Processing...

 Matrix Secure Messaging, Hosted or On-Premises

Open, encrypted, federated messaging you own, hosted in the UK or on your premises

Matrix is the open standard for secure, federated messaging. It runs on a homeserver you own, or one GEN host for you in the UK, with end-to-end encryption on your users' devices and federation only where you allow it. It is messaging as infrastructure you control, rather than a service you rent from a platform whose priorities are not yours.

Matrix is also what we use ourselves. GEN's own internal messaging runs on a Matrix homeserver inside our secure environment, so the design, hosting, integration and support we offer come from running it every day, not from reading about it.

  • "We need to get staff off WhatsApp groups"
  • "Our chat data has to stay in the UK"
  • "Partners need to reach us, but nobody else"
  • "Our Slack history has to come with us"
Our ownInternal messaging platform runs on Matrix
OpenStandard, servers and clients, with no single vendor
On deviceEncryption, so servers store only ciphertext
Your choiceUK hosted, single tenant, on-premises or hybrid

Who Holds the Keys

Most people assume that if an app says its messages are encrypted, nobody else can read them. What decides that is not the word encrypted, but who holds the keys, who runs the servers and who writes the software on your phone. Whoever holds any of those can be required by law to use them, often without being allowed to tell you.

ServiceRun byWhere the keys sitWhat that means
WhatsAppMetaMessage keys on each phone. A new phone gets its history from a cloud backup Apple or Google can read unless the user switches on encryption, or from a key held in Meta's own key vault when the backup is protected by a password The ease of moving to a new phone comes from the keys being kept off the phone. One company also runs every server, writes the app and holds the record of who talks to whom
iMessageAppleMessage keys on each device, but with iCloud Backup on, Apple holds the keys to the backup, and the messages in it Advanced Data Protection, which moves those keys to the device, has not been available to new UK users since February 2025
TelegramTelegramOrdinary chats are encrypted with keys Telegram holds; only secret chats, which are off by default, are end to end Most Telegram conversations can be read by the company that runs it
SignalSignal FoundationMessage keys on each phone, and very little stored about you The strongest of the consumer apps, but still one organisation running the only servers, tied to a phone number, with no way to run your own
Microsoft Teams and SlackMicrosoft, SalesforceChats encrypted in transit and at rest, with keys the provider holds by default Readable by the provider, and disclosable to anyone with a lawful demand in its jurisdiction

The common thread is a single company in the middle. Keys it holds can be handed over. An app it writes can be changed. Metadata it keeps can be disclosed. Under UK law the Investigatory Powers Act lets the Home Office require a provider to change what it offers, and Apple withdrew Advanced Data Protection from UK users rather than build what it was reportedly asked for. Every other jurisdiction has its own version.

Matrix walks away from that model. Your organisation runs its own server, or we run it for you, and it talks to the servers other organisations run, exchanging only encrypted messages. The keys are created and kept on your users' own devices. There is no company holding them, no company running every server, and no one company that can be compelled to open everybody's messages.

With Matrix

  • Your server, on your premises or hosted by GEN in the UK
  • Keys created and held on your users' devices
  • Other organisations' servers receive only encrypted messages
  • No central company to target, compel or switch off
  • Open code, so anyone can check what it does

No system is immune: a compromised phone can still read what it decrypts, which is why we build device verification in from the start. What Matrix removes is the company in the middle.

Why Organisations Are Moving to Matrix

Messaging now carries operational decisions, customer information, contract negotiations and incident response. Across government, defence supply chains and other high trust environments, there is growing pressure to stop running that traffic through consumer and closed source apps. The driving force is sovereignty: who controls the code, the encryption keys, the infrastructure, the data residency, and the response when something goes wrong.

Closed central platforms concentrate risk. Even with end-to-end encryption, every customer has to trust one vendor's implementation, update pipeline, telemetry and account recovery process, and any mechanism the vendor keeps for recovery, eDiscovery or lawful access becomes a target in its own right. When a central control plane is compromised, every organisation on it is exposed at once.

How messaging data actually leaks

  • Metadata: who spoke to whom, when, from where and in which groups
  • Account takeover: phishing, SIM swaps and weak recovery processes
  • Endpoints: mobile malware, insecure backups and unmanaged devices
  • Central administration: admin consoles and bulk exports as a single point of failure
  • Drift: sensitive discussion spreading into group chats outside any policy

Public bodies have already made the move. The French government's messenger, Tchap, and the German armed forces' BwMessenger are both built on Matrix, and Element, a Matrix client, is the messenger in Germany's openDesk workplace suite for public administration.

