Trust · public audit

Sovereignty audit.

11 dependencies, every one named. 0 from Big Tech.

"Tie your camel."

اعقلها وتوكل

i'qilha wa tawakkal

"Tie it and trust in Allah."

Prophet Muhammad ﷺ · Tirmidhi 2517 · "do your part, then trust"

What follows is the asbab side: every dependency, every jurisdiction, every key custodian, transparently audited. The trust side stays with Allah.

Every "no Google, no Meta, no surveillance" claim we make has to hold at the bytes level, not just in marketing copy. Below is the complete public list of what we run, what we depend on, and what we explicitly do not use. We update this list monthly. If you find a discrepancy between this page and what your browser actually loads, email salaam@ummah.email.

Our public commitment

These are not aspirational. These are commitments we publish so they can be held against us.

  1. No Cloudflare. Ever. We will never proxy, cache, or terminate TLS through Cloudflare. The day we do is the day we cease to be sovereign.
  2. No AWS. No GCP. No Azure. Hetzner Nuremberg (web + webmail + identity) and Hetzner Helsinki (a separate box that does nothing but mail) only. Hetzner virtual servers in EU datacentres, no hyperscaler tenant agreement we cannot read end-to-end.
  3. No Google. No Microsoft. No Meta. No Sendgrid. No Mailchimp. No Hubspot. No Salesforce. No Twilio. If a vendor's business model is harvesting users at scale, they do not touch our stack.
  4. No analytics that send data outside our servers. Self-hosted Matomo only, on our hardware, IP-anonymized, cookieless.

Our poison pill against acquisition

If UMG is ever acquired, all user data is destroyed before transfer. By signing up, every ummah.email member is a party to this commitment. No buyer inherits Muslim data.

This is the asbab side of "tie your camel". We tie the camel against the day we might be tempted to leave it loose. The commitment is written into the user agreement. We disclose it here so the commitment cannot quietly disappear in a future revision.

What we run on our own iron

UMG-controlled infrastructure. No third party between you and us.

UMG mail serverOpen-source mail engine (Stalwart). A Hetzner virtual server in Helsinki, Finland, rented and run by us, doing nothing but mail. Stored mail is not encrypted at rest; see Security.
Ummah Email webmail (webmail.ummah.email)Open-source webmail engine with our Maktub theme. Runs on our web server in Nuremberg, Germany — a separate box from the Helsinki mail server above, reached over IMAP/SMTP.
nginxOpen-source HTTP server. Routes traffic to ummah.email, webmail, and UmmahPass. Same Nuremberg hardware as those.
UmmahPass · LaravelOur identity layer and signup flow. Self-hosted Postgres and Redis. Nuremberg, Germany.
Matomo (analytics.ummahmediagroup.com)Self-hosted, cookieless, IP-anonymized. No Google Analytics.
UmmahCHAT (chat.ummahmediagroup.com)Self-hosted team chat. Internal Ummah Media Group team comms. Runs on its own UMG-owned server in Nuremberg, Germany — not the ummah.email web server and not the Helsinki mail server.
Hosting: Hetzner Online GmbHTwo locations, both EU: Nuremberg, Germany (web, webmail, identity, chat) and Helsinki, Finland (the dedicated mail engine). Both GDPR-binding. Outside US CLOUD Act and FISA 702 absent the relevant EU court order.

What we use that we don't own

The minimum necessary third-party surface. Every vendor named and explained.

StripePayment processing. Card data never touches our servers. KYC and payment regulation makes self-hosting impossible at our scale. Disclosed.
Let's EncryptTLS certificates. Open standard. No tracking surface.
Dynadot (DNS registrar)US commercial registrar. In-progress migration to a secondary anti-surveillance NS provider (Njalla / 1984 Hosting) Sprint 9. Eventual full migration off Dynadot Sprint 18+.
MaxMind GeoLite2 (planned, Sprint 10)Offline IP-to-country DB. No outbound calls per visit. Replaces ip-api.com which leaked visitor IPs to a US third party.

Bunny Fonts was on this list through Sprint 7. As of May 10 2026 it is self-hosted at /fonts/ on every UMG property. Zero outbound font requests on page load. See Sprint 8 transparency report →

What we explicitly do not use

The list every company forgets to publish. Here is ours.

What we default ON

Defaults are choices. We disclose ours.

Outbound email signatureEvery paid ummah.email member's outbound email gets a small footer: Sent from yourname@ummah.email, yours at ummah.email. Plain text. Reversible. Disable here or customize here.
10% sadaqah set-aside$0.50 of every $5/mo is set aside for a Muslim charity; disbursement begins once charity onboarding completes. Non-toggleable, it is part of the offer. See pricing.
UmmahPass identity bridgeYour handle is the same across ummah.email + ummah.me + UmmahPlaces + UmmahCauses + chat.ummah.city. One identity, all surfaces.

Server geography and legal posture

Two server locations, both Hetzner, both EU. The mail engine that stores and processes your inbox (Stalwart, mail.ummah.email) runs on a server physically in Helsinki, Finland — compelling your mail content requires a Finnish court order. The web-facing layer — ummah.email, webmail.ummah.email, UmmahPass, and internal UmmahCHAT — runs on separate Hetzner servers in Nuremberg, Germany — compelling that layer's data requires German legal process. Hetzner Online GmbH (German company, EU-jurisdiction) operates both locations. All of it is subject to GDPR. Whether US law such as the CLOUD Act can reach mail we store in Finland is a question for counsel, and we do not have that answer yet. We are not going to tell you we are out of reach when we have not established it.

UMG corporate is Ummah Media Group LLC, a California limited liability company. We are a US company, so US legal process can be served on us; a separate EU order — Finnish for the mail server, German for everything else — is required to compel data on the European servers. We disclose every such order via the warrant canary below.

Warrant canary

Issued monthly by the Ummah Media Group security office. If a future month's canary is missing, that is the signal: a gagged surveillance order has been received that we cannot publicly acknowledge.

Read the current canary →

Found a discrepancy? Report it.

If your browser loads a request this page does not disclose, that is a sovereignty leak. Email salaam@ummah.email with a DevTools screenshot. PGP key publishing is planned. Bug bounty pool is planned. Right now: email us and we will fix it publicly.

Satisfied? Reserve your handle.

Reserve your handle, $5/mo

No free tier. The 10% only works if the $5 is real.