In 2019 we investigated CTemplar, a new secure email service that claimed to be, “The most secure & private email service in the world.” We called it a promising service that was worth trying out if you could get your hands on an invitation code. Now, we are revisiting the service for an updated and in-depth CTemplar review.
So let’s begin with the Pros and Cons of CTemplar that we identified in this review:
- Strong encryption standards (4096-bit RSA) with built-in support for end-to-end encrypted emails (using OpenPGPjs)
- 100% open source code
- Based in Iceland, with some of the strongest privacy laws in the world
- Passwords protected by “Zero Knowledge Password” technology
- Zero logs; IP address stripped from emails
- Anonymous signup options (no phone verification)
- Anonymous payment option using Monero
- Self-destructing emails and Dead Man’s Timer
- Can send encrypted emails to non-CTemplar users
- Custom email domains
- Desktop, mobile, and browser apps
- 2FA and anti-phishing support
- 14 day money-back guarantee
- Email Subject line only encrypted in paid plans
- Above-average prices
- Metadata not encrypted (work in progress)
- No support for IMAP/SMTP and third-party email clients (work in progress)
First we will examine the features.
CTemplar features overview
CTemplar uses the proven encryption algorithms of OpenPGPjs to apply end-to-end (E2E) 4096-bit RSA encryption to your email and contacts. All data is encrypted in transit and at rest. The only place the data is decrypted is in your browser or email client. While their encryption is based on PGP, CTemplar offers paid subscribers the ability to encrypt the subject line of messages, a privacy-boost over the other leading PGP-based service, ProtonMail. This is important since hackers seem to be endlessly resourceful in getting into secure services, like this hacker selling email credentials of hundreds of C-level executives with Microsoft email accounts.
Additional interesting features of CTemplar include:
- The ability to sign up for the service anonymously, paying for your account with the Monero cryptocurrency. Pseudonymous payment using Bitcoin.
- Desktop clients for Windows, Mac OS, and Linux.
- Android and iOS mobile apps, with Google-free access to the Android App through F-Droid.
- Open source code.
- Premium accounts with a range of additional benefits.
- The ability to send encrypted emails to non-CTemplar users.
- Dark and Light themes.
CTemplar company history and funding sources
CTemplar is a product of Templar Software Systems Ltd, a Seychelles Limited Liability Company that was founded in 2017. The Seychelles is generally regarded as a privacy-friendly location, with a constitutionally guaranteed right to privacy, no mandatory data retention requirements, and an independent legal system.
CTemplar is a small organization that is completely self-funded and pledges never to accept corporate or government funding. This too should reduce the risk that they can be pressured into sharing data on their customers.
CTemplar servers and data security
Ctemplar stores all your data on servers in Iceland. Iceland has very strong privacy laws, perhaps among the best in the world. Beyond that, the country is not part of the 14 Eyes surveillance alliance, or the international data-sharing MLAT treaties. In other words, like the Seychelles, Iceland is a highly-rated country for online privacy and a good place for your data to be stored. We also see Trust.Zone VPN operating in this same jurisdiction.
This all looks excellent. But what would happen if some high-priced lawyer, or government bureaucrat were to pressure CTemplar to turn over your data? Here’s what the company has to say on the subject,
CTemplar will only comply with valid Icelandic court orders. When presented with a valid Icelandic court order, we will give them your content. Due to our zero access password technology, we do not know your password/passphrase so we are not able to decrypt your emails.
CTemplar technical specifications
CTemplar relies on the OpenPGPjs encryption library for the 4096-bit implementation of PGP they use to encrypt your email and contacts. They are in the process of implementing encrypted metadata as well, which will greatly increase your privacy when using their service. In addition, they use TLS to protect your data while in transit.
CTemplar hands-on testing
I used a free CTemplar account, along with F-Droid version of the Android app, for testing in this review.
