Letro Private AI · In preview

Every prompt is a disclosure.

When your team uses consumer AI, client matters leave your firm and enter the provider's infrastructure, subject to their monitoring, their retention rules and their legal jurisdiction. Letro Private AI works inside your encrypted Letro environment: an isolated European deployment assigned to your organisation, never used for training, never shared with model providers.

In preview. Early access is limited and prioritised by deployment tier.

No training
On any tier, ever
Europe
Dedicated compute
Per organisation
Isolated environment
Mistral
Deployed & operated by Letro

01 · This is not speculation

Three public facts about cloud AI.

Each one is documented, and none of them is a scandal. They describe how consumer AI services work.

Providers can see what flows through them.

On 10 September 2026, Anthropic published its fourth threat-intelligence report: eight months of platform misuse it identified, reviewed and disrupted, with findings shared with authorities and industry partners. This monitoring is legitimate and necessary. It also means everything entering a consumer AI service sits inside the provider's compliance perimeter, not yours.

Source: Anthropic, September 2026 →

Retention is not yours to control.

In 2025, a US federal court ordered OpenAI to preserve user conversations, including chats users had deleted, as evidence in ongoing litigation. The order was later modified. The point stands: what a provider keeps, and for how long, is decided by the provider and the courts it answers to.

Source: Reuters, 2025 →

The leak is usually an employee, not an attacker.

In 2023, Samsung restricted staff use of generative AI after engineers pasted confidential source code into ChatGPT. No breach was needed. A convenient tool and a deadline were enough.

Source: Bloomberg, May 2023 →

None of these are scandals. They are the architecture of cloud AI: if a provider can write a threat-intelligence report, it can read what flows through it.

02 · What Private AI is

An assistant that works where your formal correspondence already lives.

Letro Private AI runs inside your encrypted Letro environment, bound to verified PostNumber identities. It does three things, and it does them without your client matters leaving your organisation's boundary.

Review documents

Before they are sent or after they arrive: summarise a mandate letter, compare versions, extract obligations and deadlines.

Design workflows

Turn a recurring approval chain (instruction, exact version, sign-off) into a structured, repeatable process.

Draft and communicate

Prepare formal correspondence in your firm's register, addressed to verified counterparties.

Your data is not used to train any model.

Not ours, not anyone's. On any tier.

Your data is never sent to a model provider.

Letro deploys and operates the Mistral models itself, on compute dedicated to this purpose. Mistral, the company, has no access to your data, your prompts or the environment.

03 · How it works, and where

Four steps. One boundary.

1

You share a document or prompt inside your Letro workspace, exactly where the correspondence already lives.

2

It travels encrypted from your device to the AI environment assigned to your organisation.

3

It is processed only there: an isolated environment that Letro deploys and operates, running Mistral models we host ourselves. Content is decrypted only inside this environment, at the moment of processing. No model provider can reach it.

4

The result returns to your workspace. Nothing is used for training.

TierPrivate AI environmentIsolation
CloudLetro-operated AI environment on dedicated European computeOrganisation-scoped access
DedicatedA fully isolated AI environment, exclusive to your organisationFull environment isolation
SovereignPrivate AI is not offered on the Sovereign tier today. See "What we don't claim" for why.

Messaging data at rest remains in Switzerland (Infomaniak). AI processing runs on European infrastructure, outside the Swiss messaging environment.

04 · What we don't claim

Claims you can check. Nothing else.

A page about confidentiality should be as careful with its own language as with your data. These are the things we deliberately do not say.

We don't claim "impossible to read".

No vendor can honestly claim that about any system, and you should be suspicious of the ones who do. We claim something verifiable instead: a defined, per-organisation boundary, stated precisely enough to be checked: who operates it, where it runs, and who can never reach it.

We don't sell "sovereign AI" we can't deliver.

Running serious model inference on customer premises requires GPU infrastructure very few firms can justify. Rather than ship a checkbox, we offer Private AI only where we can guarantee the isolation ourselves: dedicated, Letro-operated European environments. When on-premise inference meets that bar, a Sovereign option ships. Not before.

We don't claim "no logs".

Letro is an evidential platform. The delivery record (who sent what to whom, when) is retained by design, because your regulator expects you to produce it.

We don't claim to beat the largest consumer models at everything.

Private AI is built for document review, drafting and workflow in formal correspondence. For that work, the binding constraint is confidentiality, not benchmark scores.

We don't claim Letro has been penetration-tested by the auditors of Matrix.

The published audits cover the Matrix protocol's cryptography, which Letro is built on (vodozemac, audited by Least Authority in 2022). An independent penetration test of Letro itself, by ImmuniWeb, is underway (September 2026).

External asset managers · Law firms · Trustees and fiduciaries · Family offices

Professionals whose correspondence carries legal weight, and whose duty of confidentiality does not pause when the tool is convenient.

05 · Diligence

The questions your due diligence will ask.

Where is my data processed?

Messaging data is stored in Switzerland (Infomaniak). Private AI processing runs in Letro-operated environments on dedicated European infrastructure, scoped to your organisation. Nothing is processed by a model provider.

Can Letro read the content of my messages?

No. Message content and attachments are end-to-end encrypted (Matrix Olm/Megolm); the server stores ciphertext.

Then what does Private AI see?

What you choose to share with it, and nothing else. Your prompt travels encrypted from your device to the AI environment assigned to your organisation, and is decrypted only inside that isolated environment, at the moment of processing. It is not retained for training, and no model provider can reach the environment.

Is my data used for training?

No. Never, on any tier.

Which companies are involved in running Private AI?

The models are Mistral's, deployed and operated by Letro. Mistral itself has no access to your data. During preview we don't publish infrastructure partner names, because the setup is still evolving; we walk through the full architecture in demos.

What does early access cost?

Private AI preview is included for early-access participants. Standard founding terms apply platform-wide: first 3 months free on every tier, and a 30-day free trial.

06 · Early access

Get early access to Private AI.

Tell us where you'd run it. We onboard in small groups, by tier.

Prefer to see it first?

Book a demo →
Where would you want it to run?
Thank you. You're on the early-access list.We onboard in small groups, by tier, and will be in touch from a Letro address. Want to see it now? Book 20 minutes with us →
Oops! Something went wrong while submitting the form.