Security Overview

Letro is built as a Proof-of-Service / Digital Registered Delivery platform.

Insights That Drive Secure Communication Forward

Letro is built as a Proof-of-Service / Digital Registered Delivery platform.

Our security design prioritizes:

(1) protecting message content with end-to-end encryption,

(2) minimizing and protecting metadata required for delivery and evidence,

(3) producing auditable, exportable records suitable for regulated workflows.

Core security principles

  • End-to-end encryption by design. Message content and attachments are encrypted on the sender device and decrypted only on recipient devices, using the Matrix protocol with Olm/Megolm encryption.
  • Zero-knowledge orientation. Letro is designed so that internal staff and backend systems do not have access to message plaintext or user private keys.
  • Trustless evidence. Where possible, evidence artifacts (e.g., delivery events) are cryptographically verifiable (e.g., signed records) to reduce reliance on trust in a single operator.
  • Least privilege and auditable operations. Administrative access is limited, time-bound, and logged; security review expects a clear answer to 'who can access what' and why.
  • Swiss data residency. Customer data is hosted in Switzerland. Dedicated and Sovereign deployments give customers further control over where their data lives.

Important definition. In this document, 'content' means message bodies and attachments. 'Metadata' means delivery routing information and system events required to operate the service and produce proof-of-service records.

Where Letro data lives, who operates it, and how each deployment tier changes the answer.

Data Residency & Infrastructure

How Letro detects, contains and resolves security incidents, and how customers are notified.

Incident Response Outline

The third parties that process data for the Letro platform, website and sales process — who they are, what they handle, where, and under which safeguard.

Subprocessors List