Instantané du 8 octobre 2026 · ICANN APS, champs publics

Candidatures / .proton / PTL2687T-T18174 · publié par l'ICANN le 7 octobre 2026 · instantané du 2026-10-08

.proton

TLD de marque · Spec 13Active

PROTON TECHNOLOGIES LTD, GB Q1·Q25

Contrôle ultime déclaré : Fondation Proton Q108 · Fiche ICANN ↗

§ 1 — Sens de la chaîne Q118·Q120

Proton is our company name, registered trademark and the name of our suite of products created to embody the shared vision of scientists and engineers, committed to protecting freedoms and online privacy, of over 100 million user accounts worldwide.

prəʊtɒn

§ 2 — Mission et objet Q133

Proton was founded in 2014 by scientists who met at CERN, the European Organization for Nuclear Research in Geneva. The brand exists because we believed - and still believe - that the architecture of the internet makes privacy an afterthought, and that fixing this requires people who understand the cryptography, not just the policy. We built an encrypted email first. Over a dozen products later - from email and VPN to cloud storage and video conferencing - over 100 million user accounts have been created on our platform, and more than 100,000 organizations use Proton to communicate, store files, manage passwords, and hold video calls without exposing their data to us or to anyone else. Our encryption is end-to-end. We cannot read user content, even if compelled to do so. Every application we ship is open source and has been independently audited. In 2021, the United Nations Independent Investigative Mechanism for Myanmar recommended that witnesses contact them via secure tools, naming Proton Mail specifically. The non-profit Proton Foundation, whose board includes Sir Tim Berners-Lee, ensures that this mission cannot be sold or redirected. We are applying for .proton to bring our product infrastructure under a single namespace that we operate ourselves. Today, our services depend on registries we do not govern. Proton is one registrant among millions on .com, .me, and .ch, with no contractual lever if a registry changes its policies or acts on a legal order in its own jurisdiction. A domain lost for any reason - lapse, dispute, seizure - falls back into the public pool, where anyone can register it and intercept traffic meant for our users. The probability is low. The impact on users who rely on us for encrypted communications would not be. Under .proton, we are the registry operator. The namespace is closed. No domain can leave our control or be registered by a third party. Phishing campaigns targeting our users rely on registering domains that resemble ours on open TLDs. That will not stop because we operate .proton — attackers will keep registering lookalikes on .com or .net regardless. What changes is the signal we can give our users. Today, there is no simple way for a non-technical person to tell a legitimate Proton domain from a convincing imitation. Under .proton, the rule becomes straightforward: if the address ends in .proton, we issued it. Anything else warrants caution. We still have to pursue takedowns on other extensions — but our users gain a reliable reference point they did not have before. We will operate the registry under Specification 13 as a .Brand TLD. All registrations will belong to Proton Technologies Ltd or its affiliates. We will not open the namespace to outside parties. In practice, this means replacing addresses currently spread across proton.me, protonvpn.com, simplelogin.io, and standardnotes.com with a single namespace - mail.proton, vpn.proton, drive.proton - all under one registry we govern.

§ 3 — Engagements et sauvegardes Q164–Q188

Confiance accrue, risque pour le consommateur, secteur réglementé, déclarations à l'État, préjudice, fonction régalienne Q164–Q169Non à chacune
PIC de sauvegarde volontaires Q170·Q171Aucun · 90 candidatures de la ronde en proposent
Registry Voluntary Commitments Q172·Q173Aucun · 5 en proposent
Critères de TLD de marque confirmés, certificat de marque joint Q180·Q181Oui · certificat non publié
Confirme que la chaîne n'est pas une « generic string » Q183Oui
Déclaration Spec 11 §3(d) Q184

We have reviewed Section 3(d) of Specification 11 of the Base Registry Agreement and do not see a conflict with our application. The word “proton” exists in English as a physics term. We are aware of this. But in the context of internet services, “Proton” has been used exclusively as our company name and trademark since 2014. It does not describe a category of products or services. The situation is comparable to .apple, where the common English word was not considered generic in the context of a technology company’s brand application. We are applying for a closed .Brand TLD. All registrations will belong to Proton Technologies Ltd or its affiliates. There will be no third-party registrants and no secondary market. The protections that Specification 11 was designed to provide are already built into our operating model. Our legal team reviewed the Safeguard Assessment questions (Q164 through Q171) and returned “No” on each one. The string has nothing to do with regulated industries or government functions.

§ 4 — Toutes les autres réponses publiées

Toutes les autres réponses que l'ICANN a publiées pour cette candidature, dans l'ordre du formulaire. Les coordonnées (Q17–Q24) sont laissées à la fiche ICANN.

Q212Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.

Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.

Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.

Q220Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.

Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.

Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.

Q221Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.

Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.

Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.

Q121As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.

As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.

true

Q223By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

true

Q224By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

true