The structure is confidential. The communication should be too.

Settlors, beneficiaries, protectors and co-trustees across jurisdictions — in one Swiss-hosted, end-to-end encrypted channel. Built for the duty you hold, not adapted to it.

Letro secure communication network: a locked, verified document vault connected to verified client identities

A trust runs on communication that was never designed to be secure.

The parties are the risk. A beneficiary forwards a distribution schedule. A settlor's relative sits in the family WhatsApp group. The trustee didn't cause the leak and is still accountable for it. Cross-border means cross-jurisdiction. Communication that touches the US, the UK and Switzerland in one thread sits under three legal regimes — and under the reach of whichever platform hosts it. And when a beneficiary challenges a decision, the trustee's protection is a complete, timestamped record; email threads and chat exports don't meet that standard.

A trust document distributed from a secure vault to verified settlors, beneficiaries and co-trustees, with an unverified party excluded

Since FinIA, trustees are supervised. The exposure is personal.

Swiss trustees now operate under FinIA licensing and Supervisory Organisation oversight, where insufficient channel governance is a documented finding category.

The revised FADP (Art. 62) adds a personal criminal fine of up to CHF 250,000 for intentional breach of confidentiality — on the trustee, not the trust company.

Above that sit SO remediation, beneficiary claims, and insurance policies that exclude unsanctioned channels.

UK trustees: the confidentiality and record-keeping duties differ in source, not in substance. The architecture problem is the same. The full exposure analysis is in the whitepaper.

What moves into Letro

Every party to the structure, in one channel — verified.

Verify the parties, deliver documents, communicate with beneficiaries and co-trustees — inside one Swiss-hosted, end-to-end encrypted channel.

In practice

Verify every party with PostNumber

Settlors, beneficiaries, protectors, co-trustees. NFC passport scanning issues each a verified, permanent PostNumber identity tied to a verified address. You know who you're communicating with — and can prove it later.

Deliver documents through the Hub

Trust deeds, accounts, distribution notices, letters of wishes. Each party sees exactly what they're entitled to, in one secure space. Nothing goes as an attachment; nothing sits in a family inbox. You see what was delivered, when, to whom.

Communicate without leaving the record

Encrypted messaging, voice and video with beneficiaries and co-trustees. The request that used to arrive on WhatsApp stays inside the same auditable channel as the documents it concerns.

Private AI that never leaves the encryption boundary

Two things, nothing more: it helps design how communication should flow among the parties to a structure, and it works inside end-to-end encrypted chat. No data to a third-party model, nothing used for training. Ask us to show it.

Built for the regulatory context, not adapted to it.

Swiss-hosted, Swiss-controlled: infrastructure in Switzerland, operated by a Swiss company, outside the reach of the US CLOUD Act. End-to-end encrypted by default, on the Matrix open protocol, with Swiss-controlled key custody. Independently penetration-tested: external penetration test completed September 2026 by ImmuniWeb (Geneva, CREST-accredited) — attestation letter available to prospects on request. Audit-grade record: exportable, timestamped, tamper-evident. Your deployment, your risk profile: cloud, dedicated single-tenant, or sovereign on your own infrastructure — including air-gapped.

See where you stand.

A 90-second calculator shows your exposure range across five layers, the size of your potential insurance gap, and the procedures that reduce both. No form, no gate. The five-step migration off WhatsApp — including how to move a family without a family argument — is documented in the whitepaper.