Client communication built for the obligations you actually carry.
Reports, tax statements, client instructions and everyday questions — in one Swiss-hosted, end-to-end encrypted channel your clients open from their phone. Not another chat app. Not another portal.


PDF-by-email is not a client experience — and it isn't a compliant one.
Email leaves the firm's control the moment it's sent. Forwarded, cached, backed up to personal accounts, retained by whoever hosts the mailbox. The audit trail is whatever survived. Consumer messengers can't be made compliant. WhatsApp, Signal and Telegram harvest metadata, store backups outside your control, and produce no audit-grade record — regardless of how disciplined your team is. And client portals stop at reporting: source-of-wealth documents and client instructions still travel by email because the portal wasn't built for them.

The fine is the smallest part — and it lands on you, not the firm.
FADP Art. 62: intentional breach of professional confidentiality carries a personal criminal fine of up to CHF 250,000 — on the partner, the relationship manager, the founder. Not the firm.
Art. 321 StGB and Art. 47 BankG add up to three years custodial. FINMA cannot fine you directly; the Supervisory Organisations can refer you to a prosecutor who can.
Above the fine sit SO remediation costs, civil claims from HNW clients, and professional-indemnity policies that exclude unsanctioned channels.
UK firms: FCA SYSC 9 and COBS 11.8 carry parallel record-keeping obligations. The architecture problem is the same. The full exposure analysis is in the whitepaper.

What moves into Letro
Three things your clients do with you — moved into one channel.
Deliver documents, answer questions, onboard new clients — the everyday work that currently runs on email and WhatsApp, inside one Swiss-hosted, end-to-end encrypted channel.
In practice
Deliver documents through the Hub
Monthly reports, statements, tax packs — each client has one secure space for everything you share. Nothing goes as an attachment; nothing sits in a personal inbox. You see what was delivered, when, to whom.
Answer questions without leaving the record
Encrypted messaging, voice and video. The quick question that used to go to WhatsApp stays inside the same auditable channel as the documents. Your team answers from one place; the record is complete.
Onboard clients with PostNumber
NFC passport scanning issues a verified, permanent PostNumber identity at account creation — no video call, no photocopies. Every client in your channel is a verified person, tied to a verified address.
Private AI that never leaves the encryption boundary
Two things, nothing more: it helps your team design communication workflows, and it works inside end-to-end encrypted chat. It runs on Letro's infrastructure — no client data to a third-party model, nothing used for training. Ask us to show it.
Built for the regulatory context, not adapted to it.
Swiss-hosted, Swiss-controlled: infrastructure in Switzerland, operated by a Swiss company, outside the reach of the US CLOUD Act. End-to-end encrypted by default, on the Matrix open protocol, with Swiss-controlled key custody. Independently penetration-tested: external penetration test completed September 2026 by ImmuniWeb (Geneva, CREST-accredited) — attestation letter available to prospects on request. Audit-grade record: exportable, timestamped, tamper-evident. Your deployment, your risk profile: cloud, dedicated single-tenant, or sovereign on your own infrastructure — including air-gapped.


See where your firm stands.
A 90-second calculator shows your exposure range across five layers, the size of your potential insurance gap, and the procedures that reduce both. No form, no gate. The five-step migration off WhatsApp is documented in the whitepaper.