Skip to content

Glossary

The words a security review turns on

The Enclessa glossary defines the terms that decide a collaboration platform purchase, in one sentence each and then in full. It covers encryption concepts including MLS per RFC 9420, forward secrecy and post-compromise security; platform concepts including tenant isolation, room modes and selective forwarding units; and compliance concepts including the GDPR, data processing agreements, subprocessors, retention and legal hold. Each entry states how Enclessa uses the term, including the several it deliberately does not.

Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.

At a glance

Entries
28 terms, each with its own page
Scope
Encryption, platform, compliance, operations, commercial
Standards named
RFC 9420, RFC 7643, RFC 7644, Regulation (EU) 2016/679
Terms Enclessa does not have
Single sign-on, SCIM, compliance export
Phrase Enclessa refuses
Zero-knowledge — see the entry for why
Spelling
British, and the German terms kept in German

A

C

D

E

F

G

L

M

O

P

R

S

T

W

Z

Where these terms are applied

A definition is only useful next to the thing it describes. The security page covers how the data is actually protected, the trust centre covers the paperwork a legal team asks for, and the encryption feature page covers what MLS does inside the product.

Questions

About this glossary

Why does Enclessa publish a glossary?

Because the terms in an encrypted collaboration purchase are used inconsistently across the market, and a buyer comparing two vendors is often comparing two different meanings of the same word. Defining them in public makes Enclessa easier to check rather than easier to sell.

Does every glossary entry describe something Enclessa has?

No. Several entries — single sign-on, SCIM, compliance export and platform-wide legal hold — define a capability Enclessa does not have today, and each says so in its own entry rather than leaving the definition to imply otherwise.

Is Enclessa zero-knowledge?

No, and Enclessa avoids the phrase. Direct messages and group direct messages are end-to-end encrypted with MLS and the server holds no key for them; channels are managed rooms the server can read so that search, retention and export work; and metadata, account data and billing data are visible to Enclessa in every case.

What is the difference between GDPR and DSGVO?

None. DSGVO is the German name for the GDPR — Datenschutz-Grundverordnung — and refers to the identical Regulation (EU) 2016/679. What is genuinely separate is the German Bundesdatenschutzgesetz, which fills in the areas the regulation leaves to member states.

Encrypted collaboration, hosted in Europe.

Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.

Open beta. Free plan, no payment card to start.