For law firms

Attorney–client privilege by cryptography, not by policy.

TruCrypt is an end-to-end encrypted messenger built for law firms and their clients. Client-side keys keep the vendor out. A firm-held organizational key lets partners recover case-file access when someone joins, leaves, or changes matters — with the vendor still unable to participate.

The vocabulary problem

The word "encrypted" does not mean what most attorneys think it means.

Almost every product on the market that calls itself "encrypted" is doing one of three very different things. Only one of them keeps the privilege intact under subpoena or breach.

Tier 1

Encrypted in transit

Scrambled while it travels between phones and the vendor. Stops a coffee-shop eavesdropper. Does nothing about the plaintext copy on the vendor's server.

Tier 2

Encrypted at rest

Encrypted in the vendor's database, but the vendor holds the key. A breach exposes messages. A subpoena is honored with plaintext. A rogue employee's only guardrail is HR policy.

Tier 3 · TruCrypt

End-to-end, zero-knowledge

Encrypted on the device with keys only the endpoints possess. A subpoena produces ciphertext. A breach produces ciphertext. The privilege lives in the cryptography, not in the vendor's promises.

The gap TruCrypt closes

Every other legal messaging tool forces you to pick one of two failure modes.

Vendor holds the keys

Recovery is easy. But the vendor is subpoena-able. A breach exposes the file. A curious employee can read it.

Individuals hold the keys

The vendor can't read a thing. But when an associate leaves, the firm loses access to the matter's history.

TruCrypt does neither. A client-side keypair is generated on each device and the private half never leaves. A firm-held organizational key can re-wrap case-file access when someone joins, leaves, or changes matters. The vendor cannot participate in that recovery, because the vendor does not hold the organizational key either.

Due diligence

Five questions every firm should ask before signing.

Print these. Ask them of any product you're evaluating, including the ones your bar association endorses. TruCrypt's answer follows each question.

  1. If you receive a lawful subpoena for a specific client's messages tomorrow, what can you produce?

    AnswerCiphertext only. We do not hold the decryption keys.

  2. If one of your engineers goes rogue tonight, what messages can they read?

    AnswerNone. Keys never leave the customer's devices.

  3. Where are the encryption keys stored, and who controls them?

    AnswerOn the end-user devices. We have no copy. Firm-side recovery uses a separate organizational key held by firm administrators, not by us.

  4. If a message from my client to me leaks in a breach of your systems, what does the attacker see?

    AnswerCiphertext plus routing metadata (who sent what to whom, when). We retain only what routing requires. A Data Processing Agreement is available on request.

  5. Is your product's cryptographic design published and independently reviewable?

    AnswerThe primitives are open and boring: RSA-3072 for identity keys, AES-256-GCM for messages, per-message ephemeral symmetric keys wrapped separately to each recipient. Full technical writeup available on request.

How it works

Cryptography, not vendor promises.

Shipping today

Live on iOS and macOS.

Both apps are already in the App Store. A firm can install TruCrypt Staff on macOS today and start a pilot with real client-facing threads inside a matter of hours.

Design partner slots

We're onboarding our first firms this quarter.

If any of the above matches a conversation you keep having with your IT lead, we'd like to talk. Design partners help us shape the product and get direct time with the team building it. A pilot takes an hour to set up and one hour a week to run.

A reply within one business day, from an engineer. Prefer email? Write to michal@trucrypt.io or sebastian@trucrypt.io.

Common questions

Frequently asked.

What about the professional-responsibility duty to preserve client communications?

Messages persist by default. TruCrypt does not auto-delete client-attorney communications. Firms retain control over any retention policy.

How is this different from Signal?

Signal is a superb Tier 3 consumer messenger. It has no notion of a firm, and no way to recover a matter's history when an associate takes their phone number out the door. TruCrypt adds firm-level identity, matter-scoped access, and cryptographic recovery, without the vendor being able to participate.

Do you have SOC 2?

SOC 2 Type I readiness work is underway; formal audit will follow. A Data Processing Agreement is available on request today.

What about GDPR and CCPA?

The architecture is data-minimizing by design: the vendor holds ciphertext and routing metadata only. A DPA is available on request; formal compliance documentation is in progress.

Are you HIPAA-eligible?

TruCrypt is not currently marketed as HIPAA-compliant and we do not yet offer a BAA. If your firm handles PHI and needs one, please email us. This is on the roadmap.

What does a pilot look like?

You install TruCrypt Staff on one or two attorney machines and invite a friendly client to the mobile app. Two weeks of real threads inside a real matter. We meet weekly to share what worked and what didn't. Pricing decisions come after the pilot, not before.