Secure Business Messaging · An Attomus Product
Communication that stays contained.
Semafore is secure messaging for teams that need private conversations, file exchange, and controlled communications to remain between the intended parties — without relying on consumer-grade handling or hoping the platform provider does the right thing.
The server routes your messages. It cannot read them.
That is not a policy. It is how the architecture works.
How it works
Tighter handling without asking you to trust us.
Messages leave your device already sealed
Semafore encrypts every message on-device using a session key the server never sees. The underlying protocol is Signal (X3DH key agreement + Double Ratchet forward secrecy) — the same standard used by organisations with an active interest in not being intercepted.
The server routes. It does not read.
The Semafore server receives ciphertext and forwards it. There is no moment where message content exists in plaintext on any Attomus-operated system. Decryption requires keys that live only on your devices. This is not a configuration option. It is the architecture.
Administration without surveillance
Platform administrators have a full audit trail of activity — who sent to whom, when, file transfers, group membership changes — and no access to content. Governance and discretion are not in tension. They are the same thing.
The Platform
An admin portal that is honest about what it shows.
The Semafore admin portal gives operations and compliance teams visibility into platform activity, user management, and communication volumes — without a single word of message content. Organisations under meaningful scrutiny can govern the platform without the platform becoming a liability.



Messaging teams will actually use.
The mobile clients — iOS and Android — work like a modern messaging application. End-to-end encryption runs without user intervention. Communication stays moving across offices, travel, and distributed teams without relying on consumer tools or workarounds.
Made by Attomus
A product from the firm trusted by government, defence, and regulated enterprise.
Attomus supports the Home Office, the Ministry of Defence, Boeing, Johnson & Johnson, and BAE Systems with cybersecurity and programme delivery where the standards are high and follow-through matters. Semafore comes from the same focus: tighter handling, dependable execution, and tools that solve a specific operational need.
JOSCAR Registered
Pre-qualified for defence, aerospace, and security procurement.
Armed Forces Covenant
Signatory. Attomus operates with the conduct that sensitive environments require.
Mayfair, London
23 Berkeley Square.
Registered in England & Wales. No. 06517654.
For Organisations
Built for work that carries real risk.
Data Sovereignty
All server infrastructure runs on Attomus-owned hardware in the United Kingdom, behind Attomus’s own network boundary.
No hyperscale cloud provider — no AWS, Azure, or GCP — processes or stores your organisation’s data. Databases, message queue, and key store are on Attomus infrastructure. Data does not leave UK jurisdiction in normal platform operation.
ICO Registered
ZA718457
UK GDPR Compliant
Contained messaging
Private and group threads, encrypted end-to-end. Messages stay between the intended parties.
Secure file exchange
Files are encrypted client-side before upload. The server stores ciphertext and never sees the content.
Organisation administration
Manage users, groups, and platform governance without accessing message content.
Full audit trail
Every platform event logged with actor, timestamp, and type. No content. No surprises.
Push delivery without exposure
Notification payloads contain no message content. Devices fetch and decrypt on wake.
Forward secrecy built in
Key rotation and one-time pre-key replenishment run automatically. Sessions stay forward-secret.
Free for 1–2 users · Licensed for teams and wider deployments
Discuss a Requirement
Secure communications
handled properly.
Speak to us about how Semafore fits your environment. Most first conversations take no more than twenty minutes.