The Matrix Conference 2026

Challenges of Matrix within Europe's most sovereign, most secure and largest IT Infrastructure

Matrix was designed around strong end-to-end encryption and user-controlled trust. While this model is ideal for private communication, large public-sector and critical infrastructure deployments face additional requirements that go beyond traditional E2EE.

This talk explores the challenges of operating Matrix within one of Europe's largest sovereign and security-critical IT infrastructures, where legal archiving obligations, compliance requirements, incident handling, automation and long-term information governance must coexist with modern encrypted communication.

We discuss why classic end-to-end encryption is not always sufficient in enterprise environments and examine the concept of End-to-Organization Encryption (E2OE) as a potential architectural approach. Rather than focusing solely on technical implementation, the session evaluates the trade-offs between confidentiality, organizational trust, operational resilience and regulatory compliance.

Topics include message archiving, eDiscovery, compliance scanning, bot integration, fall handling, key recovery, device loss, and organizational access models. We will also discuss how these requirements influence Matrix client architecture, headless clients, encryption key management and federation.

The presentation is intended for Matrix developers, infrastructure architects, security professionals and public-sector operators interested in deploying Matrix at national scale while balancing sovereignty, usability and compliance.

Richard Schlögl

Richard Schlögl is a technical product manager and requirements engineer based in Vienna. Over the past fifteen years he has worked in e-health, banking, payments and automotive, with a focus on requirements engineering.

At RISE (Research Industrial Systems Engineering) he was technical product manager on TI-Messenger (TIM), the Matrix-based messaging service used in Germany's national healthcare infrastructure. His work included coordinating with the technical provider that built TIM for the statutory health insurers, designing the service for both insured members and the insurers' staff. Much of the role involved turning gematik's TIM specification into a working product, covering federation, end-to-end encryption and interoperability requirements within the constraints of national healthcare IT.

Richard is a software engineer, certified requirements engineer (IREB CPRE Advanced) and Scrum practitioner (PSM II), with a background in usability and interaction design. He also teaches requirements engineering, usability engineering and web engineering at FH Wiener Neustadt, the University of Zürich and TU Graz.