Privileged communication deserves better than an inbox.

Identity documents, instructions, drafts and the quick client question — in one Swiss-hosted, end-to-end encrypted channel your clients open from their phone. Built for the duty of confidentiality, not retrofitted to it.

Letro secure communication network: a locked, verified document vault connected to verified client identities

The most sensitive thing a client sends you arrives by email.

Email is the attack surface. Payment-diversion fraud, spoofed partner addresses, intercepted bank details — the attacks that actually hit law firms run on email. The Law Society and the SRA warn about them because they work. Consumer messengers can't be made privileged. WhatsApp, Signal and Telegram harvest metadata and store backups outside the firm's control; a privileged conversation on a personal device is privileged in name only. And when a client disputes advice or a regulator asks for the file, the record is whatever survived across inboxes, phones and forwarded threads.

Verified legal documents sent through Letro and routed only to verified recipients, with unverified access blocked

Confidentiality is a criminal obligation. It lands on the lawyer.

Art. 321 StGB places professional secrecy on the lawyer personally — up to three years custodial. It attaches to you, not to the firm.

The revised FADP (Art. 62) adds a personal criminal fine of up to CHF 250,000 for intentional breach of confidentiality.

Above them sit disciplinary proceedings, civil claims, and professional-indemnity policies that increasingly exclude unsanctioned channels.

UK practitioners: the SRA Code requires you to keep client affairs confidential wherever the information travels. The architecture problem is identical. The full exposure analysis is in the whitepaper.

What moves into Letro

Three things every client does with you — moved off email.

Onboard, exchange documents, advise — the everyday work of a matter that currently runs on email and WhatsApp, inside one Swiss-hosted, end-to-end encrypted channel.

In practice

Onboard with PostNumber

NFC passport scanning issues a verified, permanent PostNumber identity at account creation. No emailed passport scans, no video-call identification. Every client in your channel is a verified person tied to a verified address — before the first document moves.

Deliver and receive documents through the Hub

Engagement letters, drafts, court documents, client instructions. Each client and each matter has one secure space. Nothing travels as an attachment; nothing lands in a personal inbox. You see what was delivered, when, to whom.

Advise without leaving the record

Encrypted messaging, voice and video. The two-line question that used to arrive on WhatsApp stays inside the same channel as the matter file. Privilege and the record stay intact.

Private AI that never leaves the encryption boundary

Two things, nothing more: it helps design how a matter's communication should flow, and it works inside end-to-end encrypted chat. No client data to a third-party model, nothing used for training. Ask us to show it.

Built for the regulatory context, not adapted to it.

Swiss-hosted, Swiss-controlled: infrastructure in Switzerland, operated by a Swiss company, outside the reach of the US CLOUD Act. End-to-end encrypted by default, on the Matrix open protocol, with Swiss-controlled key custody. Independently penetration-tested: external penetration test completed September 2026 by ImmuniWeb (Geneva, CREST-accredited) — attestation letter available to prospects on request. Audit-grade record: exportable, timestamped, tamper-evident. Your deployment, your risk profile: cloud, dedicated single-tenant, or sovereign on your own infrastructure — including air-gapped.

See where your firm stands.

A 90-second calculator shows your exposure range across five layers, the size of your potential insurance gap, and the procedures that reduce both. No form, no gate. The five-step migration off email and WhatsApp is documented in the whitepaper.