SemaFore

For Organisations

SemaFore is sold to organisations, not individuals. Governance, billing, access control, and data-processing responsibilities stay with the organisation.

How organisations use SemaFore

Every SemaFore account belongs to an organisation. There are no personal SemaFore accounts. This is a deliberate architectural decision: the platform is built for organisations that need to control who participates in their communications, and to be confident that when someone leaves, their access ends immediately.


Getting started

Access begins through the SemaFore evaluation programme. Once an application is approved, the nominated administrator receives the organisation access details. Approved organisations can use the free tier with up to 5 members and no time limit.

For larger teams, the Professional tier removes the 5-user ceiling entirely — add as many members as your organisation needs at £9 per user per month. Approved organisations can begin a 30-day trial from the portal billing section, with up to 25 seats during the trial period. To discuss requirements before applying, get a briefing.


Typical deployment

A typical rollout usually unfolds in two steps:

Day one. Following evaluation approval, the administrator receives access to the organisation and adds employees by phone number. Each receives a verification SMS. They download the SemaFore app, verify their identity, and appear in the portal for approval.

Ongoing. The administrator approves new users, manages access as people join and leave, and reviews the audit log. Employees communicate. The platform runs without intervention.


What your administrator can and cannot do

Can:

  • Add, approve, disable, and remove employees
  • See who is in the organisation and when they were added
  • Review the administrative audit log in full
  • Configure organisation-wide notification settings
  • Export the organisation’s administrative data
  • Manage billing and subscription from the portal

Cannot:

  • Read message content
  • Access encryption keys
  • Retroactively alter the audit log
  • Impersonate another employee’s messaging session

This balance — full control over access, no access to content — is intentional. Your administrator needs to be able to run the platform without being able to compromise its confidentiality guarantees.


Pricing

Free Up to 5 approved members. No time limit. Full SemaFore architecture: end-to-end encryption, admin portal, iOS and Android apps, audit log.

Professional — £9 / user / month (annual) · £11 / user / month (monthly) No seat ceiling. 90-day audit log retention with CSV export, in-app admin metrics, message delivery indicators, email support. 30-day trial available from the portal billing section after evaluation approval, up to 25 seats during the trial period, cancel any time before the trial ends.

Enterprise — custom pricing For organisations that need a negotiated contract, dedicated support SLA, or a DPA tailored to specific regulatory requirements. Includes everything in Professional plus unlimited audit log retention, 4-hour SLA, dedicated customer success manager, and custom contract. Get a briefing about requirements and timelines.


Data processing

SemaFore processes the following data on behalf of your organisation:

  • Employee phone numbers (for authentication)
  • Message ciphertext (queued for delivery; not retained after delivery)
  • Delivery metadata (timestamps, delivery status)
  • Administrative actions (for the audit log)
  • Device registration information

We are the data processor. Your organisation is the data controller. We will sign a Data Processing Agreement appropriate to your jurisdiction. A standard DPA is available on request: hello@attomus.com.

The SemaFore messaging servers and customer message and file ciphertext storage run on Attomus-operated UK infrastructure. The public website and portal interface run on Cloudflare; the Privacy notice describes that boundary and the separate support services.


Security and compliance

Security review should not need a product tour. Send over a questionnaire, or book a technical call if your engineering team wants to test the architecture.

Independent penetration test summaries are available to enterprise customers under NDA. For implementation-level review, see the Architecture and Threat Model on docs.semafore.io.

Key recovery, onboarding boundaries, retention, and audit are covered in Security Approach.

Apply to evaluate, get a briefing, or write to hello@attomus.com.