I've had a 4 char account for years - never did it because they were inherently secure though.
They're an American company with an American hosting provider. Only pro accounts use the encrypted email feature set.
Here's Lavabit's whitepaper on their process - pretty standard setup:
http://lavabit.com/secure.html