Private & air-gapped deployment

When connectivity itself is part of the risk model

Run Letro where your policy says it has to run. A managed Swiss rollout, your own cloud, or an environment with no route to the public internet.

In plain terms

The whole idea, in three steps

Letro is the same product in every model. What changes is the boundary — and who holds it.

1

You choose the boundary

Where the homeserver runs, who administers it, and which jurisdictions can reach it.

2

Everything syncs inside it

Clients reach your environment over the Matrix client-server API. Messages stay end-to-end encrypted.

3

Nothing leaves without policy

Federation to other homeservers is a switch you own. Turn it off and the environment is closed.

Deployment models

Four boundaries. Move right as your risk rises

Pick one to see who operates it, where the keys sit, and what may cross.

Cloud — managed deployment

Letro operates the platform on Swiss infrastructure. The shortest path to production.

Runs on
Letro's Swiss cloud
Administered by
Letro, under your policy
Message keys
On your users' devices
Federation
Available
Internet route
Required

Choose this if you want secure, evidential communication without any infrastructure work.

Dedicated private environment

A separate environment for your users, policies and administration. Operated for you, isolated from other tenants.

Runs on
A dedicated Swiss instance
Administered by
Your admins, Letro operations
Message keys
On your users' devices
Federation
Approved homeservers only
Internet route
Required, restricted

Choose this if you need your own retention, identity and admin rules without running infrastructure.

Sovereign — private cloud or self-hosted

Run Letro in infrastructure you control and align it with your own network and monitoring architecture.

Runs on
Your cloud or data centre
Administered by
Your team
Message keys
Your custody
Federation
Your decision
Internet route
Optional, policy-controlled

Choose this if Letro has to sit behind your existing controls — SIEM, backup, identity, egress rules.

Air-gapped or isolated

For environments where internet connectivity is not permitted, or not acceptable as a trust assumption.

Runs on
Isolated infrastructure you control
Administered by
Your cleared staff
Message keys
Your custody, on site
Federation
Off by policy
Internet route
None

Choose this if a route to the public internet is itself the thing you are defending against.

Who this is for

Teams that work offline by rule

Air-gapped deployment is not a preference. Their rules require it.

National security & defence

Classified programmes where the network boundary is set by accreditation, not by convenience.

Cyber-incident response

When the corporate network is compromised, the response team needs a channel that is not on it.

Industrial control & OT

Plant and grid environments where the operational network is segmented by design.

Healthcare protection

Patient data that must stay inside the institution and inside the jurisdiction.

Financial services

Trading, custody and private-client desks with residency and retention obligations.

Law & fiduciary work

Privileged matter files that cannot sit in a vendor's shared cloud.

You are likely a fit if

→Your security policy forbids third-party cloud for this class of data
→An external jurisdiction must have no legal route to your environment
→Your team already runs segmented or classified networks
For IT and security

Deployment is more than hosting

It is not just where the VM sits. Five controls change with the model you pick — which makes this a security decision, not an infrastructure preference.

01
Administration

Who holds admin rights, and whether Letro staff can reach the system at all.

02
Identity integration

How Letro binds to your directory, and how PostNumber verification is issued.

03
Update path

Continuous release, scheduled windows, or offline updates for isolated sites.

04
Logging and backup

Where the evidential record is written, retained, and exported for audit.

05
Jurisdictional reach

Which legal regimes can compel access to the environment — and which cannot.

Discuss deployment

Tell us your boundary. We map the deployment

Send your operating model, network boundary and risk requirements. You get a personal reply from the people who build the deployment — not a sales sequence.

Personal replyNDA on request
Request a security briefing

Bring your network diagram

We map it against the four models and tell you which one your policy actually needs.

Request briefing We use your details only to answer your request. No newsletter.