For law firms
TruCrypt is an end-to-end encrypted messenger built for law firms and their clients. Client-side keys keep the vendor out. A firm-held organizational key lets partners recover case-file access when someone joins, leaves, or changes matters — with the vendor still unable to participate.
The vocabulary problem
Almost every product on the market that calls itself "encrypted" is doing one of three very different things. Only one of them keeps the privilege intact under subpoena or breach.
Tier 1
Scrambled while it travels between phones and the vendor. Stops a coffee-shop eavesdropper. Does nothing about the plaintext copy on the vendor's server.
Tier 2
Encrypted in the vendor's database, but the vendor holds the key. A breach exposes messages. A subpoena is honored with plaintext. A rogue employee's only guardrail is HR policy.
Tier 3 · TruCrypt
Encrypted on the device with keys only the endpoints possess. A subpoena produces ciphertext. A breach produces ciphertext. The privilege lives in the cryptography, not in the vendor's promises.
The gap TruCrypt closes
Recovery is easy. But the vendor is subpoena-able. A breach exposes the file. A curious employee can read it.
The vendor can't read a thing. But when an associate leaves, the firm loses access to the matter's history.
TruCrypt does neither. A client-side keypair is generated on each device and the private half never leaves. A firm-held organizational key can re-wrap case-file access when someone joins, leaves, or changes matters. The vendor cannot participate in that recovery, because the vendor does not hold the organizational key either.
Due diligence
Print these. Ask them of any product you're evaluating, including the ones your bar association endorses. TruCrypt's answer follows each question.
If you receive a lawful subpoena for a specific client's messages tomorrow, what can you produce?
AnswerCiphertext only. We do not hold the decryption keys.
If one of your engineers goes rogue tonight, what messages can they read?
AnswerNone. Keys never leave the customer's devices.
Where are the encryption keys stored, and who controls them?
AnswerOn the end-user devices. We have no copy. Firm-side recovery uses a separate organizational key held by firm administrators, not by us.
If a message from my client to me leaks in a breach of your systems, what does the attacker see?
AnswerCiphertext plus routing metadata (who sent what to whom, when). We retain only what routing requires. A Data Processing Agreement is available on request.
Is your product's cryptographic design published and independently reviewable?
AnswerThe primitives are open and boring: RSA-3072 for identity keys, AES-256-GCM for messages, per-message ephemeral symmetric keys wrapped separately to each recipient. Full technical writeup available on request.
How it works
Every user's keypair is generated on their device at first sign-in. RSA-3072 identity keys. The private half never leaves the device.
Each message is encrypted with a new symmetric key (AES-256-GCM), which is then wrapped separately to each recipient's public key.
Our servers hold blobs of ciphertext and a routing envelope. There is no key on the server to read anything with.
Firm administrators hold an organizational key that can re-wrap case-file access when someone joins, leaves, or changes matters. Access boundaries live inside the cryptography.
When a member is removed, case-file keys are rotated. Access is not merely revoked in a database. It is cryptographically severed.
iOS and macOS Staff are native Swift apps. Private keys never touch a browser origin, a cloud sync, or a vendor JavaScript bundle.
Shipping today
Both apps are already in the App Store. A firm can install TruCrypt Staff on macOS today and start a pilot with real client-facing threads inside a matter of hours.
Design partner slots
If any of the above matches a conversation you keep having with your IT lead, we'd like to talk. Design partners help us shape the product and get direct time with the team building it. A pilot takes an hour to set up and one hour a week to run.
A reply within one business day, from an engineer. Prefer email? Write to michal@trucrypt.io or sebastian@trucrypt.io.
Common questions
Messages persist by default. TruCrypt does not auto-delete client-attorney communications. Firms retain control over any retention policy.
Signal is a superb Tier 3 consumer messenger. It has no notion of a firm, and no way to recover a matter's history when an associate takes their phone number out the door. TruCrypt adds firm-level identity, matter-scoped access, and cryptographic recovery, without the vendor being able to participate.
SOC 2 Type I readiness work is underway; formal audit will follow. A Data Processing Agreement is available on request today.
The architecture is data-minimizing by design: the vendor holds ciphertext and routing metadata only. A DPA is available on request; formal compliance documentation is in progress.
TruCrypt is not currently marketed as HIPAA-compliant and we do not yet offer a BAA. If your firm handles PHI and needs one, please email us. This is on the roadmap.
You install TruCrypt Staff on one or two attorney machines and invite a friendly client to the mobile app. Two weeks of real threads inside a real matter. We meet weekly to share what worked and what didn't. Pricing decisions come after the pilot, not before.