I've had a 4 char account for years - never did it because they were inherently secure though.<p>They're an American company with an American hosting provider. Only pro accounts use the encrypted email feature set.<p>Here's Lavabit's whitepaper on their process - pretty standard setup:
<a href="http://lavabit.com/secure.html" rel="nofollow">http://lavabit.com/secure.html</a>