Private 1:1s. Provably private.

encrypted1on1 is an open-source, self-hosted platform for structured manager–employee 1:1 meetings — end-to-end encrypted, so not even the people running the server can read what’s written. Not a policy promise. A mathematical one.

Read the docs
  • Open Source (AGPLv3)
  • Self-Hosted
  • End-to-End Encrypted
  • No Vendor Lock-in

Why we built this

We didn’t set out to build another SaaS tool. We started as a customer.

Our organization ran its 1:1 process through a third-party tool — one of the many well-designed, well-intentioned products in this space. It did its job. Then, like a lot of small vendors eventually do, it announced it was shutting down.

That’s normal. Startups exit. What wasn’t normal was what it made us realize: we’d never actually asked ourselves what a vendor shutdown means for the content of a 1:1. Performance concerns someone raised in confidence. A manager’s private notes on a direct report’s career trajectory. Compensation conversations. Personal circumstances an employee disclosed expecting it to stay between two people.

None of that content is ever supposed to be visible to anyone beyond the two participants — not their skip-level manager, not HR by default, not IT, and, we realized with some discomfort, not really the vendor either, even though the vendor could, technically, always see it. A shutdown is exactly the moment when a company’s data-handling practices get tested hardest: support staff doing exports, an acquirer doing technical due diligence, a skeleton crew winding things down under deadline pressure. We had no reason to think anything bad would happen with our data specifically. But we also had no way to know that it wouldn’t — because the entire model was “trust us,” and “us” was a company actively going out of business.

That’s the gap we decided was worth closing properly, not just for our own organization, but as something anyone in the same position could actually verify for themselves rather than take on faith. If a 1:1 platform is going to hold some of the most sensitive conversations a company has, “we promise not to look” isn’t a strong enough guarantee. The only guarantee strong enough is one where looking is not possible — where the operator, the IT team, the company that self-hosts it, even a full server compromise, gets nothing but ciphertext. That’s not a policy. That’s end-to-end encryption, done properly, with the code open for anyone to check that the claim is actually true.

encrypted1on1 is what came out of that.

The highest-leverage meeting on a manager’s calendar

Regular 1:1s aren’t a nice-to-have management ritual — they’re one of the best-evidenced levers an organization has for retention, engagement, and catching problems while they’re still small.

  • Andy Grove, in High Output Management (1983) — the book that effectively defined modern tech management practice — argued that a manager’s one-on-ones are among the highest-leverage activities available to them, precisely because they’re where a manager gets the information needed to act before a problem becomes visible anywhere else.
  • Ben Horowitz, in The Hard Thing About Hard Things, builds directly on Grove’s framework and makes the same point from the other direction: a 1:1 is the employee’s meeting, not the manager’s status-update slot — its entire value is in surfacing what wouldn’t otherwise get said.
  • Google’s Project Oxygen — the internal research project that analyzed over 10,000 observations across 100+ variables to find out what actually distinguishes great managers from average ones — found that holding regular 1:1s, and running them well (employee sets the agenda, focus on development and well-being, not just task status), was one of the strongest identified behaviors. Technical expertise, notably, ranked last of the eight behaviors identified. (Google re:Work)
  • Gallup’s research is the sharpest business-value case: employees whose managers hold regular meetings with them are almost three times as likely to be engaged as employees whose managers don’t. And managers account for 70% of the variance in team-level engagement — meaning the quality of the 1:1 relationship isn’t a soft factor, it’s the single most controllable driver of engagement an organization has. (Gallup, Gallup Business Journal)
  • Julie Zhuo (The Making of a Manager) and Camille Fournier (The Manager’s Path) — two of the most-cited modern management books, both written by former engineering-org leaders (Facebook, Rent the Runway) — independently arrive at the same conclusion: the 1:1 is the primary mechanism through which a manager actually does their job, not a meeting that competes with “real work.”

The pattern across all of this research is consistent: the value isn’t in having meetings. It’s in having them regularly, structurally, and with continuity — tracking what was said last time, what commitments were made, what goals are still open. That consistency is exactly what gets lost the moment 1:1s live in scattered documents, memory, or whatever tool happened to be open that week.

A shared doc isn’t a system

Most teams don’t lack a place to write things down. Google Docs, Notion, a shared folder — any of these can technically hold 1:1 notes. That’s exactly the problem: they hold notes, not a process.

No structure.

A blank doc has no memory of what a good 1:1 covers. Mood, workload, achievements, blockers, feedback — every manager either reinvents this from scratch or, more often, skips half of it under time pressure.

No continuity.

Goals set three months ago live in a doc from three months ago, if anyone can find it. There’s no automatic link between this cycle’s commitments and the next one’s follow-up.

No cadence.

Nothing reminds anyone a 1:1 is coming up, or that one side hasn’t filled in their part yet. The process runs entirely on individual discipline — which is exactly why it quietly stops running the moment someone gets busy.

No structured performance-review input.

