Ascaion
Product platform · Services · Secure communication

Words, files, forms — for the two of you only.

End-to-end encrypted communication, in the Absidion app and the web interface. Texts, files and forms — and groups with clear roles, in the platform's permission model.

The server carries ciphertext. The plaintext arises on the device — and nowhere else.

E2E
Forward secrecy
Hosting
CH · EU
Certified
ISO 27001 · 27018
absidion.app/talk/g/project-2026
WEB
Groups
Project 2026 3
Case · F-1148
Staff · ops 1
Ext. partners
New group
Project 2026 · 6 members
End-to-end · 3 roles
MKABSBTR +2
M. Keller · Owner
I'm uploading the current version of the agreement.
agreement_v3.pdf
412 KB · v3
FILE
A. Brun · Write
Please send the application form too — then we can release.
You · Moderate
Here — please fill it in directly.
Application · release
6 fields · required
FORM
S. Bianchi is typing …
Message or /form …
9:41
Project 2026
End-to-end
I'm uploading the version.
agreement_v3.pdf
Please send the form too.
Here — please fill it in.
Application · release
Message …
Key verified
9f3a · cba2 · 17de · …
01
Absidion app
iOS · Android · push
Plaintext arises here
02
Web interface
Browser · web push
Plaintext arises here
Platform
CIPHERTEXT ONLY
Transport · storage · routing
Identity, permissions, audit trail — shared across app and web. Plaintext and keys stay on the device.
Identity
Keys
Audit
One platform, two surfaces

Encryption that fits the workplace.

Secure communication is not a foreign body in the toolkit — it is a platform service. You can exchange texts, files and forms in one conversation, in the native Absidion app or in the web interface, with the same security model and the same identity as at any other point of the platform.

Groups, roles and permissions follow the model you know from the specialised processes — not a separate chat logic that would have to live somewhere on the side.

Highlights

Four traits that carry.

End-to-end encrypted, in app and web, for texts, files and forms — in groups with clear roles.

01

End-to-end encrypted

Messages, attachments and form responses are encrypted on the device and only decrypted at the recipient.

Key path
You
Server
Counterparty
9f3a · cba2 · 17de · 4e08 · … CIPHER
Keys on the device · forward secrecy
02

In the app and the browser

End-to-end encryption in the native Absidion app and in the web interface — both surfaces with a closed key path. Pick the channel that fits the situation.

App
Push
Biometrics
Offline
Web
Browser
Web push
Multiple tabs
Both surfaces · closed key path
03

Text, file, form

A conversation can be a short message, a confidential attachment or a structured form. All in the same encrypted channel, with preview, versioning and audit trail.

Conversation 3 elements
Please send the form too.
agreement_v3.pdf · 412 KB
Application · release · 6 fields
All in the same key path
04

Groups with roles

Group chats with clear roles: who may read, who may write, who may invite, who may delete. Roles follow the platform's permission model — not a separate chat logic.

Group · roles 4 members
NAMEROLERWID
M. Keller Owner
A. Brun Write · ·
S. Bianchi Read · · ·
Ext. · T.R. Guest · · ·
Use cases

Where a protected conversation makes the difference.

Internally, with external partners, with citizens — wherever content must not travel through someone else's inbox and the conversation should stay on the case, not in a private chat.

01
Confidential consultation

Two case workers clarify a sensitive matter directly on the case — without an external messenger or a plaintext email attachment.

02
Encrypted document exchange

A confidential dossier is handed over via the encrypted channel — with versioning and read receipt — rather than as a mail attachment.

03
Form in the chat

An external person receives a link via the portal, answers a structured form, and can ask questions back at any time — encrypted.

04
Project group with externals

Employees and external partners work in the same group — each with the rights their tenant and role provide.

05
Citizen request

A citizen writes from the portal to the responsible unit. The conversation stays on the case, not in someone else's inbox.

06
Crisis staff

An operations cell coordinates in a closed channel — push to the phone, fully at the workstation too, all encrypted.

All capabilities

What secure communication delivers in the platform.

Six areas — from encryption itself through the two surfaces, the supported content and the role model to integration into the platform and the compliance frame.

Encryption

End to end, with keys on the device — not on our server.

End-to-end encryption

Content is encrypted locally; the server carries only ciphertext. Even we cannot read the plaintext.

Forward secrecy

Session keys are continuously rotated. A compromised key does not open old messages.

Device verification

Every device has a visible security fingerprint. New devices on the counterparty's side are explicitly confirmed, with a warning on key change.

Keys on the device

Private keys do not leave the device — neither in backups, nor in sync, nor in support cases.

Attachments equally encrypted

Files, images, voice notes and form responses run on the same key path as the messages.

Established crypto libraries

Built on proven, regularly audited algorithms — no home-grown crypto.

Surfaces

Secure conversation in the Absidion app and the web interface.

Native Absidion app

iOS and Android, with push, biometrics and background sync — plaintext arises only on the device.

Web interface

In the browser, without a plug-in or separate install — end-to-end encrypted, with a closed key path.

Multiple devices

Several devices per surface, with mutual device confirmation and a visible device list per identity (in the app).

Identical capabilities

What the app can do, the web can do — and vice versa. No second-class surface, no "PC only" notice.

Offline reading

Readable offline in the app; actions sync on connection — also encrypted at rest on the device.

Push & web push

Alerts for new messages via Apple Push, FCM and web push — the actual content does not travel in the push, but is decrypted locally.

Content

Text, file, form — all in the same encrypted channel.

Text messages

Direct messages, mentions, quotes, reactions — short and fast, without formal hurdles.

Files & images

Attachments up to the configured tenant limit, with preview, versioning and optional expiry.

Structured forms

Forms from the form designer as a conversation element — responses land encrypted on the case, not in a mail inbox.

Quotes & threads

Reply to messages, quote histories, threads per topic — readably ordered even under encryption.

Edit & retract

Fix typos or retract a message — visible to all participants, with an audit entry.

Groups & roles

Who may see, write and invite — finely steerable, in the platform's permission model.

Group chats

Closed groups with verified members, internally or across tenants.

Roles per group

Owner, moderator, write, read, guest — each role with clear rights and visible status.

Read-only observers

Supervisory bodies read along without altering the conversation — without breaking the key path.

Invite & remove

Members are invited with their identity and can be removed in a controlled way — new keys from joining onwards.

External participants

External people join via the portal, with their own account, identity and key.

Cross-tenant

Groups across tenant boundaries are possible — with separate tenant config and clear visibility rules.

Integrated in the platform

A conversation belongs to a case, a project, a contact — not to an inbox.

Anchored to the case

Conversations hang on the record: case, project, contract, contact. Whoever opens the record sees the conversation — if entitled.

Identity-bound

Every message is bound to an identity, with the same ACL checks as the record itself.

Audit trail

Who wrote, edited or read what when — traceable in the platform's audit trail.

Workflow triggers

A message can kick off a workflow — receipt of a reply, receipt of a form, approval step.

Permissioned search

Your own conversations are full-text searchable locally — plaintext index on the device, not on the server.

Retention & deletion

Retention periods and automatic deletion per group are configurable — encrypted at rest, forgotten under control.

Compliance & operations

Security is the default — not a feature you have to switch on.

Data residency CH / EU

Hosting in Switzerland or the EU area, depending on tenant — encrypted storage at the chosen site.

ISO 27001 / 27017 / 27018 / 27701

The platform service runs in the same certified management system as the rest of the Absidion platform.

Per-tenant key separation

Key material and conversations are separated per tenant — no shared key space, no shared search basis.

Emergency recovery

Users can deposit encrypted recovery keys — controlled, without a backdoor master key.

Export & supervision

Supervisory exports per tenant with a documented four-eye principle — not secretly, not centrally, but defined.

Penetration testing

Regular external tests of the crypto and application stack, with a list of findings and a fix status per release.

Absidion product platform

All processes and services at a glance.

From any Absidion page, navigate to every other process and to the services that work across all of them.

Next step

See Absidion secure communication in action.

A short demo where we're happy to answer your questions in person. No commitment, no sales theatre.

01 Request a demo