惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
S
Security @ Cisco Blogs
N
News and Events Feed by Topic
H
Hacker News: Front Page
Attack and Defense Labs
Attack and Defense Labs
S
Secure Thoughts
Microsoft Security Blog
Microsoft Security Blog
N
Netflix TechBlog - Medium
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
T
Threat Research - Cisco Blogs
Google Online Security Blog
Google Online Security Blog
Spread Privacy
Spread Privacy
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
L
LINUX DO - 热门话题
T
Tenable Blog
博客园 - 叶小钗
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
博客园 - 三生石上(FineUI控件)
量子位
P
Proofpoint News Feed
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
宝玉的分享
宝玉的分享
Recorded Future
Recorded Future
The Register - Security
The Register - Security
F
Fortinet All Blogs
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
S
Schneier on Security
V
Vulnerabilities – Threatpost
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
G
GRAHAM CLULEY
G
Google Developers Blog
月光博客
月光博客
V
V2EX
T
Troy Hunt's Blog
A
Arctic Wolf

Element Blog

Organise your chats your way with Sections We’re interoperable, so you can be sovereign Matrix-based ZaPuK confirmed as a core component within Germany’s Deutschland-Stack Element recognised as a Digital Public Good CompuGroup Medical (CGM) and Element partner to transform healthcare communications Sweden goes live with Matrix-based federation! Air-gapped communications for national security Seamless encrypted history sharing arrives in Element Digital sovereignty is built on an open standard that enables federation Introducing the ESS Community migration tool Spaces has landed on Element X! Meedio partners with Element to deliver sovereign communications across Europe Governments need to adopt Matrix responsibly The Cyber Resilience Act: Implications for open source and digital products Latest Signal and WhatsApp breaches show that consumer apps have no place in government Sustainable decentralised comms at Element Exploring MatrixRTC: Real time communication in rooms The Digital Omnibus: opportunities and risks for open source Open source is key to Europe’s digital sovereignty
Element’s multi-tenancy TI-Messenger solution secures ‘Good’ rating in gematik commissioned pentest
Patrick Maier · 2026-02-17 · via Element Blog

Element’s multi-tenancy implementation of Synapse Pro has secured a Good rating in a penetration test commissioned by gematik, Germany’s national digital health agency.

The security analysis rating is an important milestone in the widespread adoption of gematik’s TI-M Pro standard, which creates a sovereign, interoperable and secure messenger for healthcare professionals, by embedding healthcare specific requirements on top of the decentralised Matrix open standard.

Gematik commissioned an external service provider to conduct the pentest. It used active exploitation techniques to assess the security status of Element's Synapse Pro multi-tenancy implementation - as used in Element Server Suite Pro for TI-Messenger - against best practice criteria, validate security mechanisms, and identify application-level vulnerabilities.

The resulting report found that: “The security of the tested application is rated as ‘Good’. Key interfaces of the Synapse Pro server, including both interfaces for Matrix clients and the server-to-server API, behaved in the examined solution in a manner consistent with a deployment scenario in which a dedicated Synapse instance is used for each tenant.”

The successful gematik pentest now brings external security validation to ESS Pro for TI-M, making it a proven and mature solution; ESS Pro for TI-M already being the server-side component in T-Systems’ TI-M ePA compliant communications solution for BARMER, which launched in July 2025.

A catalyst for local healthcare practitioners to adopt TI-Messenger

Multi-tenancy ESS Pro for TI-M is the first solution available to enable hosting providers to deliver a cost efficient TI-M Pro compliant service to family doctors, local clinics and high street pharmacies. 

Total cost of ownership efficiencies are driven by optimisations within Synapse Pro to reduce RAM usage and associated costs by around 90%, and server-side fleet management features to simplify the administration of thousands of multiple deployments.

For the first time, hosting providers now have a professional server-side solution to deliver affordable TI-M Pro compliant services profitably - even to small healthcare organisations with just a few employees.

A competitive marketplace is now ready to explode as healthcare technology providers race to provide TI-M Pro compliant communications to local healthcare providers. The ecosystem can now build their own frontend TI-M Pro clients, knowing that self-hosted ESS Pro for TI-M is a proven, cost efficient and secure solution backend.

Synapse Pro
Synapse Pro resource savings

The benefits of a professional server-side solution for TI-Messenger

Element Server Suite Pro for TI-Messenger (ESS Pro for TI-M) is the only standalone server-side product available for healthcare technology providers, enabling them to build their TI-Messenger solutions on top of a vendor-backed server built for TI-Messenger. It includes Synapse Pro, a TI-M Messenger Proxy, Push Gateway, dedicated Federation List Service for TI-M and stays aligned with evolving specifications.

Synapse Pro, an enhanced version of community Synapse, dynamically scales to save resources during low demand and automatically cover demand spikes to ensure performance. Resource savings for large single tenant deployments (meeting TI-M ePA standard) are typically in excess of 80%, and for multi-tenant (meeting the TIM Pro standard) are usually in excess of 90%. ESS Pro for TI-M also ensures stable operations with minimal downtime as it enables High Availability deployments, along with Element’s SLA, technical support and regular security updates. Perhaps most important for multi-tenancy deployments, ESS Pro for TI-M includes effective administration features to make it easy for a hosting provider to manage thousands of small hosts individually.

Organisations not using ESS Pro for TI-M have to build their own backend, typically by building from scratch on Element’s community FOSS Synapse implementation and then servicing the associated technical debt and maintenance burden. The community version of Synapse is not designed for commercial use. A host with just five end-users has a memory footprint of around 150MB, which is considerable for a service provider wanting to host 50,000 small hosts (for, say 50,000 local pharmacies) and makes providing such a service uneconomic. A subscription to ESS Pro for TI-M removes all of those challenges in an instant.

Multi-tenancy within ESS Pro for TI-M allows the pooling of resources, keeping costs predictable and performance consistent - while preserving the isolation each tenant requires. Each shard can support up to 50 tenants, with every tenant segregated at a database schema level. The solution is delivered with a Kubernetes controller to manage the shards and their tenants dynamically (via a tenant management API that is provided by Synapse Pro), and enables integration with continuous deployment tooling and GitOps processes for automation.

Similarly Element’s TI-Messenger Proxy is designed for performance, efficiency, and compliance. Built in Rust, it benefits from modern memory safety and concurrency models, reducing operational risk by eliminating data races. With an idle memory footprint of just 10 MB - compared to around 800 MB in the TI-M reference implementation - it is exceptionally resource efficient. The proxy fully complies with the latest TI-M Pro and TI-M ePA specifications, integrates with the FHIR Directory via a dedicated Federation List Service, and supports automatic, load-dependent scaling to ensure high availability and resilience.


A deep dive on multi-tenancy within ESS Pro for TI-M, given at Matrix Conference 2025.


Focus on your own frontend client

The successful pentest signals a game change for secure healthcare communications. With ESS Pro for TI-M providing a state-of-the-art server-side component for a TI-Messenger compliant solution, healthcare technology providers can focus their own development efforts on creating an outstanding frontend client for frontline healthcare professionals such as family doctors, local clinics and high street pharmacies.

Understanding and meeting healthcare professionals’ exact requirements will determine healthcare technology providers’ marketplace success, without having to focus on reinventing TI-Messenger server-side performance and features. Just as laptop and smartphone manufacturers work with semiconductor firms, the TI-Messenger ecosystem is now mature enough for healthcare technology providers to use highly specialised components as a part of their own overall solution.