The sale of Dutch secure-communications provider Zivver to US company Kiteworks drew scrutiny over legal jurisdiction and the technical handling of messages used by European public institutions. An investigation by Follow the Money reported that hospitals, courts, government services and other organizations in the Netherlands, Germany, Belgium and the United Kingdom use Zivver to exchange confidential material.
Kiteworks acquired the Amsterdam-based company in June 2025. Zivver, founded in 2015, provides encrypted communication through email, chat and video. Follow the Money reported that some customers had considered the supplier's Dutch origin and European data storage important when selecting the service. The change in ownership therefore prompted concern among experts quoted by the publication about whether sensitive communications could fall within the reach of US authorities.
The investigation also examined how Zivver's web application handled messages. Two unnamed cybersecurity specialists at a Dutch government agency tested the service at the publication's request. Their tests indicated that message contents, attachments and sender and recipient addresses reached Zivver's servers in readable form before encryption. Independent researcher Matthijs Koot verified the findings and said the brief readable stage meant the company could technically view the material.
Zivver disputed the broader implication. It said it did not hold customers' encryption keys and therefore could not provide their data to US authorities. Follow the Money reported that Zivver acknowledged processing readable content in the specific tested cases. The investigation said it had found no evidence that the company misused that technical access. Zivver also argued that security would improve under Kiteworks.
A separate concern involved the backgrounds of Kiteworks executives. Follow the Money reported that chief executive Jonathan Yaron, chief business officer Yaron Galant and chief product officer Amit Toren had served in Unit 8200, an Israeli military intelligence unit. Experts quoted by the publication argued that those ties increased risk; their warnings were assessments, not evidence that Zivver or Kiteworks had transferred customer information to Israeli authorities.
The acquisition was not reviewed under the Netherlands' investment-screening system because the interior ministry did not classify Zivver as critical infrastructure, according to the investigation. Critics described that decision as a missed safeguard and called for secure-communication services to receive greater strategic oversight.
The central issue is broader than the nationality or prior employment of individual executives. Institutions entrusted with medical, legal and government records depend on both technical safeguards and predictable legal control. The investigation suggests customers need precise answers about when data is readable, which corporate entity can access it and what legal demands could apply after ownership changes.


