Secure Business Messaging · An Attomus Product

Encrypted messaging built for organisational control.

End-to-end encrypted messaging, file exchange, and governance for organisations that need the facts of communication without exposing the content.

The server routes your messages. It cannot read them. This is not a policy. It is cryptography.

0 server-held message keys
UK core messaging infrastructure
Full defined security and admin audit
SemaFore admin portal dashboard with activity metrics and no message content
SemaFore Android client showing encrypted conversation list
SemaFore iOS client showing encrypted conversation list

Admin sees activity, membership, and risk signals. Operators never see message content.

How it works

Tighter handling without asking you to trust us.

Mobile messages leave your device already sealed

Encryption happens in the mobile client before transmission. X3DH key agreement and Double Ratchet forward secrecy run automatically. The session key never reaches the server.

The server routes. It does not read.

Mobile-message ciphertext arrives at the messaging server and leaves it. That server has no decryption key and never receives plaintext or device-side key material. Portal-admin broadcasts are encrypted before they reach the messaging server, as described below.

Administration without surveillance

The organisation audit log records defined security and administrative events with actor, time, event type, outcome, and relevant target identifiers. Broadcast audit entries add message and recipient counts. Message and file content is never included.

Made by Attomus

The firm trusted by government, defence, and regulated enterprise.

Attomus is brought in when the work is sensitive, the standards are high, and outcomes need to stand up under scrutiny.

SemaFore is what Attomus built for its own communications handling. The same discipline that goes into regulated and high-consequence engagements is what makes the server plaintext-blind by design.

JOSCAR Registered

Pre-qualified for defence, aerospace, and security procurement.

Armed Forces Covenant

Signatory. Attomus operates with the conduct that sensitive environments require.

Berkeley Square

23 Berkeley Square, Mayfair, London W1J 6HE
Registered in England & Wales. No. 06517654

Data Sovereignty

Messaging servers and ciphertext storage
stay on UK-controlled infrastructure.

Attomus-owned. UK-hosted. Core messaging.

The SemaFore messaging servers and customer message and file ciphertext storage run on Attomus-owned hardware in the United Kingdom, behind Attomus's own network boundary. AWS, Azure, and GCP are not used for that core service or its storage.

The public website and portal interface are hosted on Cloudflare. Messages from mobile devices are encrypted on-device before transmission. For portal-admin broadcasts, plaintext passes over TLS to the Cloudflare-hosted portal service, which creates per-recipient encrypted envelopes before sending them to the SemaFore server; Cloudflare is not used to store those broadcasts.

Support requests are separate from the messaging service and may be stored in YouTrack Cloud's EU-hosted service. The [Privacy notice](/privacy/) describes these service boundaries and the data involved.

ICO Registered · UK GDPR Compliant · Message and file ciphertext stored in the UK

SemaFore audit log showing masked actors and event metadata without message content
Defined security and administrative events record actor, time, type, and outcome. Never message or file content.

For Organisations

Built for work that carries real risk.

Encrypted on the device. Decrypted only on the device.

Private and group threads. Every message is sealed before it is sent. Keys stay with user devices. The server sees ciphertext.

Files encrypted before upload. Storage stays blind.

File exchange follows the same handling model as messages. The server stores and forwards encrypted material, not readable content.

Full administration. Zero content access.

User management, group governance, invitations, retention settings, and platform administration without giving operators message content.

Defined security audit. No content.

Security and administrative audit entries record actor, time, event type, outcome, and relevant targets. Broadcast entries add message and recipient counts, never content.

Who it is for

Built for the teams who have to approve it.

A secure messaging decision rarely belongs to one person. Security, compliance, and operations each need a clear answer before a platform earns trust.

Security lead

Content access must be technically impossible, not just prohibited.

Compliance owner

Governance needs evidence without creating a surveillance archive.

  • Retention policy controls
  • SIEM-ready audit export
  • UK core messaging infrastructure and content-blind operations

Operations team

People still need to use it once security signs off.

  • iOS and Android messaging clients
  • Groups, receipts, files, and push wake-up
  • Invite and onboarding flows for new members

Pricing

Same encryption model. Different rollout terms.

Free Up to 5 approved members. Available without a time limit after evaluation approval. Apply to evaluate →
Professional £9 per user per month. Approved organisations can begin with a 30-day trial from portal billing. Apply to evaluate →
Enterprise / Gov Negotiated. On-premise and device-attestation options available. Contact sales →

Access begins through the evaluation programme. Every tier uses the same encryption model and applications; the differences are seats, retention, and support terms.

Free tier — early access notice:  The free tier is available as part of our early-access launch. If availability changes, organisations on the free tier will receive at least 90 days' written notice and can move to a paid plan at the standard rate.

Government and defence:  Device attestation and on-premise deployment options are available for government, defence, and classified-adjacent organisations. These options are negotiated separately and are not on the standard rate card. Speak to us to discuss requirements and timelines.

Get a briefing

A technical sales conversation,
not a product tour.

In twenty minutes we can cover architecture, governance, deployment, pricing, and the risks SemaFore does not try to hide. If it is not the right fit, we will say so.

The briefing form is temporarily unavailable. Please email [email protected] and we will respond shortly.