NerunaCloud

Neruna Cloud Security

Neruna manages settings – not your data

Your email, calendars and contacts stay on your own mail server – or in Microsoft 365. Neruna Cloud only knows what management requires.

01 What lives where

WhatWhereCan Neruna read it?
Email, events, contactsYour mail server – and as an offline copy on the workstationsNo – it never passes through us
Certificate keys, account passwordsNeruna Cloud, encrypted per deviceNo – zero knowledge
Personal backupsNeruna Cloud, encrypted with the vault passwordNo – zero knowledge
Organisation, profiles, groups, devices, signatures, templatesNeruna CloudYes – that's the configuration
Chat messages (if used)Neruna CloudYes, unencrypted, per your retention

02 Principles

Hosted in Switzerland

Neruna Cloud runs in data centres in Switzerland and is subject to Swiss data protection law.

No mail, events or contacts

Neruna Cloud stores no mail, events or contacts – only organisation, profiles and configuration.

The chat: the only exception, and optional

If your organisation uses the chat, messages are kept unencrypted in Switzerland, only as long as you decide (1 day to 3 months). Switched off in the portal, nothing is stored and everything existing is deleted.

Certificates: zero knowledge

Private keys are encrypted in the browser and decrypted only on approved devices – the server can never read them.

Accounts and backups: zero knowledge

Mail account passwords and personal backups are encrypted in the browser or the app – the server can never read them. Server settings are signed, so nobody can redirect passwords.

Keys stay on the device

Every workstation signs in with its own key; the private part never leaves the computer.

One-time codes with a separate PIN

Codes work once and expire; an intercepted email alone is never enough to connect.

Open and verifiable

Neruna Desktop is open source – anyone can check how the app talks to the cloud.

03 Technology

Proven methods, not home-grown crypto.

The details for your IT. How Neruna Desktop itself is built is described on neruna.org.

Technology of Neruna Desktop
  1. Device keysEvery device has its own key pair (ECDSA P-256); the private part never leaves the computer. Sign-in with short-lived tokens.
  2. Connecting with code and PINOne-time codes are valid once and for a limited time; the PIN comes separately. An intercepted email alone is never enough.
  3. Zero knowledgeCertificate keys and account passwords are encrypted per device (ECDH P-256, HKDF, AES-GCM).
  4. Signed settingsAccount server settings are signed – nobody can redirect passwords to another server.
  5. VaultPersonal backups with a key derived from the vault password (Argon2id) and AES-GCM.

04 Questions from IT

Answered briefly.

You'll find the privacy policy of Neruna Cloud on its own page.

Privacy
Where is Neruna Cloud operated?

In data centres in Switzerland; Swiss data protection law applies.

Can Neruna read our email?

No. Email, events and contacts run directly between Neruna Desktop and your mail server – never through Neruna Cloud.

What if a device gets lost?

Block it in the portal. It then receives no more configuration, certificates or account passwords from the cloud.

Who can read the certificate keys?

Only the approved devices. The organisation key is protected by your passphrase; without it or the recovery code nobody can hand out certificates – not even Neruna.

How long are chat messages kept?

As long as you decide: 1 day to 3 months. Switch the chat off and nothing more is stored; existing messages are deleted.

Does Neruna Desktop need the cloud?

No. Neruna Desktop is fully usable without the cloud; the cloud adds central management.

Does Neruna Desktop send data to Neruna?

No usage data. Crash reports only with the person's consent, cleaned of addresses, names, servers and paths, deleted after 90 days.