Verified delivery on any device
Proof of delivery. Nothing to install.
Send sensitive information to anyone. It opens in the browser they already have, with cryptographic evidence it arrived unaltered.
See SEAL in cybersecurityHealthcare professionals need to send confidential information to patients on any device, with no software to install. SEAL (Secure Edge Application Layer) makes this possible: every MIME part encrypted separately, the message split into fragments so that no single system holds it whole, and evidence for the recipient that it arrived unaltered. No assumptions about recipient infrastructure. In production across Swiss healthcare with Health Info Net (HIN).
800,000+
verified deliveries per month
What SEAL delivers
Tamper-evident from send to open
SEAL (Secure Edge Application Layer) encrypts every MIME part individually with AES-GCM-256, splits the message into fragments and distributes them across the IPFS network. No single system ever holds the complete message, and recipients can be certain that what reaches them is what was sent.
A receipt bound to a person
Recipients can be sure a message has not been altered or intercepted, and can reply securely. Where recipient authentication is enabled, the acknowledgement is bound to the individual who opened the message rather than to a mailbox, with no proxy receipt possible.
Nothing to install, on any device
Recipients receive a link by email, SMS, messenger or QR code. The Web Verification App reassembles and decrypts the message in the browser they already have. No software, no account, no certificates to manage.
Deployable standalone or as part of Verimesh infrastructure
SEAL operates independently within existing messaging infrastructure, wherever tamper-evident delivery is needed. Organisations ready to join the full authenticated exchange ecosystem can upgrade to Verimesh.
How it works
When a sender uses their existing mail client, SEAL encrypts each MIME part individually with AES-GCM-256, splits the encrypted message into fragments and distributes them across the IPFS network. No single system ever holds the complete message, so there is no central store to breach. The recipient receives a link, and the Web Verification App reassembles and decrypts the message in their browser. Evidence and zero recipient effort usually pull against each other: a portal can give you an audit trail, but every recipient needs an account, and S/MIME or PGP give you cryptography, but the far end needs a certificate and a mail client that understands it. SEAL asks the recipient for nothing and still produces evidence.
For technical readers, the diagrams below show the full message flow and data structure. Expand either section to view.
SEAL message flow
SEAL delivery operates in three phases: per-part encryption with AES-GCM-256 as the message leaves the sending organisation, fragmentation and distribution across the IPFS network in transit, and reassembly with decryption in the recipient browser on arrival. The Web Verification App provides the recipient experience with no software installation required.

Email data structure
A SEAL message is stored as encrypted fragments rather than as a single file. Each MIME part is encrypted separately, so body text and attachments are independent objects, and the fragments are content-addressed across the IPFS network. Assembly and decryption happen only at the edge, in the recipient browser, so no intermediate system can read the message or alter it undetected.

What recipients see
When someone receives a SEAL message, they open it in their browser and can confirm it arrived unaltered, with no software to install and no certificates to manage.
Delivery verified
Integrity check passed: message unaltered in transit
- From
- Dr. Maria Huber
- Organisation
- Kantonsspital Zürich
- Sent
- 13 March 2026, 09:14
- Subject
- Patient referral: confirmed
- Delivery receipt recorded for this recipient
- No modifications detected since encryption
SEAL and Verimesh
SEAL is the entry product. It solves the delivery problem: every delivery verified, every message tamper-evident, and nothing for recipients to install. Verimesh is the infrastructure destination: identity management, certificates, credentials, policy engine, sovereign data exchange, transport, and semantic interoperability. Start with SEAL. When your organisation is ready to join, or to lead, the authenticated exchange ecosystem, upgrade to Verimesh.
SEAL can be deployed independently wherever tamper-evident delivery is needed: it does not require the full Verimesh infrastructure.
Explore VerimeshSEAL is the message-layer foundation. Verimesh is the authorisation layer that enforces consent withdrawal across institutions. Together with SEAL, they form the consent enforcement substrate.
Read the consent architecture thesisFully open source
AGPLv3 or later
SEAL: frequently asked questions
What is SEAL?
Does SEAL prove who sent a message?
How does SEAL differ from S/MIME or PGP?
Do recipients need to install anything to open a SEAL message?
Who runs SEAL in production today?
Can SEAL be deployed without Verimesh?
Is SEAL open source?
Ready to add verified delivery to your infrastructure?
Whether you are evaluating secure communication for your organisation or exploring how verified delivery fits your sector, let us talk.