Lawyer–client communication increasingly takes place not through ordinary phone calls, but through messengers. They make it possible to exchange messages and documents and to hold audio and video calls, yet the mere presence of encryption does not mean absolute confidentiality. To protect attorney–client privilege, it is important to assess not only the transmission channel, but the whole system: the messenger, server infrastructure, account, the lawyer’s device, and the client’s device.
Why communication moved to messengers
The growth of mobile internet and the spread of 3G, 4G, and 5G networks have substantially changed everyday communication. Ordinary voice calls and SMS have largely given way to messengers that can carry not only voice, but also text, documents, photos, video, and other information over the internet.
For a lawyer, that is convenient because a large share of client communication can happen in one app. At the same time, it means a large volume of information that may constitute attorney–client privilege is concentrated in a single environment.
Under Article 22 of Ukraine’s Law “On the Bar and Practice of Law”, attorney–client privilege covers, among other things, information about the client, the matters they raised, the content of advice and explanations, and documents and information stored on electronic media. Protecting messengers is therefore directly relevant to a lawyer’s professional work.
There is no absolutely “untappable” messenger
When choosing a communication tool, it is important to avoid a simplistic approach in which one messenger is treated as absolutely safe and another as absolutely unsafe.
Security depends on the architecture of the specific service, the encryption model, the authentication mechanism, how messages are stored, how backups work, the protection of endpoints, and the behaviour of the users themselves.
What matters most is whether end-to-end encryption is used. In that model, a message is encrypted on the sender’s device and should be decrypted only on the recipient’s device. With a correct implementation, the server is used to relay encrypted data but should not hold a key that can read the message content.
For example, Signal states that messages and calls in the service are always protected by end-to-end encryption. Telegram uses a different model: ordinary cloud chats use encryption between the client and the server and are stored in Telegram Cloud, while Secret Chats use separate end-to-end encryption and are tied to specific devices.
When assessing a messenger, a lawyer should therefore look beyond the marketing claim that “data is encrypted” and understand where encryption happens, who may hold the keys, and where conversation history is stored.
Protected transport is not the whole of security
Intercepting modern, properly encrypted traffic while it travels across the network is a far harder task than obtaining information through a compromised account or endpoint device.
For a lawyer, practical risk therefore often sits not in the middle of the channel, but at its ends.
Even strong transport encryption will not help if a third party gains access to the phone itself, an active messenger session, or the user’s account. In that case, information can be obtained after it has already been lawfully decrypted by the app for display to the device owner.
That is why “is the messenger encrypted?” is only one of the questions that must be asked when assessing its security.

