
Security
ECHO is designed to keep your most personal messages safe — not just today, but for decades. Security and longevity are at the core of everything we build.
Every capsule is encrypted with AES-256-GCM, the same standard used by governments and financial institutions. Your data is unreadable without the proper keys.
Each recipient gets a unique, cryptographically secure token. No one can access a capsule without their personal link.
All capsule content is encrypted at rest using AES-256-GCM. Access to decryption keys is strictly limited and audited. We take every measure to protect your data, though server-side encryption means the service technically has access to the keys needed to operate.
Capsules are programmatically locked until their opening date. No early access is possible, even by ECHO staff.
Built on Amazon Web Services with multi-region redundancy. Your data lives in SOC 2 and ISO 27001 certified data centers.
Media files stored on AWS S3 with eleven 9s of durability. Your files are designed to last decades without data loss.
Database snapshots every 6 hours. Point-in-time recovery. Your capsules are never at risk of being lost.
Full GDPR compliance. Data deletion on request. Transparent data processing. Your rights are always respected.
You can export your capsules and all associated media at any time.
Your content always belongs to you. We're just the vault.
It's the most important question you can ask. Here's our answer.
Your capsules are stored across multiple geographic regions with automated failover. Even if one data center goes down, your data survives.
You can download all your capsules and media at any time. Your content is never locked in.
We are building toward a transparent governance model so that ECHO's mission outlives any single person or company.
A dedicated financial reserve ensures that ECHO can continue operating and delivering capsules for decades — even if the business model evolves.