Guide
Chat Control alternative: how to keep your business messages truly private
If your business runs on confidentiality — legal privilege, patient records, financial data, journalistic sources — the EU's "Chat Control" debate isn't abstract. It goes to the heart of whether your private conversations stay private. This guide explains what Chat Control is, why it matters for professionals, and what a genuinely private alternative looks like.
What is "Chat Control"?
"Chat Control" is the shorthand campaigners use for the EU's proposed Child Sexual Abuse (CSA) Regulation. The stated aim is to fight the spread of abuse material. The controversial part is how: earlier drafts pushed toward obliging messaging services to detect and report certain content — including, potentially, by scanning messages inside end-to-end encrypted apps before they're sent.
The politics keep shifting. Voluntary and temporary regimes have come and gone, and a permanent, mandatory version has repeatedly been debated in EU trilogues. The direction of travel worries security researchers, privacy regulators and industry alike, because once a scanning mechanism exists, it can be extended.
Why "just use an encrypted app" isn't enough
End-to-end encryption is necessary but not sufficient. With a consumer app you don't control:
- The server. Someone else holds the infrastructure, the metadata and, ultimately, the ability to change how the app behaves in a future update.
- The jurisdiction. If the provider sits inside a scanning mandate, your protection is only as strong as their willingness — and legal ability — to resist.
- The client software. Client-side scanning proposals target exactly this layer: the app on the device, before encryption.
For a firm, the meaningful question isn't "is it encrypted?" It's "who controls the system, and can they be compelled to look inside?"
What a real Chat Control alternative looks like
The strongest position is one where your firm — not a platform — is in control. In practice that means three things:
- Self-hosted infrastructure. The server runs for your firm, on infrastructure you choose, so no shared platform can flip a switch on your data.
- Audited, open encryption. A protocol like Matrix (Olm/Megolm) gives you end-to-end encryption that has been independently reviewed — not a black box.
- Jurisdiction you choose. Hosting outside mandatory-scanning regimes keeps the legal ability to compel scanning at arm's length.
How Sovryk approaches it
Sovryk is a self-hosted, end-to-end encrypted communications platform built for confidentiality-critical businesses. Instead of asking you to trust a platform, it puts the platform under your control:
- Dedicated instance per firm — your own private server, optionally hosted offshore.
- Built on Matrix — inheriting years of independent cryptographic review rather than reinventing it.
- Full workspace — encrypted messaging, voice and video calls, screen sharing and file sharing, with an admin console for your team.
- Human onboarding — your staff sign in with a username and password (no phone number, email optional); the cryptography stays out of their way.
Confidentiality that depends on someone else choosing not to scan is not confidentiality. Control is the only real guarantee.
Frequently asked questions
What is EU Chat Control?
It's the informal name for the EU's proposed CSA Regulation, which in various drafts would require messaging services to detect and report certain content, potentially including scanning within end-to-end encrypted apps.
Does Chat Control break end-to-end encryption?
Client-side scanning inspects messages on the device before encryption. Security experts widely argue this undermines the guarantees end-to-end encryption is meant to provide.
Is self-hosting legal?
Yes. Running your own communications infrastructure is a normal, legitimate business decision — the same reason organisations run their own email or file servers. Sovryk simply makes it practical.
How fast can we get started?
A demo runs on a private instance within a day. Moving your firm onto a dedicated instance typically takes days, not months.