Return to Natrium|
NatriumSecurity Architecture
Request Access
SECURITY WHITE PAPER • REF: NAT-SEC-2026.4 • ZERO-KNOWLEDGE ACTIVE

Natrium Security & Cryptographic Architecture

Natrium is engineered from first principles around a strict zero-knowledge trust perimeter. This document details the technical mechanisms, key derivation pipelines, envelope cryptography, and defense-in-depth measures safeguarding user communications.

Client-Derived Keys

Keys are generated client-side inside the user browser. Plaintext keys are never transmitted over network wires or stored in server RAM.

AES-256-GCM Envelopes

Mailbox records and attachments are encrypted using authenticated 256-bit Galois/Counter Mode, guaranteeing confidentiality and cryptographic integrity.

70+ Engine Threat Detonation

Inbound attachments are analyzed across commercial and proprietary threat intelligence engines before download to eliminate malware execution.

1. The Zero-Knowledge Cryptographic Model

Traditional webmail providers encrypt data “at rest” using server-held master keys. This architecture means employees, cloud service providers, rogue insiders, and state actors holding subpoenas can decrypt and read your communications at will.

Natrium employs a strict Zero-Knowledge Cryptographic Perimeter:

  • Key Derivation: Master encryption keys are computed in memory via salted client-side cryptographic hashing. The server never receives the passphrase or the unencrypted derived key.
  • Subpoena Immunity: If Natrium servers are seized, subpoenaed, or subjected to third-party forensic extraction, our database contains exclusively encrypted ciphertext blobs. We physically, mathematically, and legally cannot decrypt user messages.
  • End-to-End Transit: Inbound and outbound relays enforce modern TLS with mandatory Perfect Forward Secrecy (PFS), preventing retrospective passive decryption.

2. Attachment Threat Screening & Tracker Neutralization

A truly secure email client must protect the user’s physical endpoint as thoroughly as its stored data. Natrium embeds two active defense filters:

Automatic Tracking Pixel Stripping

Marketing organizations commonly embed 1x1 transparent GIFs and CSS tracking beacons to monitor user IP addresses, location, and open timestamps. Natrium sanitizes all incoming HTML bodies, neutralizing telemetry beacons before content is rendered on screen.

Multi-Engine Sandbox Inspection

Inbound attachments are evaluated against 70+ threat intelligence engines via automated sandbox detonation. Known CVE exploits, weaponized macros, and malicious executables are flagged and contained before they reach your local file system.

3. Perimeter Hardening & Vulnerability Disclosure

Natrium operates under strict cryptographic transparency and defense-in-depth:

  • DNSSEC Chain of Trust: Public DNS zones are cryptographically signed with DNSSEC (`AD=true`), immunizing resolvers against DNS cache poisoning and BGP hijacking.
  • RFC 9116 security.txt: We publish an RFC 9116 security contact manifest at /.well-known/security.txt with public PGP disclosure keys.
  • Content Security Policy (CSP): Strict nonce-based CSP directives eliminate inline script injection, prototype pollution, and cross-site scripting (XSS).

Experience Verifiable Privacy

Join the vetted community communicating with mathematical confidence and zero corporate surveillance.

Request AccessHome