UltiSuite Zero Trust

End-to-end encryption

Your data stays
unreadable on the server.

Mail, files, documents, calendar, chat, and contacts: Zero Trust encrypts sensitive content on your device before storage. The server only keeps unreadable content — only your unlocked vault lets you read it.

Why Zero Trust

Real sovereignty, not just EU hosting

Hosting on your own infrastructure or in Europe is not always enough: with Zero Trust, even the server administrator or an attacker with access cannot read your protected content — only your unlocked vault on your device can.

encryption on your device
100%
secret key per resource
1
server admin read access
0
mail, drive, chat, calendar, docs
Suite
Your vault

Your vault, your passphrase

On first activation, UltiSuite creates a key pair on your device. The private key stays protected by your passphrase in a local vault — it is never sent to the server. One vault serves the entire suite.

  • Vault on your device

    Your private key is passphrase-protected and unlocked for the duration of your session.

  • Only the public key goes to the server

    The server stores only what is needed to lock each resource — never your private key.

  • Rotation & revocation

    Key compromised? Revoke it and register a new one in a few clicks.

  • Multi-device

    Export or import your vault, or create one key per device according to your policy.

Loading demo…
Ultimail

Mail and attachments unreadable on arrival

As soon as mail arrives — even if you are not connected — subject, body, and attachments are encrypted with a unique secret key, locked with your public key, then wiped from server memory.

  • One key per message

    Each email has its own secret key — compromising one message does not expose the others.

  • Attachments included

    Files and sensitive metadata are encrypted like the rest of the message.

  • Per account or folder

    Enable Zero Trust on an entire mailbox or only specific folders.

  • Plaintext copy wipe

    Option to delete the readable version at your mail provider after encryption.

Loading demo…
UltiDrive & editors

Files and documents sealed on the client

Enable Zero Trust file by file or on a folder tree: content stays unreadable in storage. UltiDocs relies on Drive permissions; UltiCells adds an encrypted sidecar and protected Yjs collaborative sync.

  • UltiDrive

    Client-side encryption of a file or subtree — share without delivering plaintext to the server.

  • UltiDocs

    Collaborative editing under Drive roles: sensitive content stays tied to authorized collaborators' vaults.

  • UltiCells

    Spreadsheets with encrypted sidecar and encrypted Yjs sync — co-editing without a permanent server-side reader.

  • Role-based sharing

    Viewer, commenter, editor — access rights and encryption combine, not one without the other.

Loading demo…
Chat, calendar & contacts

Conversations, events, and records under the same vault

UltiChat requires the Zero Trust vault on sensitive channels (Matrix E2EE). UltiCal encrypts events on the client. UltiCards protects sensitive contact records — one vault for the entire suite.

  • UltiChat

    « Require Zero Trust » channels: Matrix E2EE + unlocked vault to read and write.

  • UltiCal

    Enable Zero Trust per calendar: event titles and details encrypted on the client.

  • UltiCards

    Sensitive contact records encrypted before storage — CardDAV sync without exposing plaintext.

  • Verified devices

    On UltiChat, verify a new session before trusting it — same zero-trust logic.

Loading demo…
Blind server

The server can neither read nor search

On locked perimeters, content and attachments are replaced with ciphertext in the database. Search and AI only access them after decryption in your session — not on the server.

  • Opaque storage

    The database and file storage contain only unreadable blocks.

  • Read on your device

    You only see content after unlocking your vault in the interface.

  • Local AI only

    UltiAI only analyzes Zero Trust content after decryption in your browser — plaintext does not go back to the server.

  • Leak-free webhooks

    External integrations receive notifications without the plaintext body of locked resources.

Loading demo…
Where it applies

Web, desktop and mobile

The vault and decryption work the same way across all UltiSuite clients — mail, drive, chat, calendar, and editors under your control.

  • Browser

    Local vault in the browser, on-the-fly decryption across the suite.

  • Desktop app

    Reinforced local storage depending on your operating system.

  • Android & iOS mobile

    Planned parity with the phone's secure vault (Keychain on iOS, Keystore on Android).

  • No cloud key service

    No mandatory third party to manage your keys — full sovereignty.

Loading…

shell.crossPlatform.platformPhoneshell.crossPlatform.caption

Under the hood

Proven algorithms, auditable code

For the curious and auditors: an open stack, aligned between server and browser — no proprietary black box.

Envelopes

Key exchange

shell.interop.personal

Modern key exchange (X25519) to lock each resource's secret key.

shell.interop.enterprise

Rotation, revocation, and team policies on user keys.

Content

Message encryption

shell.interop.personal

AES-256 encryption per message, file, or cell — industry standard, unique key per resource.

shell.interop.enterprise

Compromising one resource does not expose others thanks to a secret key per object.

Storage

Blind server

shell.interop.personal

Database and file storage: only encrypted content and key envelopes.

shell.interop.enterprise

Search and AI disabled on server-side encrypted fields.

Interop

Outside world

shell.interop.personal

OpenPGP to exchange with mailboxes outside UltiSuite.

shell.interop.enterprise

Webhooks and integrations without leaking locked resource content.

  • Browser crypto

    Modern client-side libraries, no mandatory native component.

  • Same server and client logic

    Key locking is identical between the backend and your browser.

  • Open to audit

    Encryption code auditable in ulti-backend and the frontend.

  • Progressive activation

    Enable account, folder, file, calendar, or channel — no all-or-nothing.

Enable Zero Trust across the entire suite

Create your vault, choose a passphrase, and enable encryption where you need it — mail, files, chat, calendar, or documents.

UltiSuite Zero Trust — End-to-end encryption