Trust · transparency report

Transparency report.

Published 2026-09-19. Covers 2026-05-10 to 2026-09-19.

The sovereignty audit is a static, real-time snapshot. This report is the longitudinal record. On a regular cadence we publish: the dependency list as it stood, the jurisdictions our data crossed, and every government request received. We used to run a separate warrant canary alongside this report; as of this publication it is retired and this report carries that disclosure instead — see the section below.

Headline numbers

Government data requests (2026-05-10 to 2026-09-19, this report period)0
National Security Letters received0
FISA court orders received0
US CLOUD Act requests received0
German court orders received0
Finnish court orders received0
Requests from Saudi, UAE, Indian, or Israeli government agencies0
Backdoors added under any compulsion0
Third-party content access grants beyond mail routing0
Direct dependencies on third-party vendors4
Self-hosted infrastructure components7
Big Tech vendors in the stack0

Dependency list (snapshot 2026-05-10)

This dependency, jurisdiction, custodian, and data-flow snapshot is carried forward from 10 May 2026 and was not re-audited for this report. Only the request-count numbers above are current as of 19 September 2026. We are saying so rather than implying a fresh audit we did not run.

The complete public list of every system component, library, and external service we depend on. If your browser loads anything not on this list, that is a sovereignty leak. Email salaam@ummah.email.

System packages and runtimes (self-hosted)

Application frameworks

Third-party vendors (4 total)

Hardware and hosting

What changed this quarter

Jurisdictions data touches

Where your data physically sits, where it is routed, and what legal regime applies at each step.

Key custodians

Who can technically access your data, and under what conditions.

Neither encryption at rest nor end-to-end encrypted mail is in place today. Both are wanted. Neither is built. This page will say otherwise only when each one is actually running.

Data flow diagram

Where bytes move when you use ummah.email. Text representation; hand-drawn for clarity.

Browser (you) │ │ TLS 1.3 (Let's Encrypt cert) ▼ nginx (Hetzner, Nuremberg) │ ├──▶ Static (HTML / CSS / fonts / WOFF2) ← served from disk, /fonts/ self-hosted │ ├──▶ UmmahPass (Laravel + PostgreSQL) ← identity, billing, OAuth │ │ │ └──▶ Stripe (San Francisco) ← cards only, never inbox │ ├──▶ Mail server (Hetzner, Helsinki) ← IMAP/SMTP/JMAP over TLS; stored mail not encrypted │ ├──▶ Webmail (Hetzner, Nuremberg) ← reads from mail server over local socket │ └──▶ Matomo (analytics.ummahmediagroup.com) ← self-hosted, IP-anonymized │ └─ does NOT egress user data anywhere Outside this diagram = sovereignty leak. Report it to salaam@ummah.email.

Warrant canary (retired 2026-09-19)

We published a warrant canary from 2024 until today. It listed the things that had not happened to us, on the principle that if it ever stopped being updated, the silence would tell you what we could not.

We are retiring it, and we want to be plain about why. We did not keep it on schedule. It lapsed by 51 days, then by 53 days, then again this month. This report said it first, above: a stale canary is worse than no canary, because it is the failure it exists to warn you about. Ours had come to send that signal three times for no reason other than our own inattention, not compulsion.

Nothing has happened. As of 19 September 2026 we have received no National Security Letter, no FISA court order, no CLOUD Act request, no German or Finnish court order, and no request from Saudi, UAE, Indian or Israeli government agencies. No backdoor has been added under any compulsion, and no third party has been granted access to user mail content, contacts or routing metadata beyond what delivery requires. The infrastructure described at /sovereignty is accurate as of this date. That is the same statement the canary carried, and it now lives here, in a document we do keep current.

The headline numbers above are the disclosure from now on. /canary.txt continues to resolve, and carries this same retirement notice rather than disappearing.

What's next

The next report is published on a regular cadence; its date is posted here when it is issued.

Planned changes:

Found something we did not disclose? Report it.

Email salaam@ummah.email. We publish corrections to this report (with timestamps) rather than silently editing. The edit log lives at the bottom of the next report.

Reserve your handle.

Reserve your handle, $5/mo

Transparency report · published 2026-09-19. Warrant canary retired the same day.