What happens on the messenger’s server
A separate issue is the service’s server side.
The user sees a mobile or desktop app, but most modern messaging systems also have server infrastructure. It handles authentication, message routing, device synchronisation, and other operational processes.
How much information is available to the server depends on the messenger’s architecture. For services with end-to-end encryption, the server may have no access to message content, yet certain metadata may still be required for the system to function.
It is therefore incorrect to assume that every messenger necessarily stores the content of every conversation. It is equally incorrect to assume automatically that the server knows nothing about the user merely because encryption exists.
Open-source code also matters. The ability to review client or server source code increases technical verifiability. Signal, for example, publishes client and server source code. Even open source alone is not an absolute guarantee that a specific live infrastructure is running exactly the configuration a user inspected.
A lawyer should therefore treat the messenger server as a separate element of the threat model.
Information on the phone itself may matter more than the server
Another major issue is local storage of information.
Even if a message travels through a strongly protected channel, it must ultimately be displayed on the user’s phone or computer. Chat history, attachments, photos, documents, app cache, notification previews, and other data may remain on the endpoint.
Messenger security therefore cannot really be separated from device security.
If a lawyer’s or client’s phone is unlocked by a third party, infected with malware, or otherwise compromised, cryptographic protection of the channel no longer solves the whole problem.
In other words, even a highly secure messenger cannot compensate for a completely unprotected endpoint. See also how to tell if your phone is being tapped.
Account takeover
A separate category of risk relates not to cryptography, but to authentication logic.
Some messengers use a phone number as one of the main user identifiers. Others may use email, a password, QR codes, one-time links, or a combination of methods.
If signing in requires only control of a phone number and a one-time code, compromise of that mechanism can create an account-takeover risk. That may happen, for example, if an attacker obtains an authentication code or control of the phone number.
That is why an additional password or two-step verification is an important protection wherever the messenger supports it.
This becomes especially critical for services that synchronise message history through the server. If a third party successfully connects a new authorised session, the consequences can be far more serious than intercepting a single SMS code.
Telegram, for example, allows one account to be used on multiple devices, and ordinary cloud messages synchronise across them. Secret Chats use a different model and are not part of Telegram Cloud.
Anonymity and user identification
Security and anonymity are not the same thing.
A messenger may use strong encryption while the account is still linked to a phone number, email address, or other identifiers.
A lawyer therefore needs to understand separately what information is used to create and recover an account, what other users can see, and which identifiers may remain with the service itself.
That is especially important when confidentiality concerns not only the content of negotiations, but also the very fact of communication between a particular lawyer and a particular client.
Both sides must follow the rules
One of the most important conditions for safer communication is the same level of discipline from all participants.
There is little practical point in a lawyer securing a phone and account carefully if the client uses a weak password, skips extra login protection, or leaves open messenger sessions on third-party devices.
The security of a negotiation process is defined by its weakest link.
For especially sensitive matters, lawyer and client should agree on messenger rules: use one clear communication channel, control active devices and sessions, and protect access to accounts and devices themselves.
This is not about inventing a complex technical procedure for every consultation. It is about understanding that confidentiality depends on both sides of the conversation.
Requests to messenger operators
Another aspect is the information the service provider actually holds.
Online service operators may receive requests from law-enforcement or other competent authorities in the manner prescribed by law. The volume of information a service can technically provide depends directly on what data it collects and stores.
That is why it is wrong to claim that any messenger can hand over a user’s entire chat history on request.
Signal, for example, publicly states that because of its architecture it has no access to message content, calls, and a large related data set, and therefore cannot disclose what it does not store. Telegram’s privacy policy provides for disclosure of an IP address and phone number upon a proper request from competent judicial authorities in cases defined by that policy.
When assessing risk, it is therefore important to distinguish message content, metadata, and registration data.
Loss or seizure of a phone
A separate risk arises when a third party physically obtains the phone.
That may be loss of the device, theft, or seizure in the manner prescribed by law.
In that case the main target is no longer network traffic, but information stored directly on the device. Whether it can be obtained depends on the phone model, operating-system version, device state, lock method, cryptographic protection, and other technical factors.
One should not assume that data from any modern smartphone can be obtained “easily”. Equally, it is wrong to assume that using a secure messenger automatically makes device examination impossible.
For a lawyer, this again underlines the need to protect not only the messenger account, but also the phone as a physical carrier of confidential information.
A messenger does not protect against room eavesdropping
Even a perfectly protected communication channel does not solve the problem of physically capturing sound.
If a lawyer holds a messenger call in a room where a third-party microphone or other recording device is installed, an adversary has no need to attack the messenger’s cryptography.
That risk becomes especially obvious with speakerphone use. The conversation is then physically played into the room and can be recorded by any means capable of capturing acoustic information.
Messenger security and technical protection of the meeting place should therefore be treated as linked issues. See also how to protect a meeting room from eavesdropping and the article on lawyer–client confidentiality.

Self-hosted infrastructure based on Matrix
Where an organisation needs greater control over communications infrastructure, one possible approach is a self-hosted server based on the open Matrix protocol.
Matrix allows you to run your own homeserver and supports end-to-end encryption for private communications. That lets an organisation control server infrastructure instead of depending entirely on a single external provider.
For additional network-access control, such infrastructure can be used together with a VPN and the organisation’s own server and key-management rules.
A self-hosted server should not, however, be treated as automatically safer. Its protection, updates, backups, and administration also become the owner’s responsibility. The approach mainly makes sense when the necessary technical competence and capacity to maintain the infrastructure are available.
A hardened operating system as an extra layer
A final layer worth attention is the smartphone’s operating system itself.
For users with an elevated threat model, specialised solutions with stronger security mechanisms may be used. One example is GrapheneOS — an operating system based on the Android Open Source Project, focused on reducing attack surface, strengthening app isolation, and improving resistance to exploit techniques.
No operating system creates a zero probability of malware infection. Its role is to reduce attack surface, make exploitation harder, and limit the impact of a potential compromise.
A hardened operating system is therefore an additional element, not a substitute for other security measures.
Conclusion
The security of lawyer–client communication in a messenger is not defined merely by the app’s name or the presence of the word “encrypted”.
You need to assess at the same time the encryption model, server architecture, how message history is stored, the authentication mechanism, whether the account is tied to a phone number or other identifiers, active sessions, and endpoint protection.
Separately, allow for physical access to the phone, examination of information stored on it, and capture of conversation content through technical means installed in the room itself.
The same rules must be followed by both lawyer and client. If one side properly protects devices and accounts while the other does not, overall confidentiality falls.
For situations with higher control requirements, self-hosted Matrix-based systems, additional VPN use, and hardened operating systems may be considered. The core principle remains unchanged: protect not a single messenger, but the whole chain of transmitting and storing information.
That comprehensive approach helps a lawyer reduce the risk of compromised negotiations, protect client information, and treat attorney–client privilege with due care in modern digital communications.

Messengers and attorney–client privilege
Need an assessment of client-communication security?
The ProDefence team can help review the threat model for the messenger, accounts, and endpoints — and, where needed, run a TSCM survey of the room used for confidential meetings. No unsupported promises of “absolute security”.
Confidential. No requests for seed phrases or private keys.
