Controls your compliance team can sign off on

Access controls, communication rules, device approval, and auditing, on top of an encryption model you choose. Built for regulated environments.

  • Roles and permissions
  • Communication rules
  • Device approval
  • Message and call auditing
  • MLS or Signal

2

Encryption protocols for messages, MLS and Signal

3

Security levels: MLS, Signal, or client-server where auditing requires it

0

Third parties on the call path. Your organization runs the infrastructure

1

Action to log a lost phone out from the console

Who may do what, written down

Roles and permissions

Define roles once and assign them to users. Each role says exactly what a person may see and do.

Communication rules

Decide who may talk to whom, for the whole organization or for a single user.

Device approval and remote logout

New devices wait in a queue until an admin approves them. Any device can be logged out from the console.

Message auditing

Where your security level allows it, auditors review messages from the console with a record of who looked.

Call auditing

Every call has a timeline: who joined, when it started, how long it ran, and how it ended.

Certificate pinning

The mobile app only trusts your deployment's certificate, so an intercepting proxy cannot read the traffic.

Built for regulated environments

A dedicated deployment, in-region hosting, an encryption model set by your compliance team, and auditing built into the console. Bring your requirements and we will show you where each one is met.

Encryption you choose

Messages are protected with the MLS protocol or the Signal protocol. Both are available, the admin picks one for the organization, and the choice can be switched from the console. Where auditing requires it, the organization can run client-server encryption instead, so the deployment can keep a reviewable record. The decision is yours and it is set per deployment.

  • MLS or Signal for messages, chosen by the admin
  • Switch from the console, no release needed
  • Client-server where auditing requires a reviewable record

Security level

  • MLS protocolEnd-to-end. The deployment cannot read content.Active
  • Signal protocolEnd-to-end. The deployment cannot read content.
  • Client-serverReviewable record for auditors, where regulation requires it.

Set per deployment. The admin switches it from the console.

Identity, devices, and audit, all under your control

Three links in one chain, all held inside your deployment.

  1. 1

    Identity

    Users are created by your admins or imported in bulk, and each one carries a role that says what they may see and do.

  2. 2

    Devices

    A person's devices are listed in the console. New devices wait for approval, and a lost phone is logged out remotely in one action. Screen lock and linked-device management on the user side complete the picture.

  3. 3

    Audit

    Message auditing and call auditing live in the console, and reports summarize activity for the people who have to sign off. Because the deployment is yours, the audit record is yours too.

Questions compliance teams ask

The MLS protocol and the Signal protocol are both available for messages. Your admin picks one for the organization and can switch it from the console. Client-server encryption is available where auditing requires it.

Bring your compliance checklist.

We will walk through it line by line and show where each requirement is met in your deployment.