Client communication that stands as evidence.

End-to-end encrypted messaging with verified identities and tamper-evident records. Swiss-hosted, built for wealth managers, law firms and fiduciaries.

Hosted in Switzerland

End-to-end encrypted

Verified identities (PostNumber)

10-year retention

Letro is a secure, evidential communication platform for regulated client work.

LetroLetters: formal correspondence with a timestamped, tamper-evident record.

PostNumber: one verified identity per person, issued after passport verification.

Organisations: hierarchies, roles and approval workflows built in.

Ordinary channels can't carry regulated work.

Billions in fines

Off-channel messaging has cost regulated firms billions in fines.

No verified sender

Email has no verified sender — impersonation and payment fraud live there.

No proof, years later

Years later, can you prove what was sent, to whom, and when?

Consumer messengers hide everything. Office tools prove nothing. Regulated work needs privacy AND proof.

Privacy and proof, in one platform.

Verified identity

Every account is a PostNumber, issued once after passport verification. No anonymous counterparties.

End-to-end encrypted

Content is encrypted on your device with Matrix. Letro cannot read it.

Evidential record

Every exchange is timestamped and tamper-evident. Retained 10 years, exportable as evidence.

AI-assisted (in preview)

Letro AI drafts, summarises and organises formal correspondence. On Dedicated and Sovereign, it runs inside your own infrastructure.

Enterprise Governance and Access Control

Security does not stop at encryption. Letro adds organisation-aware controls for roles, approvals and policy-driven workflows.

1. Organisation-Aware Structure

Model communication around departments, legal entities, teams and external counterparts.

2. Role-Based Access Control

Define who can view, send, approve, escalate, or administer communications.

3. Approval and Escalation Workflows

Support templates, review steps, escalation paths, and audit-friendly process design.

4. Governance Without Breaking Security

Enterprise controls sit around the workflow; message content stays end-to-end encrypted.

External participants

Your clients don't need Letro.

Reach anyone by email — they get a link to a temporary room, free, no account required. Your clients see the professionalism; you keep the record.

Works for counterparties, co-trustees and one-off contacts: no account and no onboarding on their side.

Who it's for

Built for regulated client work.

Wealth & Asset Management

Onboarding, mandates and reporting with proof of delivery.

Explore →

Law Firms

Privileged exchange that holds up years later.

Explore →

Fiduciaries & Trustees

Settlors, beneficiaries and co-trustees on one clean record.

Explore →

Choose your level of control.

Run Letro on shared Swiss infrastructure, on a dedicated homeserver, or entirely inside your own perimeter.

Cloud

Shared infrastructure hosted in Switzerland. Running in minutes, no setup fee, 10-year retention included.

Dedicated

Your own isolated homeserver on Swiss infrastructure, run and maintained by Letro. Separation without operating anything yourself.

Sovereign

Runs inside your own data centre or private cloud, up to fully air-gapped. Your servers, your perimeter, your control.

Founding offer: first 3 months free

See transparent pricing

Post, email, messaging — then Letro.

1970s

Post

  • Slow
  • Manual tracking
  • Limited reach
  • Some security challenges
1990s

Email

  • Fast, but insecure by default
  • No verified sender identity
  • Spam and phishing exposure
  • No reliable tracking or audit trail
  • Not built for confidential exchange
2010s

Messaging Apps

  • Instant
  • Casual
  • Lack of formality
  • Not connected properly to organizations
Today
  • Verified sender
  • Encrypted content
  • Delivery you can prove
  • Built for organisations

Letro Architecture

Letro is built on Matrix, an open standard for decentralised real-time communication — the foundation for sovereign deployment, federation and end-to-end encryption.

End-to-End Encryption by design

Matrix Olm/Megolm encryption protects one-to-one and group content from intermediaries, including Letro.

Open standard foundation

Open APIs for real-time communication: interoperability, integrations and no single-vendor lock-in.

Federation by design

Homeservers talk directly to each other, so separate organisations stay on separate servers and still communicate.

Air-gapped path for high-security environments

For higher assurance, Letro can run in isolated or air-gapped environments with no internet connectivity.

Penetration test underway

Independent penetration test underway — September 2026. Report available to customers under NDA.

Audited cryptography

Built on Matrix's vodozemac library, independently audited by Least Authority (2022).

Read the audit →Security architecture →

Certification roadmap

Designed to support SOC 2 and ISO 27001 alignment — certification roadmap underway.

Join as a founding firm.

We're onboarding a limited group of founding firms: 3 months free, a direct line to the team, and influence on the roadmap.

See Letro on your own cases in 30 minutes.

Bring a real client scenario. We'll show you the encrypted exchange and the evidential record it leaves behind.