In May 2025, one of the best-known names in message archiving was breached. The service ran modified versions of WhatsApp and Signal, and kept a readable copy of every client's messages on its own servers – senior US government officials' and major financial firms' alike, all in one place. The intruder reportedly needed less than half an hour. Message content was stolen, the flaw entered the US government's catalogue of actively exploited vulnerabilities, and the service was suspended.
We take no pleasure in the story – the people involved were working on the same problem we are. We retell it because the lesson is not about one company's carelessness; it is about shape. A supplier that holds everyone's records has built a single, well-signposted prize. That break-in wasn't bad luck. It was the shape.
So we built the opposite shape. The record is made in our system and handed straight into your own Microsoft 365 from your own channel, or – where the conversation runs on Microsoft Teams, no changed apps, nothing bolted on – captured and passed into the same Microsoft 365. The permanent record of truth rests in your own Microsoft 365 – with you, not us, per organisation and never pooled. We never become your system of record. To run the channel we hold a working copy of message content, which you control – a 90-day purge, or a dedicated deployment in your own Azure – and our billing systems only ever see the plan, the number of lines and whether the service is running. An attacker who wanted a hundred organisations' permanent records would have to break into a hundred organisations, one set of locks at a time. There is no single shared vendor vault pooling everyone's record of truth, so there is no pooled archive to steal.