I've had a 4 char account for years - never did it because they were inherently secure though.<p>They're an American company with an American hosting provider. Only pro accounts use the encrypted email feature set.<p>Here's Lavabit's whitepaper on their process - pretty standard setup:
<a href="http://lavabit.com/secure.html" rel="nofollow">http://lavabit.com/secure.html</a>
About time to update that VMWare install - <a href="http://status.lavabit.com/export/graphs/graph_401_4.png" rel="nofollow">http://status.lavabit.com/export/graphs/graph_401_4.png</a>