
Security
Encryption is not a luxury, it is your title deed: why sovereignty starts with your private key
Do you own your data or are you merely its custodian? Discover why PGP encryption and digital sovereignty are the only real defence for your company in 2026.
Published updated 3 min read

In the physical world, if someone wants to get into your office, they need a court order or a key. In the digital world, if your data is not end-to-end encrypted, your office walls are made of glass and the lock opens with any key.
Encryption is often confused with “wanting to hide something bad”. At Oksigenia we see it differently: encryption is the only technology that guarantees that your data belongs to you alone. Without encryption, you are not the owner of your information, merely its temporary custodian for as long as whichever provider you happen to use allows it.
“If privacy is outlawed, only outlaws will have privacy.” — Phil Zimmermann, creator of PGP.
Lavabit's sacrifice (2013)
The most powerful story about the importance of controlling the keys is that of Lavabit, the encrypted email service used by Edward Snowden. In 2013, the US government demanded that Ladar Levison, Lavabit's owner, hand over his service's SSL keys.
Handing over those keys meant that the government would be able to read not only Snowden's emails, but those of all its 410,000 users. Levison made a historic decision: rather than betray the architecture of his system and the trust of his customers, he shut the company down.
Levison understood that if he, as the provider, had the technical ability to hand over the keys, the system was not truly secure. This case drove the mass adoption of what we champion at Oksigenia today: encryption where only the end user holds the key.
The architecture of control: PGP and asymmetric encryption
For your company to be sovereign, we need to implement systems in which the “server” is blind. This is where PGP (Pretty Good Privacy) comes in.
Unlike traditional email, where Google's or Microsoft's server can “read” the content to show you advertising or filter spam, asymmetric encryption uses a pair of keys:
- Public key: The one you give to everyone so they can write to you. It is like the letterbox at your home; anyone can drop a letter in, but nobody can take it out.
- Private key: The one that only you hold, protected and out of reach of third parties. It is the only one capable of opening that letterbox.
# Generating sovereignty from the terminal:
$ gpg --gen-key
> Real name: Oksigenia SL
> Email: contacto@oksigenia.com
> Key type: RSA and RSA (default)
> Key length: 4096 bits
# Result: a lock that nobody but you can open.
Why this is vital for a business
If you handle patents, contracts, medical data or business strategies, you cannot rely on the “goodwill” of a corporation.
- Integrity: Encryption guarantees that the message has not been altered since it left your computer.
- Non-repudiation: A PGP-based digital signature ensures that you are the author, with the same (or greater) legal validity as a signature on paper.
- Protection against breaches: If the servers hosting your data are hacked, the attacker will find nothing but unreadable digital noise. Without your private key, the data is useless.
# The logic of real privacy:
if (message.is_encrypted_with(recipient_public_key)):
can_read = recipient_private_key.present()
else:
can_read = "Anyone with server access"
# Which side of the equation do you want to be on?

The Oksigenia commitment
In our Digital Services division, we do not just install software. We configure environments where privacy is the default. We use open-source tools such as Proton for corporate email, and storage systems where encryption happens on your device before anything is uploaded to the cloud.
As advocates of free software, we know that transparent code is the only way to verify that there are no “back doors”. Your right to privacy is the right to your property.

