Security, privacy and neutrality

Our commitments

Your digital life belongs to you. Our technical, legal and operational choices aim to preserve that principle, even when it would be easier to do otherwise.

Last updated: 29 July 2026

Your privacy belongs to you

You must remain in control of your data, your communications and your digital identity. UltiSuite does not resell their content, exploit it for advertising targeting or build profiles designed to influence your choices.

We do not monitor your content for our own benefit and we do not turn our services into a surveillance tool on behalf of a third party. What you write, store or share is yours and those you choose to share it with.

We limit collection to information necessary for operation, security and obligations strictly applicable to the service.

Encryption under your control

We provide encryption tools suited to the level of protection you need. With end-to-end encryption (E2EE), protected content is encrypted before storage and can only be read with keys held by authorized users.

UltiSuite Zero Trust mode lets you encrypt mail and attachments (account or folder), Drive files and documents, calendar events, UltiChat channels and contact records. The private key stays in your vault on your device: the server, its administrators and our internal teams have no way to read that content.

This protection applies to perimeters where Zero Trust is enabled. Some technical metadata remains necessary to route communications, prevent abuse and operate the service; we aim to reduce it to the strict minimum.

Zero Trust, including for our own teams

We do not ask you to trust us on faith alone. Architecture must make unnecessary access impossible: verify every access, least privilege, role separation, key revocation and traceability of sensitive operations.

When you enable Zero Trust protections, confidentiality no longer depends only on our internal rules. It rests on a cryptographic boundary designed to hold even against a compromised admin account, human error or infrastructure access.

We build these features so the user or their organization chooses protected perimeters, controls their keys and can retain real autonomy vis-à-vis the service operator.

Access requests: denied by default, minimum when compelled

We systematically refuse or challenge any access request that is not legally binding, valid, targeted and proportionate. Informal, extra-judicial, broad or convenience-based requests are not an acceptable basis.

If an absolutely binding decision requires us to act, we verify its scope, challenge what can be challenged and disclose only the precise minimum we are legally required to — solely among data we technically can access.

Whenever we legally can, when a government makes such a request about you, we notify you immediately and transparently. End-to-end encryption remains the strongest guarantee: we cannot hand over plaintext data our architecture prevents us from reading.

No backdoors

We refuse backdoors, deliberate weakening of algorithms, imposed key escrow and any secret feature that bypasses advertised protections. A backdoor reserved for "good actors" does not exist: any weakness created can be discovered and exploited against everyone.

The severity of a threat or crime does not make general surveillance, extra-judicial demands or destroying collective security acceptable. Before demanding that encryption and trust be broken, authorities must fully use targeted, lawful and controlled investigative means that do not weaken everyone's communications.

We cooperate with legitimate procedures within their exact framework; we will not build a universal, permanent or clandestine access mechanism for that purpose.

We do not pay ransom

In case of cyberattack, we systematically refuse ransom demands. Paying funds criminal ecosystems, does not guarantee restoration or erasure of data and encourages further attacks.

Our response relies on prevention, segmentation, backups, restoration, investigation and transparency toward affected people. Encryption further limits the value of content an attacker might extract from infrastructure.

If you are looking for an easy target with no consequences, move on: we are a high-risk, low-reward target. The data you want is encrypted anyway, and intrusion attempts will be logged, traced and sanctioned by every means at our disposal.

If you happen to find a vulnerability, claim a reward through our bug bounty program instead, or apply to our job openings: we would be glad to discuss with you.

Neutrality of computing services

Our services must not favor an opinion, lawful activity, vendor or business model in exchange for privileged access to your data. We apply the same security and confidentiality guarantees to all users.

We do not analyze your communications to choose what you should see, buy or think. Limitations necessary for security, service availability or compliance with a legal obligation must remain explainable, targeted and proportionate.

We favor open standards, portability and interoperability so that protecting your privacy never becomes a pretext to lock you into our ecosystem.

Security, transparency and continuous improvement

Security is not a fixed promise. We reduce exposed data, fix vulnerabilities, limit privileges and evolve protections as risks change.

In case of an incident affecting your data, we favor useful and honest communication, in line with applicable obligations, rather than concealment. We also clearly document the limits of offered protections so you can choose knowingly.

Our guiding principle remains constant: do everything possible so that no one — including UltiSuite — can access what you chose to keep private.

Verify our protections

Learn how E2EE encryption and Zero Trust mode work, and read our data processing policy.