The sovereignty audit is a static, real-time snapshot. This report is the longitudinal record. On a regular cadence we publish: the dependency list as it stood, the jurisdictions our data crossed, and every government request received. We used to run a separate warrant canary alongside this report; as of this publication it is retired and this report carries that disclosure instead — see the section below.
Headline numbers
Dependency list (snapshot 2026-05-10)
This dependency, jurisdiction, custodian, and data-flow snapshot is carried forward from 10 May 2026 and was not re-audited for this report. Only the request-count numbers above are current as of 19 September 2026. We are saying so rather than implying a fresh audit we did not run.
The complete public list of every system component, library, and external service we depend on. If your browser loads anything not on this list, that is a sovereignty leak. Email salaam@ummah.email.
System packages and runtimes (self-hosted)
- Ubuntu 24.04 LTS, OS on all UMG servers
- nginx 1.24, HTTP server / reverse proxy
- PHP 8.4-fpm, Laravel application runtime
- Python 3.12, FastAPI dashboard, automation scripts
- PostgreSQL 16, identity, profiles, business data
- MySQL 8.0, legacy WordPress, dashboard internals
- Redis, sessions, cache, queues
- Open-source mail engine, IMAP/SMTP/JMAP, our hardware
- Open-source webmail engine (Maktub theme)
- Matomo, self-hosted analytics, IP-anonymized, cookieless
- Self-hosted team chat, internal team comms
Application frameworks
- Laravel 12, UmmahPass, UmmahCauses, UmmahPlaces, ummah.me
- FastAPI, UMG Dashboard
- Tailwind CSS, styling (compiled, self-hosted)
- Alpine.js, client interactions (self-hosted minified bundle)
- Stripe.js, payment widget (loaded from Stripe origin only on checkout pages)
Third-party vendors (4 total)
- Stripe Inc. (US), payment processing only. Card data never touches our servers.
- Let's Encrypt / ISRG (US non-profit), TLS certificates. Open standard, no tracking.
- Dynadot LLC (US), DNS registrar. Migration to anti-surveillance NS provider (Njalla / 1984) planned Sprint 9.
- MaxMind GeoLite2 (US), offline IP-to-country DB. Planned Sprint 10. No per-visit calls.
Hardware and hosting
- Hetzner Online GmbH (DE), virtual servers in Nuremberg, Germany (web + webmail + identity) and Helsinki, Finland (mail engine). Not bare metal or dedicated hardware.
- EU jurisdiction. GDPR-binding. German and Finnish data protection law. See /sovereignty for what US legal process can and cannot reach.
What changed this quarter
- 2026-09-19, warrant canary retired. Its disclosures move into this report; see the Warrant canary section below.
- 2026-09-10, false encryption-at-rest, bare-metal, and jurisdiction claims removed from /security, /sovereignty and this report. Stored mail is not encrypted at rest; UMG corporate is a California LLC; whether US law reaches mail stored in Finland is unresolved and we say so rather than claim otherwise.
- 2026-05-15, homepage v2 launch: Sovereign Seal mark adopted, full v2 brand kit (cream surfaces, Inter primary, forest accent). v1 dark hacker aesthetic retired. Trust pages migrated to v2 same day.
- 2026-05-10, Bunny Fonts (BunnyWay d.o.o., Slovenia) removed from third-party list. Self-hosted at
/fonts/on every UMG property. Net dependency count: 12 → 11. - 2026-05-10, CSP
font-srcandstyle-srchardened to'self'on ummah.email, ummahpass.io, ummahcauses.org. Bunny.net removed from allowlist. - 2026-05-10, public commitment + acquisition poison-pill clause added to /sovereignty.
- 2026-05-09, SPF/DKIM/DMARC sweep across 25 Dynadot-owned UMG domains. 8 domains hardened. ummah.email DKIM verified end-to-end.
- 2026-05-09, muslimtorrents.com + ummahmediagroup.com NS migration off legacy GoDaddy nameservers (NS-drop incident response). Both zones rebuilt at Dynadot.
Jurisdictions data touches
Where your data physically sits, where it is routed, and what legal regime applies at each step.
- Helsinki, Finland: Primary mail server (Hetzner FI, virtual). Inbox storage. Finnish data protection law + GDPR.
- Nuremberg, Germany: Web, webmail and identity servers (Hetzner). German BDSG + GDPR.
- Falkenstein, Germany: Backup target (Hetzner FSN). German BDSG + GDPR.
- San Francisco, USA: Stripe (payment processing only). Card data, billing email. Never the inbox content. US PCI-DSS, CA Consumer Privacy Act.
- Slovenia (deprecated this quarter): Bunny Fonts CDN. As of 2026-05-10 we no longer route font requests outside our servers. Removed.
- San Mateo, USA: Dynadot DNS registrar (control plane only; queries are public DNS). Migration to anti-surveillance NS provider planned Sprint 9. US.
Key custodians
Who can technically access your data, and under what conditions.
- Ummah Media Group LLC: root SSH on the mail server. Stored mail is not encrypted at rest, so this is direct access to mail content. There is no key we hold that would change that.
- Ummah Media Group LLC (again): identity layer keys (UmmahPass JWT signing, OAuth client secrets, Passport personal-access keys). No third party holds these.
- Stripe Inc.: cardholder data and payment metadata. Required by KYC and PCI-DSS. Never the inbox.
- Hetzner Online GmbH: operates the hardware our servers run on. Because stored mail is not encrypted at rest, disk access is content access. They could in theory image disks under legal compulsion (zero such requests this report period, see below).
- Let's Encrypt: signs our public TLS certificates. Cannot read user traffic; only attests our domain control. No per-user surface.
Neither encryption at rest nor end-to-end encrypted mail is in place today. Both are wanted. Neither is built. This page will say otherwise only when each one is actually running.
Data flow diagram
Where bytes move when you use ummah.email. Text representation; hand-drawn for clarity.
Warrant canary (retired 2026-09-19)
We published a warrant canary from 2024 until today. It listed the things that had not happened to us, on the principle that if it ever stopped being updated, the silence would tell you what we could not.
We are retiring it, and we want to be plain about why. We did not keep it on schedule. It lapsed by 51 days, then by 53 days, then again this month. This report said it first, above: a stale canary is worse than no canary, because it is the failure it exists to warn you about. Ours had come to send that signal three times for no reason other than our own inattention, not compulsion.
Nothing has happened. As of 19 September 2026 we have received no National Security Letter, no FISA court order, no CLOUD Act request, no German or Finnish court order, and no request from Saudi, UAE, Indian or Israeli government agencies. No backdoor has been added under any compulsion, and no third party has been granted access to user mail content, contacts or routing metadata beyond what delivery requires. The infrastructure described at /sovereignty is accurate as of this date. That is the same statement the canary carried, and it now lives here, in a document we do keep current.
The headline numbers above are the disclosure from now on. /canary.txt continues to resolve, and carries this same retirement notice rather than disappearing.
What's next
The next report is published on a regular cadence; its date is posted here when it is issued.
Planned changes:
- Dynadot → Njalla / 1984 Hosting NS migration on at least 5 UMG domains.
- MaxMind GeoLite2 offline DB replaces ip-api.com calls in the dashboard.
- Independent Muslim-led security audit kicks off.
- A full re-audit of the dependency, jurisdiction, and custodian sections above (last done 2026-05-10).
Found something we did not disclose? Report it.
Email salaam@ummah.email. We publish corrections to this report (with timestamps) rather than silently editing. The edit log lives at the bottom of the next report.