Compliance & Trust

Whitepaper

Last updated: 15 September 2026

SemaFore security and compliance overview

Architecture and encryption

SemaFore mobile clients use end-to-end encryption based on the Signal Protocol: X3DH for session establishment and Double Ratchet for forward secrecy. Mobile message content is encrypted on the sender’s device before transmission. Portal-admin broadcasts are encrypted into independent per-device envelopes in the administrator’s browser. The portal server rejects plaintext message fields, so only ciphertext envelopes cross the Cloudflare-hosted portal boundary and reach the core messaging server. The core server stores ciphertext only and cannot read message content.

Data minimisation

SemaFore is designed to minimise plaintext data held by the service. The platform processes:

  • phone numbers
  • display names
  • organisation and membership records
  • device identifiers and push tokens
  • audit metadata needed to operate the service
  • billing data for paid organisations through the payment processor

SemaFore does not process message content in plaintext on Attomus-operated systems.

Privacy posture

Personal data stays inside the Attomus boundary except for narrow technical exceptions:

  • Apple APNs and Google Firebase Cloud Messaging for push delivery
  • Twilio for SMS OTP delivery
  • Mailgun EU for transactional email delivery
  • Stripe for billing on paid plans
  • Cloudflare for public-site and portal hosting, edge protection, and routing ciphertext portal-admin broadcast envelopes

SemaFore does not use third-party advertising, behavioural tracking, or data-broker services. Transactional email is limited to evaluation and account setup, organisation invitations and approval requests, portal-admin login codes, and security notifications where those functions apply.

Hosting and residency

Attomus operates the core SemaFore server infrastructure and encrypted object storage from Coventry, United Kingdom. Account data, organisation data, audit events, encrypted message ciphertext, and encrypted file ciphertext remain under Attomus control in the UK.

Attomus Limited is the data controller for SemaFore under UK GDPR. Individuals can contact hello@attomus.com to exercise access, rectification, erasure, restriction, portability, or objection rights.

Read the full whitepaper

This page is a summary of SemaFore’s current security and compliance posture. For deeper technical review or due-diligence material, read the Architecture and Threat Model, including its downloadable PDF.