πŸ“„ Secure Business Communication using Threema

Secure Business Communication using Threema

Document ID: TEPA-GOV-COM-001

Version: 1.0 (Draft)

Classification: Internal

Owner: TEPA.swiss Enterprise Architecture & Governance

Applies to: All TEPA.swiss companies, subsidiaries, projects and digital platforms

1. Purpose

This governance standard defines the mandatory use of Threema as the trusted communication channel for business communications where confidentiality, authenticity and operational integrity are essential.

The objective is to reduce reliance on consumer messaging platforms for sensitive business operations while providing a secure communication layer fully integrated into the TEPA.swiss Digital Platform.

Threema is not intended to replace email, WhatsApp or Microsoft Teams. Instead it provides the secure communication backbone for high-value transactions, approvals and critical operations.

2. Scope

This policy applies to

  • CyberMountain
  • TEPA.swiss
  • Swintra Ventures Pvt. Ltd.
  • World Wide Services Group Ltd.
  • Swiss Wine India
  • Customer Projects
  • Odoo Platform
  • Portal Users
  • Suppliers
  • Government Partners
  • Embassies
  • VIP Customers
  • Executive Management
  • External Consultants

3. Governance Principles

The following principles apply.

Principle 1 β€” Privacy First

Sensitive business information shall never rely solely on consumer messaging platforms.

Threema shall be the preferred secure communication channel whenever confidentiality is required.

Principle 2 β€” Identity Matters

Every Threema ID must be associated with

  • a verified person
  • supplier
  • customer
  • employee
  • partner
  • authority

within Odoo.

Anonymous communication is not permitted.

Principle 3 β€” Business Record

Business relevant Threema conversations shall become part of the business record.

Messages may therefore be

  • linked to CRM
  • linked to Projects
  • attached to Purchase Orders
  • attached to Quality records
  • attached to Incidents
  • attached to Compliance Cases

Principle 4 β€” Least Information

Only the minimum required information shall be transmitted.

Instead of sending confidential documents directly,

the preferred approach is

Secure Link β†’ Portal β†’ Authentication β†’ Access

Principle 5 β€” Automation First

Whenever possible communication shall be automated by Odoo.

Manual messaging should become the exception.

4. Classification Matrix

Classification

Preferred Channel

Public Marketing

Website

Newsletter

Email

Sales Campaign

WhatsApp / Email

General Customer Service

WhatsApp

Internal Collaboration

Microsoft Teams

Internal Documentation

Odoo

Sensitive Customer Data

Threema

Executive Communication

Threema

Security Incident

Threema

Legal Communication

Threema

Supplier Verification

Threema

Identity Verification

Threema

Digital Sign-off

Threema

Emergency Communication

Threema

5. Approved Business Use Cases

5.1 Executive Communication

Examples

  • CEO communication
  • Board decisions
  • Confidential strategy
  • Acquisition discussions
  • Financial approvals

5.2 Supplier Verification

Examples

Identity verification

Document requests

Bank account confirmation

GST verification

IEC confirmation

Factory verification

Quality incidents

5.3 Customer Identity

Used for

VIP onboarding

Identity verification

Secure delivery confirmation

Compliance communication

High-value orders

5.4 Logistics

Shipment status

Cold chain alerts

Container release

Customs exceptions

Embassy shipments

Warehouse incidents

Excise notifications

5.5 Compliance

FSSAI

Import compliance

Product recalls

Audit requests

Document validation

Corrective actions

5.6 Laboratory

Secure communication with

Envirocare

Testing laboratories

Sampling

Certificates

Corrective measures

5.7 Government

Swiss Embassy

Indian authorities

Trade offices

Government partners

Secure exchange of documents

5.8 Cybersecurity

Incident response

Compromised account

Credential reset

SOC notifications

Infrastructure outage

Security approval

Emergency communication

6. Use Cases inside Odoo

Every business object may initiate secure communication.

Examples include

CRM Lead

Opportunity

Supplier

Vendor

Purchase Order

Sales Order

Shipment

Invoice

Quality Alert

Support Ticket

Project Task

Approval Workflow

Contract

Laboratory Report

Compliance Record

Employee Record

Asset

Knowledge Article

Document

7. Identity Governance

Every Threema identity shall contain

Verified Name

Organisation

Role

Country

Verification Date

Trust Level

Owner

Linked Partner Record

Linked Contact

Linked Company

Status

Trust Levels

Level 0

Unknown

Level 1

Email verified

Level 2

Phone verified

Level 3

Identity document verified

Level 4

Personally verified

Level 5

Trusted Business Partner

8. Data Protection

Messages shall not contain

Passwords

Private Keys

Encryption Keys

Credit Card Numbers

Authentication Secrets

Instead,

secure portal links shall be used.

9. Retention

Business relevant communication

shall be archived inside Odoo.

Retention follows

Company policy

Swiss regulations

Indian regulations

Customer contractual obligations

Applicable legal hold requirements

10. Integration Architecture

User

↓

Threema Gateway

↓

TEPA Integration Service

↓

Odoo

↓

CRM
Projects
Quality
Approvals
Helpdesk
Documents
Compliance
Portal
Knowledge

11. Approved Automation

Examples

Automatic Shipment Notification

Laboratory Result Ready

Invoice Approved

Purchase Order Released

Supplier Verification Request

Customer Identity Verification

Passport Request

Visa Request

FSSAI Reminder

Project Escalation

Critical Infrastructure Alert

Incident Bridge

Approval Request

Payment Confirmation

Document Signature Request

12. Prohibited Use

The following are prohibited.

Personal conversations

Political discussions

Mass marketing

Spam

Unauthorised advertisements

Unverified identities

Sharing credentials

Sending confidential files without business purpose

Deleting business records

Circumventing Odoo workflows

13. Future Capabilities

The following capabilities are considered strategic extensions.

  • AI-powered message summarisation into Odoo records.
  • Automatic translation between English, German, French, Italian and Indian languages.
  • AI-assisted drafting of responses based on CRM context.
  • Secure voice and video session initiation.
  • Digital identity verification and onboarding.
  • Document signing workflows with audit trails.
  • Integration with DigiLocker, GST, FSSAI and other government services.
  • End-to-end encrypted approval workflows for executives.
  • Incident command communications integrated with SOC and DevSecOps tooling.
  • Cross-platform federation with WhatsApp, email and Microsoft Teams while preserving Threema as the trusted secure channel.

14. Strategic Position within the TEPA Digital Platform

Threema is designated as the trusted secure communication layer of the TEPA.swiss Digital Platform. While channels such as email, WhatsApp and Microsoft Teams remain appropriate for general collaboration and customer engagement, all communications involving identity assurance, regulatory compliance, executive decisions, critical operations or sensitive business information should transition to Threema.

Within the TEPA architecture, Threema is not merely a messaging application; it functions as a security and governance component. Every interaction is linked to a verified business identity, integrated with Odoo workflows, and recorded as part of the organisation’s operational evidence chain. This approach strengthens auditability, reduces communication risk, and supports TEPA.swiss’s broader objective of delivering sovereign, privacy-by-design digital services across Switzerland and India.