
Product
One platform. Every mission-critical channel.
Silentel replaces the patchwork of consumer apps, radios, conferencing tools, and unsecured file transfer with a single sovereign platform for voice, messaging, file exchange, screen sharing, video calls, and Push-To-Talk.
Silentel isn’t a messaging app with security features bolted on.
It’s a communications platform built from the ground up for organisations that cannot risk a single breached call or an unaccounted-for message. It runs on the commercial iOS, Android, Windows, and MacOS devices your teams already carry, no hardened handsets necessary, no separate device fleet to procure or maintain.
01 / 03
Per-user certificates
Every user automatically creates an individual certificate in the client app that encrypts their content; the server never holds a copy.
Silentel isn’t a messaging app with security features bolted on.
It’s a communications platform built from the ground up for organisations that cannot risk a single breached call or an unaccounted-for message. It runs on the commercial iOS, Android, Windows, and MacOS devices your teams already carry, no hardened handsets necessary, no separate device fleet to procure or maintain.
Per-user certificates
Every user automatically creates an individual certificate in the client app that encrypts their content; the server never holds a copy.
Post-quantum ready
ML-DSA and SLH-DSA signature schemes layered with classical ECC for long-lived certificate validity.
Blind relay
The server cannot read message content or files; it only routes between authenticated endpoints.
Endpoint application
Silentel Client
Every channel your team needs, inside one closed system.
Silentel Client is not a messaging app with security bolted on. Voice, messaging, files, video and field coordination run through the same accounts, the same groups and the same end-to-end architecture - so there is never a weaker channel to fall back on.

Apple Silicon
iOS & macOS
One build for iPhone, iPad and Apple Silicon Mac - Apple Silicon runs the same App Store app natively, with no separate desktop build to install.
- Requires iOS 16.0 or later.
- Compatible with iPhone, iPad, and iPod touch.
- Requires macOS 13.0 or later and a Mac with Apple M1 chip or later.
Administration console
Silentel Studio
Administration built for control, not complexity.
Silentel Studio is where your team provisions users, manages user groups and sets feature privileges, without ever gaining access to message content itself. Content is encrypted using the user’s own certificate and remains inaccessible to anyone other than the user, including Studio, administrators, system operators and service providers.

Silentel Studio: Administration built for control, not complexity
Silentel Studio governs who exists on the system and what they’re allowed to use. It never governs what they said. Content stays encrypted by the user’s own certificate at all times, including while a user is logged out, and remains inaccessible to anyone other than the user, including Studio administrators, system operators, and Ardaco itself.
01 / 03
User and group management
Organise users into groups and organisational units, with feature privileges set per group.
Silentel Studio: Administration built for control, not complexity
Silentel Studio governs who exists on the system and what they’re allowed to use. It never governs what they said. Content stays encrypted by the user’s own certificate at all times, including while a user is logged out, and remains inaccessible to anyone other than the user, including Studio administrators, system operators, and Ardaco itself.
User and group management
Organise users into groups and organisational units, with feature privileges set per group.
Built for scale
Onboard and manage large user bases without the administrative overhead growing alongside them.
Strong authentication by default
A user token is required to access messages, a requirement that cannot be bypassed by credentials or ordinary two-factor authentication alone.
On-premises infrastructure
Silentel Server
Your infrastructure, your jurisdiction, nothing retained.
Silentel Server routes every session between authenticated clients without ever being able to read them. There is no cloud tier, no foreign infrastructure and no third party in the path - and because nothing is logged, there is nothing to hand over or leak.
48 h
0
50+
Security that assumes the worst case
This is the same layered design behind every Silentel deployment: sovereignty, verification, data minimisation, device behaviour, and encryption each stand on their own, so no single layer ever has to hold alone.
01 / 05
Two independent encryption layers
Post-quantum cryptography has not been tested in real-world conditions, since no quantum computer capable of testing it against a real attack exists yet. Silentel layers it on top of a second, independently strong classical standard, so protection never rests on one unproven bet.
Security that assumes the worst case
This is the same layered design behind every Silentel deployment: sovereignty, verification, data minimisation, device behaviour, and encryption each stand on their own, so no single layer ever has to hold alone.
Two independent encryption layers
Post-quantum cryptography has not been tested in real-world conditions, since no quantum computer capable of testing it against a real attack exists yet. Silentel layers it on top of a second, independently strong classical standard, so protection never rests on one unproven bet.
Fully on-premises
Deployed entirely on your own infrastructure. No cloud, no foreign servers, no third party with access to your traffic.
No personal data collected
Silentel doesn’t require personally identifiable data to operate, so there’s nothing retained for an attacker, or anyone else, to find.
Nothing left behind on the device
The Silentel client application doesn’t store data permanently, and wipes autonomously if it loses connection to the server.
Verified, not self-declared
The first solution for standard commercial mobile phones listed in the NATO NIAPC catalogue, certified since 2006, independently reviewed by national security authorities. Unlike most commercial platforms, these claims can be checked, not just taken on trust. We’re glad to walk through how, in a briefing.
Certificate authority
Silentel CA
The root of trust stays inside your organisation.
Silentel CA issues the certificates that make every call, message and map layer verifiable. It runs as your own private PKI, so no external authority and no vendor ever holds material that could be used to impersonate a user or decrypt a session.
ECC-521
Offline
0
Technical
Runs on the devices already in the field
No hardened handsets, no separate SIM estate, no parallel device fleet to procure and maintain.
- Platforms
- iOS, Android, Windows, MacOS - commercial off-the-shelf devices
- Encryption
- AES-256 and ECC-521, layered with FIPS 203 / 204 / 205 post-quantum primitives
- Authentication
- User token required to access messages; cannot be bypassed by credentials or SMS 2FA alone
- Data at rest
- Reverse-logic protection, temporary device data, automatic wipe triggers
- Connectivity
- Any IP connection - mobile, satellite or Wi-Fi
Technical
Administrative reach stops at the envelope
Studio governs who exists and what they may use - never what they said.
- Scope
- Server settings, user accounts, groups, organisational structure, feature privileges
- Content access
- None - content remains encrypted by the user certificate at all times
- Provisioning
- QR code credential issuance; structured bulk import
- Authentication
- Two-factor administrator login; user token enforced for message access
- Deployment
- Runs alongside Silentel Server inside your own environment
Technical
Standard infrastructure, sovereign result
No specialist hardware and no vendor-operated tier - the whole system runs on infrastructure your team already knows how to operate.
- Deployment model
- On-premises, deployed on Windows Server
- Data retention
- No personal data, no metadata, no message content stored
- Transport
- End-to-end encrypted sessions; server holds no decryption material
- Assurance
- NATO approved and listed in the NATO NIAPC catalogue; source code review available
Technical
A PKI built for classified environments
Designed to satisfy organisations that must demonstrate exactly who can decrypt what, and prove nobody else can.
- Key algorithms
- ECC-521 with FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) signatures
- Hierarchy
- Offline root CA with one or more online issuing authorities
- Revocation
- CRL and internal revocation distribution to all connected clients
- Hardware
- Optional HSM binding for root and issuing key storage
- Deployment
- Fully on-premises; no external OCSP or CA dependency