IncaMail

from Wikipedia, the free encyclopedia
Globe icon of the infobox
IncaMail
Website logo
Secure email service
languages German, English, French, Italian, Dutch
operator Post CH AG
On-line 2006
https://www.post.ch/incamail

IncaMail is the Swiss Post's e-mail service for the electronic exchange of information or documents that require protection. IncaMail is offered worldwide in integrated solutions and is officially recognized as a secure delivery platform by the Swiss Department of Justice and Police . The encryption is carried out using a proprietary technology (Secure Attached File Encryption).

technology

IncaMail can be used via the IncaMail web interface or as an integrated solution in the most common e-mail clients (e.g. MS Outlook , MS Office 365 ) or software (e.g. SAP , Abacus ). The data is encrypted using the patented SAFE technology (Secure Attached File Encryption). The SAFE technology allows existing e-mail addresses to be used in communication, so there is no need to exchange keys between sender and recipient. The recipient receives an e-mail signed by Swiss Post in which the confidential information (including attached documents) is located as an encrypted attachment. He opens this attachment directly with his IncaMail password in his personal mailbox (e.g. Gmail , Bluewin, etc.). The procedure ensures that no data is stored on the IncaMail platform and that third parties cannot see the content of the messages. The dispatch of the IncaMail messages is documented by Swiss Post and can be verified at any time.

Shipping methods

IncaMail users have three different shipping methods available:

Confidential

In the case of confidential transmission, the message is encrypted and transmitted to the recipient. The sender optionally receives a delivery confirmation via email. The recipient does not have to register in order to read the confidential e-mail, but can verify himself by e-mail with a security code. Recipients with a business customer contract receive the message as a normal e-mail via an encrypted connection and can read it without any further precautions.

Personally

When sending in person, the message is encrypted and transmitted to the recipient. The sender optionally receives a delivery confirmation via email. The recipient must register once to read the personal e-mail and have at least verified his or her e-mail address using an activation code. If the recipient is not yet registered on IncaMail, he will be prompted to do so as soon as he wants to open the personal email.

Registered mail

When sending by registered mail, the sender and recipient receive digitally signed PDF receipts with which the sending and receipt of the message can be verified. Messages must be accepted by the recipient within 7 days, otherwise they will expire. The shipping method can be used in the context of communication with the Swiss authorities and corresponds to the relevant legislation.

functionality

Incamail does not allow end-to-end encryption for private users. Especially when using the Incamail app, messages are written on the sender's device and only transmitted to Incamail in TLS-encrypted form when they are sent. Incamail then decrypts the mail on its own servers and then re-encrypts the mail using an undisclosed method. If the recipient of a message does not have his own Incamail account, he has sent a notification to his email address and can then request a PIN code from Incamail for decryption. Incamail will send the pin code to the same email address to which the encrypted message was sent. The subject of the mail is always transmitted unencrypted and supplemented with the addition "(Secured by IncaMail)".

Areas of application

Use from the online service

The IncaMail online service is aimed at private and small businesses (e.g. lawyers) who want to send confidential information or documents in encrypted form and verifiably by email. Any email address worldwide can be written to via the IncaMail online service. With the basic account, users send ten confidential or personal messages per month free of charge, after which they have access to the paid premium account, with which unlimited communications can be encrypted. The receipt of encrypted e-mails and the first reply are always free of charge with both accounts.

Use from the business software

IncaMail has flexible interfaces and can be connected very easily to a wide variety of business software. IncaMail is already integrated in a large number of HR applications and government software and can be used by business customers. These send important documents to any recipient directly from the software at the push of a button.

Examples of important documents:

  • Payroll accounting
  • Time sheets
  • Salary certificate
  • Pension fund cards
  • Commercial register extracts
  • Tax bills
  • Court rulings
  • additional

IncaMail fulfills the legal framework that must be complied with when sending pay slips electronically. Relevant are v. a. the Data Protection Act and the data protection regulations under labor law (Art. 328b OR). When sending pay slips electronically via the Internet, the relevant data must be protected against unauthorized processing by appropriate technical and organizational measures in accordance with Art. 7 Para. 1 DSG.

Use from the email client

IncaMail can be connected to the e-mail clients MS Outlook , Mozilla Thunderbird and Lotus Notes . Add-ins are available for these e-mail clients, with which the sender can communicate in encrypted form with just one push of a button from the respective application. With the integration of IncaMail into the e-mail client, business customers send confidential information and sensitive documents from their usual e-mail infrastructure without having to switch to another e-mail service.

Examples of confidential information and documents:

  • contracts
  • Strategy papers
  • Offers
  • additional

Data security and certifications

IncaMail's information security is based on the certified establishment of an information security management system (ISMS) in accordance with ISO / IEC 27001: 2013 (Information Technology - Security Techniques - Information Security Management Systems - Requirements). According to the legal requirements, IncaMail is officially recognized in Switzerland as an officially approved delivery platform for electronic legal transactions in proceedings before courts and authorities (e-government). The accreditation as a recognized delivery platform requires not only the fulfillment of architecture and technical security requirements but also the fulfillment of high operational requirements (information security and IT service management). When handling customer data, Swiss Post is bound by Swiss postal and telecommunications secrecy and, with IncaMail, also fulfills the confidentiality level prescribed in the Swiss banking world, in the insurance industry or in the legal profession (banking secrecy, securities dealer secrecy, insurance secrecy, attorney's secret). The auditing company KPMG confirms that the operation of the IncaMail platform meets the requirements of the Swiss Financial Market Supervisory Authority FINMA according to FINMA circular 2008/7 “Outsourcing Banks” (revised December 2012).

Naming

The letters INCA stand for the four security features of IncaMail:

Integrity (change protection): The messages remain unchanged. Post CH AG ensures that the data is not changed during transport.

Non-repudiability (non-repudiation): Sending and receiving of IncaMail messages are verifiable and are documented by IncaMail. In the case of registered mail, the sender receives proof as a digitally signed receipt with a time stamp.

Confidentiality (access protection): The data cannot be viewed by third parties. IncaMail transmits all data using an encrypted connection.

Authentication (protection against forgery): Users are identified by specifying their email address or postal address when registering for the first time and by entering the corresponding activation code.

Individual evidence

  1. IncaMail website of Post CH AG. Retrieved July 24, 2017.
  2. Recognized delivery platforms ( Memento of June 8, 2015 in the Internet Archive ) Website of the Swiss Federal Administration. Retrieved July 23, 2017.
  3. a b c IncaMail - Security website of Post CH AG. Retrieved July 24, 2017.
  4. IncaMail - How the Post CH AG website works. Retrieved July 24, 2017.
  5. IncaMail help - Confidential dispatch type Website of Post CH Ltd. Retrieved July 24, 2017.
  6. IncaMail help - personal shipping method Post CH Ltd website. Retrieved July 24, 2017.
  7. IncaMail help - Registered mail delivery method Website of Post CH Ltd. Retrieved July 24, 2017.
  8. IncaMail - web interface website of Post CH AG. Retrieved July 24, 2017.
  9. IncaMail - partner website of Post CH AG. Retrieved July 24, 2017.
  10. IncaMail - Enterprise Application Integration Website of Post CH AG. Retrieved July 24, 2017.
  11. More options with Abacus payroll accounting in 2017 with secure e-mail dispatch on the Post CH AG website. Retrieved July 24, 2017.
  12. Federal Act on Data Protection (DSG). Website of the Swiss Confederation. Retrieved July 9, 2017.
  13. IncaMail - electronic business communication, individual mailing website of Post CH AG. Retrieved July 24, 2017.