Creating a free CTemplar account
You still need to enter an invitation code during the signup process for a free account. Here are three ways you can get one according to their website:
- Request a code from one of your CTemplar contacts who has a paid account
- Send a message to their team: firstname.lastname@example.org
- Contact them on social media
Note: Invitation codes are only needed if you want to signup for the free service. You can signup for any paid plan right away (no code required).
As part of the sign-up process, you can enter a recovery email address. With this, CTemplar can help you regain access to your account. If you don’t enter one and lose your login information, you will permanently lose access to the data in your account.
Note: Instead of entering a recovery email address, you can store your login info in a high-quality password manager like Bitwarden. You’ll find a full range of options in our review of the best password managers.
Signing in to CTemplar
To sign in to your encrypted CTemplar account, just go to their homepage, click the Login button, and enter your login credentials into the respective fields.
The look and feel of CTemplar
Here’s what the CTemplar email view looks like. Nothing fancy, just clean and easy to read.
On the left side of the CTemplar mailbox you’ll find a list of the predefined email folders, along with an Add Folder option for creating your own. As is common with privacy-oriented email services, CTemplar blocks remote content like images by default.
Note: If you are using the encrypted Subjects option, it can make viewing your mailbox clumsy. To get around this, you can decrypt all of the subjects of the current page by clicking on the lock icon.
Here’s the Contact view:
As you can see, the CTemplar interface is menu-based, rather than drag-and-drop. That is, you select one or more items by setting the checkboxes to the left of them, then selecting an option to act on them.
CTemplar doesn’t offer a lot of optional views for your email or contacts, but if you select the General tab in Settings you can switch between light and dark mode, as well as control how many email messages appear on a single page.
Interestingly, there is also an option to write custom CSS (Cascading Style Sheets) that changes how your mailbox appears. This isn’t a capability too many of us are equipped to take advantage of, but certainly opens up possibilities.
Clicking the Settings button in the top right of the window brings you to a large range of settings and other options, including filters, rules, whitelists, and blacklists. If you go to the Security tab in Settings, you’ll be able to adjust some unusual security settings. You have the ability to enable or disable:
- Subjects encryption – Encrypt the Subject line of messages. Only available with paid CTemplar accounts. While I would prefer that the Subject line was always encrypted, the ability to enable this is good motivation to upgrade to a paid plan.
- Contacts encryption – CTemplar doesn’t encrypt contacts by default. If you enable this option, CTemplar will encrypt your contacts for better privacy and security. However, when this is enabled, CTemplar can no longer suggest contacts when you are composing messages. Also, when this is enabled, it will be impossible to search contacts.
- Attachments encryption – CTemplar doesn’t encrypt attachments by default. If you enable this option, message attachments will be encrypted for better privacy and security. However, when this is enabled, CTemplar doesn’t support attachments in the body of a message. Among other things, that means images in the body of messages will automatically be extracted from the body of the message and converted to external attachments.
- Anti Phishing – I’ll let the CTemplar folks explain this one themselves, “The Anti-Phishing phrase allows users to link a custom word or phrase of your choice to your CTemplar account. Once set, if you ever log into your webmail and your Anti-Phishing phrase is either missing or incorrect, you may be the victim of phishing.”
The CTemplar default is to compose messages using an HTML editor in a small pop-up window. The editor has a good range of HTML options, along with some more exotic offerings:
- Encryption for non-CTemplar users – Requires sharing a password with the recipient through an alternate channel. When you send an encrytped message to a non-CTemplar recipient, the recipient receives an email with a link to the CTemplar web client. Once there, the recipient needs to enter the shared password to decrypt and read the message.
- Self Destruct Email (paid plans only) – Configure a message to automatically delete itself on a particular date and time. This only works if both you and the recipient are using CTemplar. You can’t make a message sent to a Gmail account (for example) self destruct.
- Delayed Delivery (paid plans only) – Specify the date and time to send the message.
