A security tool you can actually check.
We're asking you to route your most sensitive emails through us. Here's exactly what that means: what we hold, what we can't see, and the lines we won't cross.
What we hold
Only the recovery and reset mail sent to your SAFE2RECOVER address, and only for as long as a decision is pending, plus a short, configurable retention afterwards so you have a record. That's it.
What we don't touch
Your normal inbox. Your passwords. The contents of your accounts. We never see them, because they never come to us.
How it's handled
Mail is encrypted in transit and at rest. Access is tightly controlled and logged. Held messages are purged on your schedule. We design for the assumption that we, too, could be a target, so we hold as little as possible, for as short a time as possible.
The design factors we started from
Before a line of this service was built, four factors were fixed: longevity, security, privacy, and the odd one out, the provider deliberately not holding control. Most services accumulate power over your accounts as a side effect of helping you. We designed against that on purpose, because a service that can take over your accounts is one breach away from being the thing that loses them.
The mechanism is split knowledge. What's needed to act is held in two parts: your part and ours. Neither part is usable alone. If our systems were breached, the attacker would hold half of something that does nothing by itself. If your part were stolen, same story. No single breach, theirs or ours, exposes anything that works.
Longevity is on that list for a reason. Recovery protection only counts if it's still standing years from now, so the service is built to run lean and keep running. The less we hold, and the less what we hold can do on its own, the less of us you have to trust. That's the design.
What we'll never do
- Sell your data, or share it with advertisers.
- Train models on your mail.
- Use dark patterns, fake urgency, or make you call to cancel.
What we can't protect, honestly
We guard account recovery. We don't stop every attack: we can't help with a device that's already fully compromised, malware on your own machine, or an account you haven't pointed at us. We'll always be straight about where the edge of our protection is, rather than imply we cover everything.
Official help and reporting
These are the official Australian services. They are free and they are the ones to trust:
- Australian Cyber Security Centre: so you think you have been hacked, a step by step for the hours after a compromise.
- IDCARE, free support for people whose identity or accounts have been misused.
- OAIC: data breaches and your privacy rights, what to do when your details turn up in someone else's breach.