Security Overview

Letro is built as a Proof-of-Service / Digital Registered Delivery platform.

Insights That Drive Secure Communication Forward

Letro is built as a Proof-of-Service / Digital Registered Delivery platform.

Our security design prioritizes:

(1) protecting message content with end-to-end encryption,

(2) minimizing and protecting metadata required for delivery and evidence,

(3) producing auditable, exportable records suitable for regulated workflows.

Core security principles

  • End-to-end encryption by design. Message content and attachments are encrypted on the sender device and decrypted only on recipient devices, using the Matrix protocol with Olm/Megolm encryption.
  • Zero-knowledge orientation. Letro is designed so that internal staff and backend systems do not have access to message plaintext or user private keys.
  • Trustless evidence. Where possible, evidence artifacts (e.g., delivery events) are cryptographically verifiable (e.g., signed records) to reduce reliance on trust in a single operator.
  • Least privilege and auditable operations. Administrative access is limited, time-bound, and logged; security review expects a clear answer to 'who can access what' and why.
  • Swiss data residency. Customer data is hosted in Switzerland. Dedicated and Sovereign deployments give customers further control over where their data lives.

Important definition. In this document, 'content' means message bodies and attachments. 'Metadata' means delivery routing information and system events required to operate the service and produce proof-of-service records.

How to report a security vulnerability in letro.com or the Letro applications, and what you can expect from us.

Vulnerability Disclosure Policy

Letro is encrypted and evidential. Here is how those two properties fit together.

How End-to-End Encryption and Auditability Coexist

Where Letro data lives, who operates it, and how each deployment tier changes the answer.

Data Residency & Infrastructure