Law Enforcement Guidelines
Last updated: July 26, 2026
These guidelines describe how SekurMail (Intellect Service Consulting Company, McKinney, Texas, USA) responds to requests from law enforcement and other government authorities. They are informational and do not waive any right or create any obligation. We respond only to legally valid process and narrow requests, and we construe demands consistent with users' rights.
1. The most important fact: SekurMail is zero-knowledge for content
SekurMail is end-to-end encrypted. Message, attachment, profile, and call-media content is encrypted on users' devices; our servers relay and store only ciphertext and routing metadata. We do not possess users' private keys in any form we can use (at most, an encrypted device-linking bundle that only the user's devices can open may transiently exist on our servers), and we cannot decrypt message content. As a result, we cannot produce the content of users' messages, attachments, profiles, or calls in response to legal process — except in the narrow situations described in Section 3 — not because we decline, but because that content is not available to us in readable form. This includes messages addressed to organizations, which are encrypted to an organization's own key that we do not hold.
2. What we can provide (metadata we do hold)
Subject to valid legal process (Section 5), we may be able to provide the following non-content records, to the extent they exist and are retained at the time of the request:
- Basic subscriber information — the account's registered identifiers (email address and/or phone number, stored in cleartext), account creation date, and account status.
- Device information — registered device records (identifiers, labels, an associated email, registration and last-seen timestamps) and public keys. (Private keys are never held by us in usable form.)
- Routing metadata — sender/recipient identifiers, timestamps, message sizes, content-type labels, and delivery/read timestamps for messages transiting or stored on our systems, and forwarding lineage, to the extent retained.
- IP address and user-agent — as recorded in our security/audit log (retained durably).
- Billing identity — for paying users, the payment processor's customer id, card brand and last four digits, and invoice/payment records; for organizations, org name, contact email, and verified domain.
- Abuse/contact signals — records of blocks and abuse reports, and phone-number hashes used for contact discovery (not the plaintext of an address book, which we do not store).
We do not create records we do not otherwise keep. Retention periods are described in our Privacy Policy; some records (for example, session and one-time-code records) are short-lived and may no longer exist by the time a request arrives.
3. Limited exceptions where content may exist
There are narrow situations in which specific content is available to us, and we will disclose it only under valid process:
- Recipient-reported content. When a recipient reports a message, their already-decrypted copy is stored as evidence. That specific reported message may therefore be producible. The disclosure originates from the recipient, not from us decrypting anything.
- Content under legal hold (forced retention). When SekurMail has enabled this control (it is off by default), reported messages are retained as clawback-proof evidence and may be producible.
- Authority export. For an account with such retained report evidence, a security-role operator can produce an evidence bundle; each such export is audited and is a deliberate, attributable human action, never automatic.
- Fingerprint lookup. From a screenshot of a message, an operator can map a short identifier to that message's routing metadata without decrypting content.
- Watermark decode. A leaked screenshot may be attributed to the sending account or the viewing account/device via our forensic watermark. Decoding is a restricted, security-role operator action, and every decode is itself audited.
We will not overstate these. Outside these narrow cases, message content is unavailable to us.
4. What we do NOT have
- Plaintext message, attachment, profile, or call content.
- Users' private keys in usable form, or an organization's private key (held only by that organization's admins; any server-side copy is encrypted such that we cannot open it).
- Passwords (the Service is passwordless; sign-in codes are stored only as short-lived hashes).
- Stored address books, message content of accounts not covered by Section 3, or any ability to wiretap future content in readable form.
5. How to make a request
- Legal standard. We require legal process appropriate to the data sought: a subpoena for basic subscriber records; a court order (e.g., under 18 U.S.C. § 2703(d), where applicable) for certain transactional records; and a search warrant based on probable cause for anything more. Message content we cannot produce regardless of the process served, except as described in Section 3.
- How to serve. Send requests on official letterhead to lawenforcement@sekurmail.com (and, for legal notices, legal@sekurmail.com). Include the requesting agency, officer, callback details, the specific account identifier(s), the records sought, and the legal basis.
- Foreign requests. Requests from outside the United States should be made through a Mutual Legal Assistance Treaty (MLAT), letter rogatory, or other recognized channel, unless a valid legal basis exists otherwise.
- Preservation. We will honor valid preservation requests for records we hold, for the period required by law, pending service of appropriate process.
6. Emergency requests
In an emergency involving a risk of death or serious physical harm, law enforcement may submit an emergency disclosure request to lawenforcement@sekurmail.com describing the emergency. We may disclose information we hold if we believe in good faith that an emergency requires it, consistent with applicable law.
7. Notice to users
Our policy is to notify users of requests for their information before disclosure, so they may seek to protect their rights, except where prohibited by law or court order, or where we believe in good faith that notice would create a risk of harm, or in an emergency.
8. Cost reimbursement
We may seek reimbursement for costs of responding to legal process as permitted by law.
9. Transparency
We intend to publish periodic transparency reports summarizing the number and type of government requests received and how we responded. The best evidence of our data minimization is what we are unable to produce.
Contact for legal process: lawenforcement@sekurmail.com · legal@sekurmail.com · SekurMail (Intellect Service Consulting Company), McKinney, Texas, USA.