Skip to content

Use case · confidentiality

A room the administrator cannot let themselves into

Enclessa group direct messages are end-to-end encrypted with MLS as specified in RFC 9420, and there is no administrator override: the server holds ciphertext, no organisation administrator can add themselves to the conversation, and nothing outside the group can produce its contents. That is what makes them usable for a board discussion, a works-council conversation or a legally privileged exchange, where the risk is not an external attacker but a colleague with an administrator account.

Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.

At a glance

Encryption
MLS per RFC 9420, through OpenMLS
Group direct messages
Always end-to-end encrypted, with no exception
Administrator override
None. There is no mechanism to add one
Keys
One per device; the server runs delivery and holds no keys
Room mode
Fixed when the room is created and shown in the room
Available on
Every plan, including Free

The situation

A small group has to discuss something that the rest of the organisation, and specifically the people who administer its software, must not be able to read. A board discussing a transaction, a works council doing what the law requires it to do independently of the employer, a partner discussing a matter under privilege. The threat is internal and ordinary: an administrator account, a subpoena served on the operator, a routine export.

What goes wrong when this is spread across four products

A private channel is only private by policy

In most platforms a private channel is a row somebody with enough access can change. The confidentiality rests on a permission that an administrator can grant themselves, and on the assumption that nobody will.

The employer administers the works council’s tooling

A works council using a platform the employer operates is relying on the employer not to look. That is an uncomfortable arrangement to write down, and in Germany it is the reason these conversations often end up on personal phones.

Compliance tooling reads everything by default

The features that make a platform auditable — export, retention, discovery — are the same features that make a confidential discussion readable by whoever operates them.

The workaround is worse than the problem

The conversation moves to a consumer messenger on personal devices, where the organisation has no record of what was agreed, no way to remove somebody who leaves, and no answer at all when somebody asks where the data went.

How Enclessa handles it

  1. Start a group direct message rather than a channel

    Group direct messages are always end-to-end encrypted. This is not a setting somebody could have failed to switch on, and not something an administrator can change afterwards — there is no mechanism, in the product or in the database, to make a group direct message readable by the server.

  2. Check what the room says it is

    A room’s mode is fixed when it is created and displayed in the room itself, so nobody has to take it on trust or infer it from a settings page. Encrypted rooms are marked, and the marking is the same everywhere.

  3. Understand who can join, and who cannot

    Membership of an encrypted conversation is membership of a cryptographic group, so adding somebody is a visible event to everybody in it. There is no silent addition, no shadow member and no compliance reader that the group cannot see.

  4. Keep the searchable half where it belongs

    Use ordinary managed channels for the work that has to be searchable, retained and exportable, and keep the confidential discussion in the encrypted room. Both exist in the same product, and which one you are in is always visible.

Which plan this needs

None in particular. End-to-end encrypted direct messages and group direct messages are on every plan including Free, which means a works council or a board can use this without a purchase decision and without the organisation paying for their confidentiality.

Compare the plans

What this will not do

  • Group channels are not end-to-end encrypted. Encryption covers direct messages and group direct messages; a channel is server-readable, which is what makes its search, retention and export possible.
  • A room cannot be switched between encrypted and managed after it is created. Either the old history would be exposed or it would become permanently unreadable, so the mode is fixed.
  • An encrypted room has no server-side search, no compliance export, no bots and no webhooks. Search runs on your own device against a local index instead.
  • Losing every device in an encrypted conversation loses that history. There is no server-side copy for anybody to restore from, which is the same property that makes the room worth using.
  • Enclessa holds no certification and has commissioned no external security audit. What is offered instead is a standard protocol, an audited open-source implementation of it, and a published architecture.

Where the detail is

Questions

Board and works-council communication: common questions

Can an administrator read our confidential group conversation?

No. Group direct messages are always end-to-end encrypted with MLS per RFC 9420, there is no administrator override, and the server holds ciphertext it cannot decrypt. Adding somebody to the conversation is a visible event to everyone already in it.

Is Enclessa suitable for a works council?

The confidentiality property a works council needs — communication the employer cannot read even though the employer pays for the platform — is what an end-to-end encrypted group direct message provides. Whether that satisfies a particular works-council agreement is a question for the parties to it, not one this page can answer.

Why are channels not end-to-end encrypted?

Because a channel is where search, retention rules and compliance export have to work, and all three need the server to be able to read the message. Enclessa makes the trade-off visible per room rather than pretending it does not exist.

Can we turn on encryption for an existing channel?

No. A room’s mode is set when the room is created and cannot be changed, because converting one way would expose existing history and converting the other would make it permanently unreadable.

Encrypted collaboration, hosted in Europe.

Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.

Open beta. Free plan, no payment card to start.