 GB of storage. No card required.
Hi all,
Attaching the revised deck ahead of Thursday. The revenue section now reflects the updated forecast, and I've folded in the infrastructure notes from Amir.
Happy to walk through it beforehand if that's useful.
Maya
Encryption is the foundation that everything else is built on. Fose is made to replace the mail client you use every day.
Bring your own domain and Fose handles the rest. MX, SPF, DKIM and DMARC records are generated for you and checked continuously. Every mailbox on the domain is encrypted the same way.
Create an alias for each shop, newsletter or forum. If one starts attracting spam, switch it off. Your real address was never exposed in the first place.
Scheduled sending, templates, keyboard-first navigation and offline drafts. Encryption stays out of the way, because messages are sealed on your device before they ever reach us.
Anyone can claim their email is secure. Here is precisely what Fose runs, so you can check it against what you already trust.
Ephemeral ECDHE for key agreement and Ed25519 for signatures. A key compromised tomorrow cannot decrypt what you sent today.
Attachments are encrypted in the browser and split into individually authenticated chunks, so file size never weakens the guarantee.
Encryption and decryption run locally. Our servers only ever hold encrypted blobs, so there is nothing on them we could read or hand over.
YubiKey, Titan and any FIDO2 key work for both sign-in and message signing, which shuts down phishing and account takeover.
Independently audited security controls and processes.
Certified information security management system.
Data handling that meets EU data protection standards.
Every plan includes the full encryption stack. Paying only changes how much room you get.
For personal mail
For power users and teams
Everything you need to know about how Fose works. Still unsure? Get in touch.
Fose uses AES-256 for all mailbox contents, with end-to-end encryption ensuring that only you and your intended recipients can read the messages. Our zero-knowledge architecture means we cannot access your data.
To maintain true end-to-end encryption, Fose requires the use of our dedicated email client. This lets us implement encryption in a place we can verify, and guarantee that your communications remain private.
Our client is built from the ground up with security in mind. It features a modern interface, real-time encryption, secure attachments, and privacy features like self-destructing messages and verification of recipient identity.
Because of our zero-knowledge encryption, we cannot reset your password. During account setup you receive a recovery key that you can use to regain access. Keep this recovery key somewhere safe.
Your encrypted data is stored in secure data centres across multiple jurisdictions for redundancy. Our primary operations are based in Belize, whose privacy laws underpin how we handle requests for data.
While you can't connect other email accounts directly to Fose, we provide a secure import tool for migrating your existing mail. Everything you import is encrypted on the way in.
Fose employs X25519 for key exchange and key agreement, combined with Ed25519 for digital signatures. For the initial key exchange we use forward-secret ECDHE, so even if a private key is compromised later, past messages cannot be decrypted.
Attachments are encrypted client-side using AES-256-GCM before upload. Large files are split into encrypted chunks and use streaming encryption to handle files of any size. Each chunk is individually encrypted and authenticated.
Fose implements certificate pinning, DANE (DNS-based Authentication of Named Entities), and strict transport security. We also use subresource integrity checks and maintain a public key transparency log to prevent unauthorised certificate authorities from issuing rogue certificates for our domain.
Yes. Fose supports FIDO2/WebAuthn security keys such as YubiKey and Google Titan, for both account authentication and email signing. We recommend them as the strongest protection against phishing and account takeover.
All encryption and decryption happens locally in your browser using the WebCrypto API. Your private keys never leave your device. The server only ever sees encrypted blobs, and never has access to plaintext data or encryption keys.
We minimise metadata collection and encrypt every metadata field we can, including subject lines and recipient information. Padding and traffic obfuscation guard against timing analysis, and batch processing makes traffic analysis harder.
Start on the free plan and import your existing mail with the encrypted migration tool.