Security lead
Content access must be technically impossible, not just prohibited.
- Signal Protocol: X3DH plus Double Ratchet
- No plaintext logs or server-held message keys
- Published security and threat-model documentation
Secure Business Messaging · An Attomus Product
End-to-end encrypted messaging, file exchange, and governance for organisations that need the facts of communication without exposing the content.
The server routes your messages. It cannot read them. This is not a policy. It is cryptography.



Admin sees activity, membership, and risk signals. Operators never see message content.
How it works
Encryption happens in the mobile client before transmission. X3DH key agreement and Double Ratchet forward secrecy run automatically. The session key never reaches the server.
Mobile-message ciphertext arrives at the messaging server and leaves it. That server has no decryption key and never receives plaintext or device-side key material. Portal-admin broadcasts are encrypted before they reach the messaging server, as described below.
The organisation audit log records defined security and administrative events with actor, time, event type, outcome, and relevant target identifiers. Broadcast audit entries add message and recipient counts. Message and file content is never included.
Made by Attomus
Attomus is brought in when the work is sensitive, the standards are high, and outcomes need to stand up under scrutiny.
SemaFore is what Attomus built for its own communications handling. The same discipline that goes into regulated and high-consequence engagements is what makes the server plaintext-blind by design.
JOSCAR Registered
Pre-qualified for defence, aerospace, and security procurement.
Armed Forces Covenant
Signatory. Attomus operates with the conduct that sensitive environments require.
Berkeley Square
23 Berkeley Square, Mayfair, London W1J 6HE
Registered in England & Wales. No. 06517654
Data Sovereignty
The SemaFore messaging servers and customer message and file ciphertext storage run on Attomus-owned hardware in the United Kingdom, behind Attomus's own network boundary. AWS, Azure, and GCP are not used for that core service or its storage.
The public website and portal interface are hosted on Cloudflare. Messages from mobile devices are encrypted on-device before transmission. For portal-admin broadcasts, plaintext passes over TLS to the Cloudflare-hosted portal service, which creates per-recipient encrypted envelopes before sending them to the SemaFore server; Cloudflare is not used to store those broadcasts.
Support requests are separate from the messaging service and may be stored in YouTrack Cloud's EU-hosted service. The [Privacy notice](/privacy/) describes these service boundaries and the data involved.
ICO Registered · UK GDPR Compliant · Message and file ciphertext stored in the UK

For Organisations
Private and group threads. Every message is sealed before it is sent. Keys stay with user devices. The server sees ciphertext.
File exchange follows the same handling model as messages. The server stores and forwards encrypted material, not readable content.
User management, group governance, invitations, retention settings, and platform administration without giving operators message content.
Security and administrative audit entries record actor, time, event type, outcome, and relevant targets. Broadcast entries add message and recipient counts, never content.
Who it is for
A secure messaging decision rarely belongs to one person. Security, compliance, and operations each need a clear answer before a platform earns trust.
Security lead
Compliance owner
Operations team
Pricing
Access begins through the evaluation programme. Every tier uses the same encryption model and applications; the differences are seats, retention, and support terms.
Free tier — early access notice: The free tier is available as part of our early-access launch. If availability changes, organisations on the free tier will receive at least 90 days' written notice and can move to a paid plan at the standard rate.
Government and defence: Device attestation and on-premise deployment options are available for government, defence, and classified-adjacent organisations. These options are negotiated separately and are not on the standard rate card. Speak to us to discuss requirements and timelines.
Get a briefing
In twenty minutes we can cover architecture, governance, deployment, pricing, and the risks SemaFore does not try to hide. If it is not the right fit, we will say so.
The briefing form is temporarily unavailable. Please email [email protected] and we will respond shortly.