Envelopes
Key exchange
shell.interop.personal
Modern key exchange (X25519) to lock each resource's secret key.
shell.interop.enterprise
Rotation, revocation, and team policies on user keys.
End-to-end encryption
Mail, files, documents, calendar, chat, and contacts: Zero Trust encrypts sensitive content on your device before storage. The server only keeps unreadable content — only your unlocked vault lets you read it.
Hosting on your own infrastructure or in Europe is not always enough: with Zero Trust, even the server administrator or an attacker with access cannot read your protected content — only your unlocked vault on your device can.
On first activation, UltiSuite creates a key pair on your device. The private key stays protected by your passphrase in a local vault — it is never sent to the server. One vault serves the entire suite.
Your private key is passphrase-protected and unlocked for the duration of your session.
The server stores only what is needed to lock each resource — never your private key.
Key compromised? Revoke it and register a new one in a few clicks.
Export or import your vault, or create one key per device according to your policy.
As soon as mail arrives — even if you are not connected — subject, body, and attachments are encrypted with a unique secret key, locked with your public key, then wiped from server memory.
Each email has its own secret key — compromising one message does not expose the others.
Files and sensitive metadata are encrypted like the rest of the message.
Enable Zero Trust on an entire mailbox or only specific folders.
Option to delete the readable version at your mail provider after encryption.
Enable Zero Trust file by file or on a folder tree: content stays unreadable in storage. UltiDocs relies on Drive permissions; UltiCells adds an encrypted sidecar and protected Yjs collaborative sync.
Client-side encryption of a file or subtree — share without delivering plaintext to the server.
Collaborative editing under Drive roles: sensitive content stays tied to authorized collaborators' vaults.
Spreadsheets with encrypted sidecar and encrypted Yjs sync — co-editing without a permanent server-side reader.
Viewer, commenter, editor — access rights and encryption combine, not one without the other.
UltiChat requires the Zero Trust vault on sensitive channels (Matrix E2EE). UltiCal encrypts events on the client. UltiCards protects sensitive contact records — one vault for the entire suite.
« Require Zero Trust » channels: Matrix E2EE + unlocked vault to read and write.
Enable Zero Trust per calendar: event titles and details encrypted on the client.
Sensitive contact records encrypted before storage — CardDAV sync without exposing plaintext.
On UltiChat, verify a new session before trusting it — same zero-trust logic.
On locked perimeters, content and attachments are replaced with ciphertext in the database. Search and AI only access them after decryption in your session — not on the server.
The database and file storage contain only unreadable blocks.
You only see content after unlocking your vault in the interface.
UltiAI only analyzes Zero Trust content after decryption in your browser — plaintext does not go back to the server.
External integrations receive notifications without the plaintext body of locked resources.
The vault and decryption work the same way across all UltiSuite clients — mail, drive, chat, calendar, and editors under your control.
Local vault in the browser, on-the-fly decryption across the suite.
Reinforced local storage depending on your operating system.
Planned parity with the phone's secure vault (Keychain on iOS, Keystore on Android).
No mandatory third party to manage your keys — full sovereignty.
shell.crossPlatform.platformPhone — shell.crossPlatform.caption
For the curious and auditors: an open stack, aligned between server and browser — no proprietary black box.
Key exchange
shell.interop.personal
Modern key exchange (X25519) to lock each resource's secret key.
shell.interop.enterprise
Rotation, revocation, and team policies on user keys.
Message encryption
shell.interop.personal
AES-256 encryption per message, file, or cell — industry standard, unique key per resource.
shell.interop.enterprise
Compromising one resource does not expose others thanks to a secret key per object.
Blind server
shell.interop.personal
Database and file storage: only encrypted content and key envelopes.
shell.interop.enterprise
Search and AI disabled on server-side encrypted fields.
Outside world
shell.interop.personal
OpenPGP to exchange with mailboxes outside UltiSuite.
shell.interop.enterprise
Webhooks and integrations without leaking locked resource content.
Modern client-side libraries, no mandatory native component.
Key locking is identical between the backend and your browser.
Encryption code auditable in ulti-backend and the frontend.
Enable account, folder, file, calendar, or channel — no all-or-nothing.
Zero Trust integrates natively with other UltiSuite apps — same identity, contacts and storage.
Vault, per-account or folder activation, decryption, and protected attachments.
Files & docs
Path-based encryption, UltiDocs and UltiCells with protected collaborative sync.
Team messaging
Zero Trust channels, Matrix E2EE, and verified devices.
Calendar
Protected sensitive events, Zero Trust activation per calendar.
Contacts
Encrypted contact records and secure synchronization.
Policies
Team Zero Trust policies and protected perimeter tracking.
Create your vault, choose a passphrase, and enable encryption where you need it — mail, files, chat, calendar, or documents.