Regulatory alignment

Alignment, not blanket claims

Built to support regulated communication — without pretending every deployment is automatically compliant. We call a framework supported only where it genuinely is.

FADP
GDPR
DORA
NIS2
HIPAA
eIDAS
What we mean

Aligned architecture. Compliance is still yours.

Letro's architecture supports regulated communication. Actual compliance depends on how a deployment is run — a sovereign data centre or a dedicated server changes the answer, and so does each firm's own governance.

So we map controls case by case instead of printing a badge.

Control areaLetroYou
Encryption and protocol
Hosting and data residency
Access and identity controls
Retention and archiving tools
Configuration of your instance
Internal policy and governance
Incident response and reporting

Most rows need both sides. That is why compliance is mapped per deployment, not claimed on a page.

At a glance

Seven frameworks, plainly

FrameworkApplies toWhat it asks forWhere Letro fits
FADPSwitzerlandLawful processing and real data security under Swiss law.Swiss hosting and Swiss-bound deployment options.
GDPREU / EEAPersonal data transfers outside the EEA are restricted.Region-bound rooms, private deployments, selective federation.
DORAEU financeDigital resilience against ICT disruption and cyber incidents.Federated fabric you can host and operate yourself.
NIS218 EU sectorsCyber risk management, incident reporting, resilience.Communication brought inside the security perimeter.
HIPAAUS healthCloud is allowed for ePHI — safeguards still apply.Deployment model and access governance under your control.
SEC / FINRAUS financeBusiness communications kept as books and records.Retention and governance answered per deployment.
eIDASEU documentsHarmonised e-signatures, timestamps and trust services.Timestamped, tamper-evident document exchange, designed with eIDAS in mind.

Select a framework for the detail below.

In detail

The rule, and where Letro fits

01

FADP and Swiss data protection

The rule

The revised Swiss Federal Act on Data Protection has applied since 1 September 2023. It requires lawful processing, transparency and data security appropriate to the risk.

Where Letro fits

Letro is hosted in Switzerland with Infomaniak, and every deployment model can be kept Swiss-bound — from the shared cloud to your own infrastructure.

02

GDPR and international transfers

The rule

GDPR makes cross-border data movement an architecture question. The EDPB is explicit that transfers of personal data outside the EEA are restricted.

Entities subject to U.S. jurisdiction are generally required to comply with a valid subpoena from a court, grand jury or authorised government body — including for data held overseas, under the CLOUD Act.

Where Letro fits

Letro supports region-bound rooms, private deployments and selectively federated collaboration instead of forcing every conversation into one global tenant. Your data can reside in Switzerland with a Swiss provider, or in your own infrastructure.

03

DORA and operational resilience

The rule

DORA entered into application on 17 January 2025. It is designed to strengthen the digital resilience of banks, insurers, investment firms and other financial entities against ICT disruptions and cyber incidents.

Where Letro fits

Letro is not a single closed communications silo. It is an open, federated fabric built on Matrix, and the homeserver can be installed and operated by the organisation itself rather than only consumed as a shared vendor service.

Room-level power controls support role separation and controlled administration; identity-provider integration is scoped per deployment.

04

NIS2 and critical sectors

The rule

NIS2 creates a common EU cybersecurity framework across 18 critical sectors and raises expectations around cyber risk management, incident reporting and resilience.

Where Letro fits

For organisations in or around those sectors, communication tooling is no longer outside the security perimeter. Letro is built to sit inside it — encrypted, deployable on your own terms, and governed like the rest of your stack.

05

HIPAA and cloud use

The rule

HHS is clear that HIPAA-regulated entities can use cloud products and services for ePHI, but the security and contractual responsibilities still apply.

Where Letro fits

That makes deployment model, safeguards and access governance central to procurement. In Letro all three are choices you make — cloud, dedicated or sovereign — rather than defaults we impose.

06

SEC / FINRA communications governance

The rule

Recordkeeping is a live enforcement issue. In August 2024 the SEC announced more than $390 million in combined settlements in one recordkeeping sweep, and FINRA continues to treat business communications as part of books-and-records obligations.

Where Letro fits

For this audience, secure communication is not enough on its own. Governance and retention questions matter too, and we work through them with you deployment by deployment.

07

eIDAS and digital documents

The rule

Where signatures, timestamps or electronic documents are part of the workflow, eIDAS is the key EU reference. The Commission notes that it harmonises e-signatures and trust services across Europe, and that electronic documents cannot be denied legal effect solely for being electronic.

Where Letro fits

Letro carries hierarchy, access levels, workflows and controlled document handling, so documents stay in the same timestamped, tamper-evident channel as the conversation — designed with eIDAS and QERDS in mind.

Control areas

How Letro supports alignment

Five control areas carry the story. Each one is something a security team can inspect.

Encrypted content

Message content is end-to-end encrypted, not merely encrypted in transit.

Deployment choice

Cloud, dedicated, sovereign or air-gapped — the residency question is yours to answer.

Access control

Hierarchy, access levels and room-level power controls, scoped to how your organisation is structured.

Structured workflows

Instructions and approvals move as steps, so the record follows the process.

Documents and records

Controlled document handling with a timestamped, tamper-evident record, in the same channel.

How we talk about regulation

We describe a framework, certification or deployment option as supported only when it is genuinely available in the deployment being discussed.

That keeps the Trust Center useful to security teams and credible to procurement.

Discuss your regulatory requirements

Tell us which frameworks matter to your organisation. We map the controls, deployment choices and open questions clearly.