Secure, hardened implementation of Matrix

Matrix Server with VPN and SSO

Rust Matrix server pre-integrated with WireGuard, MFA, & OIDC for secure access. Included in the RemoteRails Appliance.

Complete isolation, or federation with other Matrix homeservers

Secure Matrix federation

The Matrix homeserver built into our appliance supports a locked-down isolated mode entirely behind your Defguard VPN and SSO with zero metadata leakage, or federated mode for interoperable E2EE communication with other trusted homeservers.

High fidelity, encrypted voice & video calls with a universal Matrix ID which functions like an email address (@username:server.tld) – without relying on the centralized chokepoints of Slack, Teams, or Zoom.

Govern your own private Matrix server using the RemoteRails Appliance on any supported hosting option, ensuring data sovereignty and compliance with security requirements.


“The WebRTC components already configured in the appliance (LiveKit, LK JWT Service, Coturn) saved us literal weeks of effort getting Element Calls running for both internal & external users – behind tricky corporate firewalls and NAT set ups.”

— Infrastructure Lead, Specialty Consulting Firm

Zero-Knowledge End-to-End Encryption

The encryption of Matrix chats builds upon the industry-standard Signal Protocol (used in Messenger, WhatsApp, and RCS) with rotating session keys that provide Forward Secrecy. WebRTC-based voice & video calls, including 1:1 and group calls, are protected in-flight by DTLS-SRTP. The operator of the homeserver maintains zero-knowledge of users’ encrypted chats and calls.

Metadata Minimization

Your Matrix homeserver only exchanges metadata for room invitations and to negotiate Element Calls with the trusted homeservers on your federation whitelist. This prevents user list scraping by public homeservers, and harvesting of metadata that indicates who is talking to who else, and when. Guest accounts are disabled to prevent spam, but federation is still possible for external communication.

Homeserver behind WireGuard VPN

The RemoteRails Appliance provides an implementation of the Tuwunel Matrix homeserver behind Defguard, a hub-and-spoke VPN gateway and enrollment proxy, which facilitates the provisioning of WireGuard connection profiles. The VPN is split-tunneled and is exclusively for accessing applications hosted on the appliance.

Single Sign On with OpenID Connect

We integrated Defguard’s OIDC-compliant Identity Provider (IdP) with all applications in the RemoteRails Appliance, including Matrix, Nextcloud, Vaultwarden, and Stalwart Mail. This provides one unified login, with support for multi-factor authentication (MFA) and centralized on and off-boarding of users.

Private conversations as if you were face-to-face

Face-to-face equivalent privacy

The RemoteRails Appliance, including its Matrix server, incorporates state-of-the-art protocols developed independently in the open, but trusted by corporate users and public sector organizations – including European governments, NATO, and the Swiss Post.

Interoperates with Matrix Ecosystem

The Tuwunel implementation of Matrix is fully compatible and interoperable with Synapse, Continuwuity, and other Matrix homeservers, including the ESS (Element Server Suite) and ESS Pro. Your server can interact with any Matrix ID or room globally, if federation is switched on.

One Login for Matrix and Other Apps

The Defguard OIDC identity provider (IdP) unifies the login for Matrix, Drive, Office, Mail, & Vault in the RemoteRails Appliance, making it function as a single, seamless platform. The web login supports TOTP authenticator codes and Webauthn Passkeys + Touch/Face ID login for the VPN.

Memory & Resource Efficient

As a Rust-based Matrix server, Tuwunel is very economical on memory usage utilizing < 1 GB RAM for small instances at idle. It leverages RocksDB for primary storage, with support for offloading media to the local filesystem or S3-compatible storage.

Reduced Attack Surface

By placing the Matrix homeserver behind a WireGuard VPN managed by Defguard and integrating Tuwunel with the OIDC, your server is protected from unauthorized vulnerability scans and credential stuffing attacks. A self-hosted push notification gateway is included, bypassing Google Firebase telemetry.

Zero-Knowledge E2E Encryption

The contents of encrypted chats are immune to theft or seizure of the physical server, as they are encrypted all the way to the device. Optional policy-based auditing is available by mandating server-to-device encryption and message retention.

Integrated with LiveKit for VoIP

The Matrix homeserver in the RemoteRails Appliance is already integrated with the high performance LiveKit SFU for concurrent, multi-user voice & video calls with one click from any Matrix client, including Element X, Desktop, and Web.

Replace consumer-grade shadow IT solutions

Where Signal or iMessage falls short

Signal, WhatsApp, or iMessage are a step up from unencrypted messaging apps such as Instagram DMs or SMS, but not a sufficiently robust solution for business or enterprise use. Without enterprise OIDC integration, work conversations shift to personal phone numbers – creating an IT blind spot where communications remain completely unmanaged and unmoderated.

For instance, a former employee can continue claiming to represent your company on these third-party platforms, and imposters can target your customers with fake business accounts – an absolute nightmare scenario.

Get corporate messaging under control with the hardened Matrix homeserver in the RemoteRails Appliance.


All Matrix IDs in the RemoteRails Appliance are tied directly to the Defguard SSO, ensuring that administrators can on and off-board users from a single, central dashboard.

Signal is hosted entirely on centralized AWS infrastructure. You cannot self-host your own nodes, control data residency, or independently verify their server-side signaling code.