For teams · Private deployment

Your organisation. Your relay.
The same encryption, under your control.

A private deployment is a dedicated, hardened instance of WingPost, pointed at your own domain, isolated from the public network, running the same post-quantum encryption stack your users already trust. The relay only ever moves ciphertext; the keys that unlock conversations live on your people's devices, never on any server. This page is the honest version: what changes, what doesn't, and how a pilot starts.

The deployment

A dedicated instance, not a tenant.

Not a shared account on someone else's server, a relay that belongs to your organisation, carrying only your organisation's encrypted traffic.

Dedicated, hardened relay
A separate, isolated instance provisioned for your organisation alone. None of your traffic is queued alongside the public network, and nobody outside your deployment is routed through it.
Pointed at your domain
Your users connect to your hostname, not ours, your network, your brand, your control plane. The deployment lives where your operations team can see and govern it.
The same crypto stack
No stripped-down "enterprise lite." Messages and media get ML-KEM-1024 key exchange, the Double Ratchet, and AES-256-GCM; calls use WebRTC's DTLS-SRTP. Identical to the public app, isolated to you.
Your team holds the keys
Server identity and infrastructure keys sit under your control. End-to-end message keys never touch any relay to begin with, they're generated and held on each user's device, ours or yours.
Where the line sits

Honest about what private changes.

A dedicated relay narrows who can see operational metadata down to your organisation. It does not, and cannot, make end-to-end content readable. Here's the exact split.

Stays sealed end to end

  • Message bodies and their attachments, sealed on-device
  • Call audio and video, encrypted in transit, device to device
  • Conversation keys, generated and kept on each user's phone
  • Unchanged whether the relay is ours or yours

Your organisation controls

  • The instance itself and the domain it answers on
  • Server identity and infrastructure keys
  • Who is provisioned onto the deployment
  • Retention posture and when updates roll out

Even a private relay still sees

  • Routing metadata, which node IDs exchanged sealed packets
  • Coarse online/offline presence, unless a user hides it
  • Never the content, only that encrypted bytes moved
Built for

Where the network is part of the threat model.

Not for casual group chats, for the conversations where it matters who can even see that a conversation happened.

Confidential professional work
Legal, finance, and advisory teams holding privilege- and NDA-grade conversations that shouldn't sit on a consumer platform's servers.
Journalism & sources
Newsrooms protecting who is talking to whom, from their own infrastructure outward, where a leaked contact graph is itself the story.
Leadership & deal rooms
Boards, M&A, and investor communications that need to move off shared consumer apps without losing the convenience people expect.
Field & operations teams
Coordinated communications for teams operating where the network itself is hostile, and metadata exposure carries real-world risk.
How a pilot works

From a first call to your own relay.

We're running scoped pilots while the product hardens toward a wider launch. No off-the-shelf checkout, every deployment is sized to the partner.

01
Scope

A short call to understand your team size, threat model, domain, residency needs, and which controls actually matter to you. No deck required.

02
Provision

We stand up a dedicated, hardened instance isolated from the public network and point it at your domain, the same encryption stack, configured to your posture.

03
Onboard

Your team installs and connects to your hostname. Identities are node IDs, no phone numbers or emails collected to join. Verification happens in-app, device to device.

04
Operate

You run it day to day with our operational support, or take fuller control of hosting over time. Updates and retention move on your schedule, not ours.

Before you ask

The straight answers.

We'd rather tell you the edges now than walk them back in a contract later.

Does a private relay hide metadata too?
It changes who sees operational metadata, not whether it exists. Any relay that delivers a message must know which node ID to route it to. A dedicated deployment keeps that routing visibility inside your organisation instead of on a shared service, but content stays sealed end to end either way. Sender-anonymising delivery is on the roadmap, not shipped. The full, honest security model is on the security page.
Managed by you, or fully self-hosted?
Both are on the table, and both run the identical encryption stack. We can operate a dedicated instance for you with ongoing support, or work toward your operations team hosting a dedicated relay for your organisation directly. We scope which model fits during the first call.
What's the pricing?
There's no public price sheet yet, deployments are scoped per partner during the current beta. Tell us your size and needs and we'll be straight with you about what a pilot involves. No surprise lock-in, no consumer-grade ToS dropped on an enterprise.
Is it ready for a production rollout today?
WingPost is in active security hardening ahead of a wider launch, and pilots run with that understood. We won't promise an SLA we can't yet stand behind. If you need a battle-tested platform this quarter, we'll say so; if you want to shape one early, that's exactly who pilots are for.
Do the same limits as the public app apply?
Yes. Public broadcast channels are still public by design, signed voice notes verify the device rather than a courtroom, and losing a device still means there's no server-side recovery loop. A dedicated relay isolates your traffic, it doesn't rewrite the cryptography's honest edges, which are listed in full on the security page.
"

If a dedicated, private deployment is what your organisation needs, start with a plain conversation. Reach the team directly at team@anadevyra.com, tell us your size, your domain, and what you're protecting, and we'll tell you honestly whether a pilot fits.

AnA Devyra · For teams