Trust & architecture

Security you can verify, not just trust

Private by architecture, not by policy promise.

Built in by design

Encrypted end to end

Every message and file, by default — not as an add-on.

You hold the keys

Keys live on your devices, never with a provider.

Open protocols

Matrix and JMAP — auditable, portable, no lock-in.

Encryption settings and key backup in Rhaetix.

E2EE

How end-to-end encryption protects you

Encrypted on your device

Content is encrypted before it leaves your laptop or phone.

The server stores ciphertext

Ours or yours: the server only ever sees data it cannot read.

Only recipients can decrypt

Keys stay on your team’s devices. Not with us, not with any cloud.

Transparency

What our servers can see

The table we would want from any vendor. Encryption claims mean nothing without the boundaries — here they are, precisely.

Your data What the server holds Can it be read server-side?
Chat messages & shared files Ciphertext only — encrypted on your device before sending (Matrix Olm/Megolm). No — E2EE
Call signalling End-to-end encrypted, like messages. No — E2EE
Your encryption keys Never stored. Keys live on your devices; the recovery key exists only with you. No — E2EE
Call media (voice & video) Encrypted in transit and relayed by the media server — self-host it to own the entire path. Relay only
Mail Stored encrypted at rest. Content is processed for delivery and spam filtering — that is how open mail standards work. Yes — encrypted at rest
Documents, sheets & slides Real-time collaboration is merged server-side; content is encrypted at rest and in transit. Yes — encrypted at rest
Drive files & calendar Stored encrypted at rest; access follows workspace membership. Yes — encrypted at rest
Metadata (who, when, sizes) Visible — required to route and deliver anything at all. Yes — encrypted at rest

Every “yes” above is a fact of how open standards work, not a choice we hide. And it is exactly why Rhaetix is self-hostable: run it yourself, and this whole table lives on your hardware, under your law.

End-to-end encryption by default

Messages and files are encrypted on your device before they are sent. Only the intended recipients hold the keys to decrypt them. The server — ours or yours — stores ciphertext it cannot read.

Key backups are protected by a recovery key that only you know. Losing a device does not mean losing your history; sharing it with your provider is never required.

Open protocols, no lock-in

Messaging and calls are built on Matrix, mail and calendar on JMAP — open, documented protocols with active security communities. Your data is portable and your workspace speaks standards, not proprietary formats.

Verifiable, down to the deployment

The strongest security claim is one you can check. Rhaetix can be self-hosted in full: run it on your own hardware, audit the traffic, own every layer.

No ads, no data mining

Rhaetix is paid software. Your data is never scanned for advertising, profiling or model training — the business model is the subscription, nothing else.

Security questions? Ask our engineers directly.

Contact us