AMVLET
Internal access
Enter password
This page is for internal use only.
Password
Incorrect password. Please try again.
Sovereign by Design

Communications built for a world that demands sovereignty.

AMVLET gives organisations the infrastructure to communicate, collaborate, and operate — on their terms, under their jurisdiction, without compromise.

Get started → Talk to sales →
No third-party data access Regional deployment ISO 27001 · GDPR · nFADP
Trusted by secure organisations
Defence
Government
Blue light
Healthcare
Utilities
Finance
Education
Defence
Government
Blue light
Healthcare
Utilities
Finance
Education
40+
Countries with active sovereign deployments
560k+
Sovereign user accounts provisioned
99.99%
Platform uptime over the trailing twelve months
0
Third-party vendor access points across all deployments
Sovereign Communication

Built for

Where a data breach is not an option.

PQ E2EE
No US Cloud Act exposure
Open Standard
No Backdoor
EU Hosted
AMVLET · Sovereign Messaging
All Unread Groups
S
Sofia 10:42
Why we switche…
A
Ahmad Yesterday
I'll review the doc 2
AM
Amara Yesterday
Video call at 3pm?
J
James Mon
👍
S
Sofia
Online
Today
Good morning! Have you seen the Q2 compliance report?
10:38
Almost done. Sending it over in 5 minutes
10:39✓✓
Perfect! Board meeting is at 2pm. Use the secure channel 🔒
10:40
Sending encrypted via SCOVR.PRO — no CLOUD Act exposure
10:41✓✓
This is exactly why we switched from WhatsApp 😄 Saudi PDPL compliant, finally!
10:42
Exactly. Open standard, auditable, sovereign 🚩
10:42✓✓
Message Sofia…
Web App

Download the app.
Work without
compromise.

One workspace across every device your team uses. End-to-end encrypted, self-hosted, and available on all major platforms — with no US CLOUD Act exposure.

iOS Android macOS Windows Linux

Auto-detects your OS — Windows (x64) · macOS (Intel & Apple Silicon)

Questions

Frequently asked.

Short answers to the things finance, legal, and engineering tend to ask first.

Does the US CLOUD Act reach AMVLET? +
No. The CLOUD Act (18 U.S.C. § 2713) compels US-incorporated entities to produce data on government demand — regardless of where the data is physically stored. AMVLET is not a US company and does not operate on US infrastructure. There is no US legal entity in the data path that a US government order can compel. WhatsApp (Meta), Teams (Microsoft), Zoom, and Slack are all US-incorporated. Every one of them is subject to CLOUD Act compelled disclosure for your organisation's data. AMVLET is not.
Who holds the encryption keys? Can AMVLET read our messages? +
No one at AMVLET can read your messages. Encryption keys are generated on your devices using the Matrix cryptographic stack. On self-hosted and air-gapped deployments, keys never leave your infrastructure at any point. On ON-CLOUD, keys remain on client devices — AMVLET's servers route encrypted ciphertext without holding the ability to decrypt it. There is no key escrow, no master key, and no backdoor at any tier. This is architecturally enforced, not a policy promise.
We operate in Saudi Arabia. Does AMVLET satisfy SAMA and PDPL? +
Yes — by architecture, not by contractual assurance. Saudi Arabia's PDPL (Art. 29) prohibits cross-border transfer of personal data without NDMO authorisation. SAMA's March 2025 circular formally banned WhatsApp for all financial institution customer communications, citing security concerns and PDPL non-compliance. AMVLET deploys on KSA-resident infrastructure with no US cloud dependencies in the data path. When no US company controls the data, CLOUD Act exposure and PDPL cross-border transfer violations are simultaneously eliminated — structurally, not contractually.
WhatsApp has E2EE. Why isn't that sufficient for regulated use? +
WhatsApp's E2EE protects message content in transit between two devices. It does not protect: (1) metadata — who communicates with whom, how often, your contact graph, device identifiers — which Meta holds and which is legally compellable under CLOUD Act; (2) cloud backups to iCloud or Google Drive, which are not E2EE by default and accessible via US government orders to Apple and Google; (3) the structural fact that Meta Platforms, Inc. is a US company subject to compelled disclosure at the infrastructure level. SAMA reached the same conclusion in March 2025 — E2EE claim and data sovereignty are not the same thing.
Is the protocol open? Can our security team audit the full stack? +
Yes. AMVLET is built on the Matrix open standard, maintained by the Matrix.org Foundation. The specification is publicly documented. Synapse Pro, the server component, is open-source and auditable. Client applications are fully inspectable. There is no proprietary black box in the communications layer. This matters for NIS2 Article 21 supply-chain security requirements — documented, auditable evidence of what your communications infrastructure does is something no closed-source proprietary platform can provide to the same standard.
If we end the contract, what happens to our communications data? +
It stays on your infrastructure — because it was always there. On self-hosted and air-gapped deployments, AMVLET holds no copy of your data at any point. On ON-CLOUD, full export is contractually guaranteed and tooled. Because Matrix is an open standard, your message history is readable by any compliant Matrix implementation — there is no proprietary format, no lock-in, and no dependency on AMVLET's continued operation to access your own communications. You own the data permanently, not conditionally.
Our staff use WhatsApp and Teams externally. Do they need to switch apps? +
Not immediately. AMVLET supports bridging via the mautrix stack, letting your sovereign Matrix homeserver communicate with WhatsApp, Teams, Slack, and other networks. Your users operate from a single sovereign client; external contacts stay on their existing platforms. For enterprise migrations we design a phased rollout — internal communications move to Matrix first, with bridges maintaining continuity for external contacts throughout the transition.
What does post-quantum encryption mean and why does it matter now? +
Standard encryption (RSA, elliptic-curve) is broken by sufficiently powerful quantum computers. Post-quantum algorithms are designed to resist that attack. The immediate threat is "harvest now, decrypt later" — adversaries capture encrypted traffic today and hold it until quantum capability is available to decrypt it retrospectively. For defence, intelligence, diplomatic, and high-value financial communications, data classified sensitive today may still be sensitive in ten years. AMVLET implements post-quantum end-to-end encryption (PQ E2EE) so ciphertext harvested today cannot be decrypted with future quantum hardware. This is not a future consideration — it is the threat model that national-security agencies already plan against.
Client voices

Trusted by teams where security
is non-negotiable.

From government ministries to private equity, organisations with the highest confidentiality requirements rely on AMVLET every day.

After a twelve-month evaluation of every sovereign communication platform on the market, AMVLET was the only solution that satisfied our zero-trust architecture requirements without sacrificing the operational velocity our teams demand. The federated deployment model was the deciding factor.

MR
Marcus Reinhardt
Chief Information Security Officer
Helios Capital Group

Discretion is the foundation of every mandate we manage. Switching to AMVLET turned secure communication from a compliance obligation into a genuine competitive differentiator. Our clients notice the difference — and they trust us more because of it.

OB
Oliver Brennan
Managing Partner
Brennan & Associates LLP

Ready to go sovereign without giving up control?

Deploy a sandbox, connect your first encrypted channel, and run live sovereign communications in under an hour.

Start free trial → Book a 20-min demo