Obsidian SuiteDocumentation
Obsidian Suite: all chapters

Docs / Obsidian Suite / For everyone

Secure messages

A secure message is encrypted mail to anyone, whatever mail service they use. The message is encrypted on the sender's side before it reaches Obsidian Suite, and the key travels only in the link the recipient receives. Obsidian Suite stores the message without being able to read it.

Secure messages are sent by a mail client through the REST API. Sending them from the Obsidian Mail app is coming.

How it works

  1. The sender's mail client encrypts the message (AES-256-GCM, a new key for every message) and uploads only the encrypted data, with the list of recipients and how many days it should stay available.
  2. Each recipient gets a link. The key is in the part of the link after #, which browsers never send to a server.
  3. The recipient opens the link, proves they own their address with a one-time code sent to it, and reads the message in the browser, which decrypts it with the key from the link.
  4. The recipient can reply securely. The reply is encrypted in the browser with the same key, and the sender is told by email that an answer is waiting.

For recipients

  1. Open the link from the email exactly as you received it. If the link is cut short, the page says the key is missing: open the complete link from the email.
  2. Enter Your email address - the one the message was sent to - and click Email me a code.
  3. Enter the 6-digit Code from that email and click Open the message. The code works for 10 minutes; Send a new code gets another one.
  4. Read the message and its attachments. To answer, write in Reply securely and click Send encrypted reply.

The page shows who sent the message and until when it can be opened.

Only the addresses the message was sent to can get a code, and the page gives the same answer for any address, so nobody can find out who the recipients are. Codes are limited: a few wrong tries end a code, and only a few codes can be requested per hour.

Expiry and withdrawal

  • The sender chooses how long a message can be opened, up to the service's maximum (90 days by default).
  • The sender can withdraw a message at any time. After that nobody can open it.
  • Expired and withdrawn messages lose their encrypted data within a day.
  • An expired, withdrawn or unknown message all show the same page: "This secure message is not available."

Opening a message, proving an address and replying are recorded in your organization's audit log.