No certifications
Enclessa holds no ISO 27001, SOC 2, HIPAA or comparable certification. Anyone requiring one as a procurement gate should treat that as decisive today.
Security and data protection
Enclessa is in open beta, and it protects data in four layers: MLS end-to-end encryption per RFC 9420 for direct messages, so the server holds no key that opens them; tenant isolation asserted at a single choke point and proven by a generated test suite that drives every API operation across organisation boundaries; European hosting under a German seller; and operational controls including audit logging, per-organisation rate limits, retention rules and full data export. Enclessa holds no compliance certifications and has not undergone an external security audit — what stands in their place is a public standard rather than our word: the encryption is MLS per RFC 9420 through OpenMLS, and the architecture, the data model and the OpenAPI surface are published, so an auditor can review how the platform works without reading our source.
Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.
Direct messages and group direct messages are end-to-end encrypted with MLS, the IETF standard published as RFC 9420, implemented with OpenMLS and compiled once in Rust so every client runs identical cryptographic code. Each device is a separate member of the group, so adding one is visible and removing one re-keys the conversation.
Several organisations share one installation and no row crosses between them. The organisation is asserted at one choke point rather than remembered at each call site, and a request for another organisation’s object is answered with a not-found rather than a forbidden, because a forbidden confirms that the object exists.
Permissions are a bitmask evaluated in the data layer, so a capability that is not granted is not merely hidden in the interface. An organisation names its own roles over that bitmask, and a role can never carry a permission its author does not hold, which closes the usual privilege-escalation path.
The controls that matter after launch rather than at signature. Rate limits are applied per organisation and scaled by seat count, with each member capped at a share of the whole, so one runaway integration cannot exhaust the budget for everybody else.
The platform control plane — the part our operators use — is a separate identity with its own sessions, its own audit log and a deliberately blind interface: it can list organisations, suspend one, schedule a deletion and run a purge, and it cannot read content. That is enforced by a build check, not by a policy document: the control-plane package is not permitted to import anything that can read your content, and continuous integration fails if that ever changes.
Enclessa itself is a commercial product and its source is not published. Everything it runs on is open source under an OSI-approved licence, and that is enforced by a licence gate in continuous integration that fails the build when a dependency relicenses. Several otherwise obvious components are absent from the stack for exactly this reason.
Every item below is something a buyer will eventually find out. Finding it here is cheaper for both of us than finding it in week six of a procurement.
Enclessa holds no ISO 27001, SOC 2, HIPAA or comparable certification. Anyone requiring one as a procurement gate should treat that as decisive today.
The cryptography uses an audited library, OpenMLS, but Enclessa’s own implementation has not been through a third-party audit. That is planned work and is not finished work.
The hosted service runs in one European Union region. There is no choice of country within it. Where that is not sufficient, the Enterprise plan buys a dedicated deployment in a region you name, still operated and updated by us — the software itself is never handed over.
Sign-in is by email and password. Integration with an external identity provider, and SCIM provisioning, are planned enterprise work and are not available.
That is deliberate — it is what makes search, retention and compliance export possible — but it means channel content is not protected the way a direct message is. Choose the room to match the sensitivity.
Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.
Open beta. Free plan, no payment card to start.