Messaging and Your GDPR Obligations

When staff discuss customers in a chat app, that chat is processing personal data, and under UK GDPR and the Data Protection Act 2018 the responsibility sits with your organisation, not with the app. Customer names, numbers, addresses, photographs of documents and screenshots of accounts all count, and so does the chat itself.

Security you can show

The law requires security appropriate to the risk, and the ability to demonstrate it. A consumer app on phones your staff own sits outside anything your organisation controls, configures or can evidence.

Knowing where the data is

You have to know what personal data you hold, where it is and who can see it. A WhatsApp group on staff phones is invisible to the organisation, and anyone can be added to it, by design or by mistake.

Retention and erasure

Personal data must be kept no longer than necessary and deleted when someone asks. On staff phones neither can be enforced, and the data walks out of the door when the member of staff does.

Subject access

A subject access request has to be answered within a month, from everywhere that person's data is held, and that includes the chats. Searching every member of staff's personal phone is not a process anyone can run.

Other people's details

WhatsApp asks for the phone's address book and shares the numbers in it with Meta on a regular basis, including those of customers and contacts who have never agreed to it and may not use WhatsApp at all.

No processing contract

Anyone processing personal data on your behalf must do so under a written contract with the terms UK GDPR requires. A consumer app on a staff phone comes with no such contract with your organisation.

The Information Commissioner can fine up to £17.5 million or 4% of annual worldwide turnover, whichever is higher, for the most serious failures, including breaches of the core principles, and up to £8.7 million or 2% for others. Reprimands, enforcement notices and the publicity that goes with them usually arrive first, and cost more than the fine in lost trust.

No recognised information security standard treats a consumer chat app on staff-owned phones as an acceptable home for customer data. A Matrix service your organisation owns answers every point above: accounts from your own directory, removed when someone leaves, retention policies you set, data held in the UK, audit of administration, and GEN as your processor under a proper agreement. Our compliance work covers the rest.

It has already happened

  • NHS Lanarkshire, 2023: reprimanded by the ICO after 26 staff shared patient data in a WhatsApp group more than 500 times over two years, including names, addresses and clinical images, with a non-member of staff added in error
  • US banks, 2022 onwards: US regulators fined 16 major banks US$1.8 billion for staff doing business over WhatsApp and other unapproved apps, and more than US$3 billion across over 100 firms since

How Matrix Works in Practice

Matrix is not an app owned by one company. It is an open standard with several server implementations and a choice of clients for desktop, web and mobile, so you are not tied to one supplier, one product direction or one commercial agenda. Three things change the trust model.

A homeserver you control

Your accounts, rooms and message store live on your own homeserver, on your premises or hosted by GEN in the UK, under your policies and in the jurisdiction you choose.

Federation on your terms

Keep messaging strictly internal, or federate with other organisations' homeservers through allow and deny lists. Each side keeps its own server and its own data, and there is no central operator able to switch the network off for everyone.

Encryption on the device

Matrix end-to-end encryption (Olm and Megolm) encrypts and decrypts on users' devices. Servers store and replicate ciphertext, including across federation, and are not in a position to read message content. The cryptography is open to review by anyone.

No platform removes risk entirely. Endpoints, identity and device verification still matter: a compromised phone reads messages after they are decrypted, and an unverified device is a device you are trusting blindly. What Matrix removes is the provider and the hosting layer as a permanent, unavoidable point of trust for message content, and we build the verification, key backup and device policy around it.

What GEN Do

We deliver Matrix as a dependable business platform: from the first architecture decision through deployment, integration and years of operation. Every engagement starts with a review of who needs to message whom, what they share and what obligations apply, and a threat model of how somebody would realistically try to get at it. The same team then designs, deploys and runs it.

Design

Server sizing, storage, encryption and key management, federation policy, room structure and access control, designed for long term maintainability rather than a quick demonstration.

Hosting

Hosted in our own UK data centres, on dedicated single tenant infrastructure, installed and hardened on your own premises, or a hybrid of those, with GEN managing the whole lifecycle if you want us to.

Identity integration

Accounts provisioned from LDAP or Active Directory, with single sign-on over SAML or OIDC, so joiners and leavers are handled in one place.

Retention and audit

Retention policies set to your obligations, and audit logging of administrative actions, so you can evidence how the service is governed.

Backups and recovery

Secure backups of the homeserver and its database, and disaster recovery planned and tested, not assumed.

Bridges, bots and integrations

Bridges to other networks where policy allows, workflow bots, room automation and connections into your CRM, service desk and business systems.