When review season arrives, “go re-read six months of 1:1 docs” is the actual workflow at most companies. There’s no aggregated view of achievements, growth, or goal progress across a whole review period.

No real privacy model.

A shared doc’s access control is whatever the platform’s sharing settings allow — and it’s genuinely readable by the platform operator, full stop. That’s a different, weaker guarantee than E2E encryption, regardless of how the sharing permissions are configured.

encrypted1on1 replaces “a doc, if you remember” with a system: a fixed, thoughtfully-designed question set on both sides, automatic periodicity and reminder emails, goals that persist and carry forward across cycles with their full progress history, and a performance-review report that aggregates achievements and goal progress across any date range — generated client-side, from data the server never had the ability to read in the first place.

Your data. Your infrastructure. Verifiably private.

For a corporate buyer, “trust us with your employees’ most sensitive conversations” is a hard sell from any vendor — and it should be. encrypted1on1 is built so that sentence never has to be the pitch.

Self-hosted.

The entire platform runs on infrastructure your company controls — your servers, your cloud account, your backup policy. No data ever has to leave your organization’s boundary unless you choose the Cloud option.

Open source (AGPLv3).

Every line of code — including the cryptography — is public and auditable. You, or an independent security team you hire, can verify the privacy claims directly instead of taking a vendor’s word for it. That’s a materially different trust model than a closed-source SaaS product asking you to trust its unread source code and its Terms of Service.

End-to-end encrypted, specifically.

1:1 content — answers, feelings, feedback, comments, meeting outcomes, goal progress — is encrypted in the browser before it ever reaches the server, with keys derived from each user’s own password and never transmitted. The server stores ciphertext. It cannot decrypt it — not the operator, not IT, not us, not an attacker who compromises the database. The one deliberate, narrow exception: a goal’s title, description, and status are stored as plain text specifically so goals can support company-wide alignment and light reporting — everything else in a 1:1 stays private to the two participants, full stop.

This is the resolution to the exact problem in the origin story above: a vendor shutting down, being acquired, or having a bad actor on staff no longer matters to the confidentiality of what’s already been written, because there was never a point where the vendor — any vendor, including us — could read it.

“What about legal holds, harassment investigations, or compliance requests?”

No, and that’s deliberate — because the alternative defeats the purpose. If a company could read 1:1 content, the conversations that most need to happen honestly would stop happening at all. The scenario compliance teams should actually worry about: an employee needs to report concerning behavior by their own manager, or by someone above their manager. If that person — or anyone in their reporting chain — could read 1:1s, would the report ever get written down truthfully? Confidentiality isn’t in tension with catching real problems. It’s the precondition for them surfacing in the first place.

And practically, this isn’t a dead end. Every 1:1 is readable by exactly its two participants, independently — never through a single shared company key. If an investigation involves one participant, the content remains available through the other one, the same way it would if the same conversation had happened on paper or in a personal notebook: legal process can compel a person to produce what they have. It was just never something a platform could hand over on its own, which is the entire point.

Two ways to run it

Why so affordable?

We’re not chasing venture-scale growth — we don’t need this to be a big business, only a sustainable one. Pricing reflects what it actually costs to run reliable infrastructure, not what enterprise software typically charges for a sales team, a marketing budget, or investor returns baked into the price.

And because the entire platform is also free to self-host, you’re never actually paying for the software itself — only, if you choose, for us to run it for you, or for a support relationship you find worth it. If we ever stopped operating tomorrow, self-hosted deployments would keep running exactly as they do today, unaffected — that’s not a promise, it’s just how open source and self-hosting work. (It’s also, not coincidentally, the exact problem this project exists to solve — see Why we built this.)

A meaningful 1:1 is two people spending real, focused time on each other’s growth — that’s the actual cost of doing this well, and no tool changes that math. All we add is making sure that time isn’t wasted rebuilding context from scratch, isn’t at risk the moment a vendor’s business model changes, and isn’t visible to anyone but the two people in the room. That shouldn’t cost more than a notebook.

Self-hosted

FreePremium
Price€0 foreverContact us
The full platform
Community support
Priority support*
Priority feature request handling*
SSOComing soon

The self-hosted core is, and will always stay, completely free — no crippled “lite” tier, no artificial limits. Premium is an optional add-on for organizations that want a support relationship and a say in the roadmap, not a gate on the product itself.

Cloud

Don’t want to run your own infrastructure? We host it for you.

Free (coming soon)Plus (coming soon)Enterprise
Price€0€20 / monthContact sales
UsersUp to 100Up to 1,000Unlimited
History retention3 monthsUnlimitedUnlimited
Priority support*
Priority feature request handling*
SSOComing soon

Cloud runs on the exact same open-source code as the self-hosted version — same end-to-end encryption, same privacy guarantees. The only difference is who operates the server.

*Priority support means paid users’ emails and issues get looked at first, not that a fix is instant or guaranteed by any SLA — this is a small, honest open-source project, not a call center. A paid bug might still take weeks. It’ll just get fixed before the free-tier queue, not instead of it.