- Dead Man Timer (paid plans only) – Create a message that will be sent only if you do not log into CTemplar for the specified amount of time. For example, you could use this to send an email containing the login information for your Bitcoin wallet to your children if you were to die or become incapacitated.
Searching for messages in CTemplar
CTemplar offers partial support for searching messages. You can search for email addresses and words or phrases in the Subject line of messages. As of now, May 2021, you cannot search the body of messages.
This is one place where CTemplar (and ProtonMail) fall behind another leading secure email service, Tutanota. Tutanota has been offering full-text search capabilities (searching the bodies of messages as well as the header information) since 2017. Tutanota creates an encrypted search index that is stored on your device.
The email search only needs to decrypt and search this index, rather than each individual message. I’m not going to claim I understand the nuances of the Tutanota approach. I will say that I have been using Tutanota for years and the search works pretty darn well. (See our Tutanota review here)
The CTemplar Mobile Apps
In March of this year CTemplar rolled out their mobile apps. They have an iOS app, along with a standard Android app and an Android app on F-Droid. Here’s what the CTemplar Android app looks like:
The app has 88 reviews in the Play store, with a rating of 3.6 stars out of 5.
Is CTemplar really secure?
CTemplar is more secure than the typical email service. After all, services like Gmail and Outlook.com read your messages to help them send targeted ads your way. That can’t happen with a secure email service like CTemplar, since they cannot decrypt your messages. The fact that your messages are end-to-end (E2E) encrypted is reassuring in the face of stories like this one from May 11, 2021. According to Ars Technica, ransomware crooks posted personal data about individual policemen that was stolen from off the Washington DC Metropolitan Police Department’s servers.
Even if hackers did somehow break into CTemplar’s servers, all they would see is encrypted gibberish instead of your personal data and messages.
That said, there are still aspects of your email and contacts that are not encrypted as of today. Things that are not encrypted by default in CTemplar’s design are:
- Subjects of messages
- Message attachments
- Contact data
This means you will need to look at your threat model and decide if CTemplar is secure enough for your purposes. Beyond the things we just discussed, here are a few additional CTemplar factors to consider:
- CTemplar can be compelled by law to disclose information about their users. As of May 2021, their Transparency Report lists 19 requests for user information. None of those requests were accompanied by an Icelandic Court Order, and none of the requests were granted. This is excellent, but you need to realize that all email services must abide by local laws and CTemplar may need to respond to a valid request in the future.
The route to CTemplar support is through their Help pages. These pages are useful, with almost 70 major entries, many of which include multiple sub-entries. I’ve found them to be very helpful, with the only issue being that it can be tough to find the specific topic you need.
When it comes to reaching the support team, there is a ticket-based system available. In addition, the company has a varied social media presence, including Facebook, Twitter, LinkedIn, and Reddit.
CTemplar cost and pricing plans
CTemplar offers one Free pricing plan, and four paid plans. As you might expect, as you go up through the plans (Prime -> Knight -> Marshall -> Champion) you gain more storage, the ability to send more messages per day, and additional features (including custom domain names). Default pricing is billed yearly; monthly billing is available for a higher price.
The Free plan is a great way to check out the service. If you don’t mind the lack of encrypted Subject lines, the Free plan, with its 1 GB of storage and 200 message a day limit, could be good enough to meet your needs without upgrading.
In my opinion, the two best alternatives to CTemplar are the secure email services I’ve mentioned several times throughout this review: ProtonMail and Tutanota. Both services have much bigger user bases (important for easily exchanging secure messages) and more features than CTemplar.
CTemplar review conclusion
CTemplar is a solid secure email service that has been busy rounding out their offering during this COVID-plagued year. They are worth a test drive if you can swing a free version invitation code. That free version, with its 1 GB of storage, may be all you need.
As with most any other secure email provider, to give yourself the maximum security possible, I strongly urge you to connect to CTemplar through a good VPN with a secure browser.
You can learn more about CTemplar on their website here:
And see these email reviews for other options: