When connectivity itself is part of the risk model
Run Letro where your policy says it has to run. A managed Swiss rollout, your own cloud, or an environment with no route to the public internet.
The whole idea, in three steps
Letro is the same product in every model. What changes is the boundary — and who holds it.
You choose the boundary
Where the homeserver runs, who administers it, and which jurisdictions can reach it.
Everything syncs inside it
Clients reach your environment over the Matrix client-server API. Messages stay end-to-end encrypted.
Nothing leaves without policy
Federation to other homeservers is a switch you own. Turn it off and the environment is closed.
Four boundaries. Move right as your risk rises
Pick one to see who operates it, where the keys sit, and what may cross.
Cloud — managed deployment
Letro operates the platform on Swiss infrastructure. The shortest path to production.
Choose this if you want secure, evidential communication without any infrastructure work.
Dedicated private environment
A separate environment for your users, policies and administration. Operated for you, isolated from other tenants.
Choose this if you need your own retention, identity and admin rules without running infrastructure.
Sovereign — private cloud or self-hosted
Run Letro in infrastructure you control and align it with your own network and monitoring architecture.
Choose this if Letro has to sit behind your existing controls — SIEM, backup, identity, egress rules.
Air-gapped or isolated
For environments where internet connectivity is not permitted, or not acceptable as a trust assumption.
Choose this if a route to the public internet is itself the thing you are defending against.
Teams that work offline by rule
Air-gapped deployment is not a preference. Their rules require it.
Classified programmes where the network boundary is set by accreditation, not by convenience.
When the corporate network is compromised, the response team needs a channel that is not on it.
Plant and grid environments where the operational network is segmented by design.
Patient data that must stay inside the institution and inside the jurisdiction.
Trading, custody and private-client desks with residency and retention obligations.
Privileged matter files that cannot sit in a vendor's shared cloud.
You are likely a fit if
Deployment is more than hosting
It is not just where the VM sits. Five controls change with the model you pick — which makes this a security decision, not an infrastructure preference.
Who holds admin rights, and whether Letro staff can reach the system at all.
How Letro binds to your directory, and how PostNumber verification is issued.
Continuous release, scheduled windows, or offline updates for isolated sites.
Where the evidential record is written, retained, and exported for audit.
Which legal regimes can compel access to the environment — and which cannot.
Tell us your boundary. We map the deployment
Send your operating model, network boundary and risk requirements. You get a personal reply from the people who build the deployment — not a sales sequence.
Bring your network diagram
We map it against the four models and tell you which one your policy actually needs.
Request briefing → We use your details only to answer your request. No newsletter.