Voice and video

Jitsi hosted and managed alongside Matrix to keep calls private and stable, and integration with Webex and Zoom where those are already in use.

Monitoring

Updates and maintenance applied for you, and the homeserver, federation, storage and certificates can be watched continuously through Oversight.

Support

UK engineers who run Matrix themselves, reached through the HelpDesk, with documentation and training for your administrators and users.

Messaging Connected to Your Business

Matrix is a messaging platform with an open API, which makes it a good base for workflow. Conversations can trigger actions, surface data, notify teams and capture events as they happen, so the messaging service is connected to the rest of the business rather than sitting beside it.

We use it that way ourselves. Alerts from Oversight, our monitoring platform, are delivered into Matrix rooms formatted for the channel, and new enquiries from our own website arrive in a Matrix room for the team to pick up.

The development work is done by the same team that builds our chatbots and backend systems, and is supported for the long term.

Typical integration work

  • Authentication and account provisioning
  • Room automation and workflow bots
  • CRM and service desk integration
  • Customer messaging embedded in a website
  • Alerting from monitoring and business systems
  • API integration with bespoke applications

Moving to Matrix

Most organisations arrive at Matrix from somewhere else: an ageing XMPP server, a Slack workspace, Microsoft Teams chat, or a scatter of WhatsApp groups nobody formally approved. The move is planned so that control of identity, history and retention is never lost on the way.

How much history comes across, and in what form, depends on what the old platform will export. Where it cannot export cleanly we say so at the start, and agree what is archived, what is migrated and what is left behind, before anyone changes the app they use.

Planned before anything moves

  • Identity: accounts mapped to your directory and single sign-on
  • History: what is exported, imported or archived
  • Retention: policies carried over and applied from day one
  • Rooms: channels and groups mapped to a sensible room structure
  • Federation: which outside parties, if any, you will talk to
  • People: clients rolled out and users shown how to verify devices

Matrix Questions

What is Matrix?

Matrix is an open standard for secure, federated messaging, with open source servers and clients for desktop, web and mobile. Each organisation runs its own homeserver, or has one run for it, and homeservers can talk to each other in the way email servers do. Messages can be end-to-end encrypted, so the servers carry and store them without being able to read them.

Can we talk to people outside our organisation?

Yes, if you choose to. Federation lets your homeserver exchange messages with other Matrix homeservers, so staff can share rooms with partners, suppliers and customers while each side keeps its own server, accounts and data. We can open federation to everyone, restrict it to an allow list of named partner domains, or block specific servers, and end-to-end encryption continues to work across the boundary.

Do we have to federate?

No. Federation is optional and many organisations leave it switched off, running Matrix as a private internal service that no outside server can reach. GEN's own internal messaging works exactly that way. It is also common to start internal only and later open federation to a short list of partners.

Can GEN read our messages?

Not in end-to-end encrypted rooms. Messages are encrypted and decrypted on the users' own devices, and the homeserver only ever stores ciphertext, so GEN as the host hold nothing we could read. The server does need some information to route messages, such as which accounts are in which rooms and when messages were sent, and we explain exactly what that is during design. If you run the homeserver on your own premises, GEN need not hold anything at all. Where a compliance archive of message content is required, it has to be designed in deliberately, and we set out the trade-off before it is built.

Can we migrate from Slack or Teams?

Yes. We plan migrations into Matrix from Slack, Microsoft Teams chat, WhatsApp groups and XMPP, with identity, history and retention agreed before anything moves. How much history comes across, and in what form, depends on what the old platform will export, and where it cannot export cleanly we say so at the start rather than part way through.

Where is our data hosted?

Where you decide. GEN can host your homeserver in our own UK data centres, on dedicated single tenant infrastructure, or install it on your own premises, and hybrid arrangements are possible. With end-to-end encryption enabled, the message content on the server is ciphertext wherever it sits.

Which apps do our staff use?

Matrix has a choice of clients for Windows, macOS, Linux, the web, iOS and Android, Element being the best known. Because the protocol is open, you are not tied to one supplier's application, and the client can be changed later without changing the server or losing your history.

Do you still support XMPP?

Yes. GEN operated XMPP messaging for many years and still maintain and harden existing XMPP estates. For most customers we recommend a planned move to Matrix, with identity, retention and security carried across rather than rebuilt afterwards.

Messaging You Own

Whether you are replacing a consumer app, leaving a closed platform, or starting from nothing, we can design a Matrix service around the way your organisation actually communicates, host it or install it for you, and run it for as long as you need it.

Messaging usually sits beside email, and we run both. See our email services for the other half of the picture.

Contact Us