Protect the account
Hashed sign-in passwords, authenticator-based two-factor authentication, one-use backup codes and a device list with session revocation. Verified password recovery signs out existing sessions and preserves 2FA.
INDEPENDENT MAIL. A PERSONAL COMMITMENT.
A place for your conversations, your agents and your own domain. Built with care. Priced to be within reach.
KeyKeeper is operated by Euler's Identity, LLC, part of the wider Key* world. We take responsibility for the service, the choices behind it and the work of making it better.
“Infrastructure we operate” means we administer the application and mail servers. Hosting, DNS and other essential providers still play a role. Independence means taking responsibility for those choices and being clear about them.
WHY BUILD ANOTHER EMAIL SERVICE?
If you want an inbox outside Google’s Gmail or Microsoft’s Outlook ecosystem, you should have more independent choices. We’re building one around a simple idea: your conversations belong to you.
We don’t sell your data to advertisers or data brokers, and we don’t build advertising profiles from your inbox. Paid plans and mail credits support the service. Operational logs and limited usage summaries help us run it and prevent abuse.
Privacy should be affordable. Personal is $1/month, including one custom domain and 10 aliases. Agents can receive and read for free, with prepaid sending from $1. See the plans and limits →
IN PLACE TODAY
Practical protections across the account, inbox, mail infrastructure and recovery process.
Hashed sign-in passwords, authenticator-based two-factor authentication, one-use backup codes and a device list with session revocation. Verified password recovery signs out existing sessions and preserves 2FA.
HTTPS for the web app, verified encrypted connections to our mail services, and TLS required for outgoing SMTP. Sender authentication and domain checks help prevent impersonation.
Mailbox storage and backups are encrypted, and stored mailbox credentials are encrypted separately. These protections use service-managed keys; ordinary mail remains accessible to the service.
Remote images load when you allow them. Received HTML is sanitized and isolated from the application. Uploaded profile photos have embedded metadata removed, without automatic Gravatar lookups.
Agent API keys are checked against stored hashes and can be rotated. Webhooks are signed, sending identities are checked, and recipient limits and bounce controls help contain abuse.
Encrypted backups run on a separate host with no public website. Recovery has been tested through an isolated restore, including mailbox access and attachments. Security fixes and dependency checks are part of release verification.
Standard messages, drafts, subjects and addressing metadata remain accessible to the service. Encryption at rest is different from end-to-end encryption. Essential providers include hosting and DNS services, Stripe for card payments, and IPstack for approximate session-location lookups. Our privacy policy explains what we collect and why.
THE TECHNICAL DETAILS
The technologies we use, where they apply, and who controls the keys. Reviewed September 21, 2026.
Backup retention policy keeps all captures from two days, plus 30 daily, 12 weekly and 12 monthly recovery points as history becomes available. Restore drills are retained separately. The six-hour schedule depends on successful jobs; it is a recovery target.
Storage encryption uses service-held keys. OpenPGP protects the encrypted body according to who holds the recipient’s private key. Standard mail and saved drafts remain accessible to the service.
THE KEY IN KEYKEEPER
OpenPGP is a central part of where we’re taking KeyKeeper. The aim is useful encryption, open formats and more control over your own keys.
The browser composer can encrypt supported message bodies using saved, verified recipient public keys. Reading encrypted mail requires an external OpenPGP client. Attachments are not encrypted by this feature.
Key import and backup, readable fingerprints and key-change notices. Then decryption, signing and signature verification for people and agents, followed by encrypted attachments.
Hardware-backed sign-in and better support for hardware-held OpenPGP keys. These are future directions, after dependable recovery and interoperability; they are not available yet.
Who holds the private key matters. Some agent integrations use service-managed keys; keeping a key under your own control changes who can decrypt the message. Subjects and addresses remain visible to mail systems.
Follow the PGP and agent roadmapHELP SHAPE WHAT COMES NEXT
A better key workflow. A useful privacy control. Something we’ve overlooked. Suggestions, careful criticism and independent security review are welcome.
Write directly to lennart@keykeeper.world. Please keep security reports private.