Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Chats Security

Open & Closed Chats/Channels

CTS
eCTS

The corporate administrator can grant access to chats or channels for all server users by placing them in a special catalog.

Chat/Channel Type Description
Closed Chats and Channels Private chats and channels. Corporate chats and channels are created as closed by default. Personal chats are always closed. Closed group chats and channels are intended for a limited audience and are therefore not available in the corporate chat catalog. New users are added to a closed group chat or channel by the chat administrator manually or via an invitation link. The corporate server administrator can make a public chat or channel closed in the admin panel.
For Administrators: How to Make a Chat or Channel Closed on the Server To make a public chat private, in the admin panel, open the Open Chats section and click the trash icon next to the desired open chat, or in the Chats section, find the chat and on its page, click the Remove from Open Chats button.
Open Chats and Channels Public chats and channels, that any registered user on the corporate server can join via the corporate chat catalog. Call or conference chats are always open. Only the corporate server administrator can create an initially open chat or channel or convert a closed chat or channel to open.
For Administrators: How to Make a Chat or Channel Open on the Server In the corporate server admin panel:
  • To create an open chat or channel, open the Open Chats section and click the Create button. The first member of an open chat cannot be added in the admin panel. The first member must join via the client app through the catalog.
  • To convert a closed chat or channel to open, find the chat in the Chats section and click the Convert to Open Chat button. When converting a closed chat or channel to open, end-to-end encryption is automatically disabled. If necessary, it can be re-enabled later, but with consideration of member limitations.
For Administrators: Opening Chats on Multiple Servers Chats are loaded onto the servers of each participant in the conversation. Therefore, to make a chat open on multiple servers, ensure that the chat has at least one user from the desired server. If not, add at least one such user to the chat and give him administrative rights (makes the Convert to Open Chat button available).

Chats Encryption

All chats are stored on the server in encrypted form. On the client device, chats are also stored in encrypted storage. All information in the messenger is transmitted using the TLS protocol (support for Russian cryptographic algorithms is available on a customer request).

Can Anyone Else See My Correspondence Besides Me?

No external party can read the content of your correspondence, even the server administrator.

CTS
eCTS
But with one possible exception: if integration with a corporate DLP system is configured, your organization's security department may monitor the correspondence.

End-to-End Encryption

Depending on the end-to-end encryption settings, chats and channels may have different limitations and capabilities.
E2E Description
Off In such chats (shared chats), you can add more than 128 participants, and the history from the moment encryption is disabled becomes available to new participants. The correspondence is encrypted with a common server key, rather than individual keys of each participant. This allows increasing the number of participants and opening access to the history, but reduces the level of security: if an attacker gains access to the server, they can steal the common key and decrypt the correspondence. Chats with end-to-end encryption disabled are marked with an unlocked padlock icon on the avatar.
On In such chats, you can add no more than 128 participants, and the history is unavailable to new participants. The correspondence is encrypted with individual keys of each participant, making it highly secure. However, new participants will not be able to see old correspondence, as it was not encrypted with their keys. Re-encryption of old messages for new participants is not performed.

Who Has Access to End-to-End Encryption and Where Does It Work?

End-to-end encryption is available to both corporate and public users.

Chats for group calls and conferences (rooms) have end-to-end encryption permanently disabled. Additionally, the corporate server administrator can configure end-to-end encryption to be disabled by default when creating chats and channels (but you can turn it on later).

In personal chats, end-to-end encryption is always enabled and cannot be disabled.

If I Turn Off End-to-End Encryption, Will Everyone See Previous Messages?

⚠️ When end-to-end encryption is switched off, previous messages are not re-encrypted and therefore won't become visible, as they remain encrypted with the previous keys of participants. The history will become available to new participants only from the moment end-to-end encryption is disabled. For new participants to see the entire history, the chat creator or administrator must disable end-to-end encryption when creating the chat and add at least one participant from each corporate server.

Can the Server Administrator Disable End-to-End Encryption?

CTS
eCTS
Yes, but only for chats. End-to-end encryption in channels can only be disabled through the app; the corporate server administrator does not have this capability.

Why is the Number of Members Limited to 128 for E2E?

The limit of 128 participants is due to technical limitations

Who Can Manage the E2E Encryption?

End-to-end encryption can be managed by the chat creator or administrator, as well as the corporate server administrator (chats only).

CTS
eCTS
Corporate server administrators can manage and verify end-to-end encryption in group chats using the admin panel — more details.

Routing — How Traffic Flows in a Chat

Routing (routing scheme) is a visual schematic representation of message exchange routes between users in any type of chat. To view the routing scheme, open the chat properties and select Routing.

The scheme is generated relative to the chat member viewing it. Lines on the diagram indicate paths from the server of the current user to the servers of other chat members. Trusted corporate servers are connected by lines to each other.

Thus, chat routing allows you to see through which servers traffic is routed in a particular chat.

Can Messages Be Sent Between CTS Servers Directly, Bypassing RTS?

CTS
eCTS
If the chat is within one server or between trusted servers, traffic will bypass the public regional transport server (
RTS
). If the chat is created between non-trusted servers or includes at least one user from an external server, traffic will go through
RTS
.

Phishing Protection

On the first message in a private chat from a user on a public or untrusted server, the app shows a warning about the risk of phishing/malicious attachments, which you must confirm to continue the conversation.

Confidential Mode

Lite
CTS
eCTS

Confidential mode allows you to configure the deletion of messages by a timer after they are read or sent, both on clients and the server. This is the only way to delete messages on the server. In this mode, screenshot protection is also enabled (a warning appears in the mobile app when a screenshot is attempted), and file downloads are blocked (files can only be viewed in the chat, but not all formats are supported). Additionally, you can restrict access to messages to mobile devices only.

On mobile devices, an internal document viewer is used since version 3.67.

How to Enable the Confidential Mode?

Open the desired corporate chat card and select the Confidential Mode settings item.

When is the Confidential Mode Unavailable?

  • Cannot be enabled in channels — the Confidential Mode is only available in group and personal chats.
  • It can be enabled and configured by any corporate participant if there is no participant from a public server or guests in the chat.
  • If a chat has more than 256 participants, the confidential mode cannot be activated.
  • The web app doesn't support the Confidential mode due to technical limits (since version 3.44).
  • In the desktop app, you cannot manage the mobile access setting.
  • In certain corporate builds of
    ETS
    web and desktop apps, privacy mode may be unavailable. Check with your organization's support team.

Messages Remain Blurred After Exiting Confidential Mode. How to View Them?

To view messages sent in the confidential mode, activate it by clicking on any message with blurred content.

How to Forward Messages From Confidential Mode to Another Chat?

This feature is disabled by default in corporate server settings. If enabled by an administrator, the option will appear in confidential mode settings.

For Administrators: DLPS and Confidential Mode In the DLPS administrator panel, under general settings, the option to forward messages from confidential mode to the corporate data leak prevention system may be enabled.

Role Model and Corporate Data Transmission Network (CDTN) Contour Configuration

CTS
eCTS

Using the role model and contour settings of the Corporate Data Transmission Network (CDTN), the organization's administrator can restrict access to information in chats — for example, prohibit screenshots and screen recording of the app or forbid forwarding files from sensitive chats.

Support for Data Leak Prevention Systems (DLPS)

CTS
eCTS
If your organization uses a data leak prevention policy, you may see clock icons on messages: yellow — the information is being checked for leaks, red — the message failed the check and cannot be sent. For details, contact your organization's support.