In development

Sovereign Communications

Messages and files that travel between two keys, and nowhere else. Built for the day the encryption everyone else is using stops being enough.

End to end encryptedPost quantum key exchangeNo directory, no phone number
The message you send today can be stored today and opened years from now, by a machine that does not exist yet.

It has a name in the trade. Harvest now, decrypt later. Encrypted traffic is being collected and warehoused right now by people who cannot read it, on the reasonable assumption that one day they will be able to.

Most of the encryption protecting your messages relies on mathematics a sufficiently capable quantum computer would undo. Not today, and probably not soon. But "probably not soon" is not much comfort for a contract, a diagnosis, or a conversation you would rather stayed between two people for the rest of your life.

Sovereign Communications is being built the other way round. Post quantum key exchange from the start, keys that belong to the two people talking, and no directory in the middle that knows either of them.

Two keys, no middle

A conversation exists between a pair of keys that you and the other person hold. There is no account lookup, no phone number and no directory to be subpoenaed, leaked or sold.

Post quantum from the start

Key exchange built to stand up to quantum attack, rather than bolted on later when it is already too late for everything sent before.

Argon2id at the door

Your passphrase becomes a key through a function deliberately made slow and memory hungry, so guessing at it costs real hardware and real time.

Files, not just messages

Documents move under the same encryption as the conversation. No separate transfer service, no public link that anyone holding it can open.

You verify the person

Pairing is something you and they do directly. You can check you are talking to who you think you are, rather than trusting a server that says so.

Nothing readable in the middle

What passes through infrastructure is ciphertext. Not decrypted for scanning, not decrypted for features, not decrypted for us.

Why post quantum, and why now

Encryption is not a thing you fix later.

A lock can be changed the day it starts looking weak. A conversation cannot. Anything sent under old encryption stays sent, sitting in whatever storage it landed in, waiting for the day it becomes readable.

The problem

  • Harvest now, decrypt later. Traffic nobody can read is worth collecting anyway, because storage is cheap and patience is free.
  • The maths has a known weakness. The key exchange most of the internet relies on is exactly the sort of problem a large quantum computer is expected to be good at.
  • Retrofitting does not reach backwards. Upgrading in five years protects what you send in five years, and nothing you sent before it.

The approach

  • Post quantum key exchange, alongside the classical kind. Belt and braces, so it is never weaker than what it replaces even if the new mathematics turns out to have its own surprises.
  • Keys derived with Argon2id. Memory hard by design, which makes the brute force approach expensive rather than merely tedious.
  • Forward secrecy as a habit. Compromising a key today should not hand anybody the entire history behind it.

What that buys you

  • Time. Messages that stay unreadable for their whole useful life, not just until the hardware catches up.
  • A defensible position. For a business holding client material, being able to describe exactly how something was protected matters as much as the protection.
  • No quiet downgrade. If a connection cannot be made at full strength, it does not happen at reduced strength without telling you.
How pairing works

You exchange a key with a person, not a profile with a platform.

There is no search box to find somebody in, because there is no list of everybody to search. That is the point rather than an omission.

01

Your keys are made locally

Generated on your own device, protected by your passphrase through Argon2id. The private half never leaves the machine.

02

You share the public half

With the person you actually want to talk to, however you like. In person, in a room, or over something you already trust.

03

You confirm each other

Both sides check the pairing matches. If somebody has interfered in the middle, that is the moment it shows.

04

The channel opens

Messages and files flow between the two of you, encrypted end to end, with the keys held at each end and nowhere else.

05

Nobody was ever listed

No profile was created, no number was verified, and no server ever held a record of who is allowed to talk to whom.

For a business

Closed communications for the material that cannot go anywhere near a group chat.

Most companies run their confidential conversations through whichever consumer app the team already had. It works, right up until somebody asks where that data lives and who else can reach it.

Where it earns its keep

  • Client files and contracts moving between the people who need them, rather than through a general purpose file service.
  • Professional confidentiality. Legal, medical, financial and anything else where the duty of care outlives the project.
  • Work with external parties who are not on your systems and never will be, without granting anybody access to anything.
  • Closed teams where the membership itself is sensitive, because no directory means no list of who is involved.

Honest about the shape of it

  • Key pairing is a deliberate friction. It is a few seconds of work at the start in exchange for knowing exactly who is at the other end. We would rather that than a convenient lie.
  • It does not replace your inbox. This is for the conversations that need it, sitting alongside the ordinary ones that do not.
  • It will not scan your messages. Not for features, not for advertising, not for us. We cannot read what goes through it, which is the entire design.
The whole idea

If we cannot read it,
nobody can make us hand it over.

An encrypted service that holds the keys is a service that can be compelled to use them. One that never had them cannot produce what it does not have. That is not a promise about how we would behave under pressure, it is an arrangement where our behaviour under pressure stops being the thing standing between you and your conversation.

What it does not do

The same honesty we put on everything else.

No messenger on earth makes you invisible, and the ones implying otherwise are selling something.

So here is the plain version, well before you rely on it for anything.

Status today
  • Still being built. This page describes what it is for and how it is designed, not something you can download this afternoon.
  • No launch date claimed. When it is ready and we are satisfied with it, this page will say so.
  • No pricing yet. For the same reason.
What encryption cannot fix
  • It does not secure the other person. Anything they receive, they can screenshot, forward, or leave open on a train.
  • It does not protect a compromised device. Something already reading your screen does not need to break the encryption at all.
  • It is not anonymity. Content is protected. The fact that a connection happened is a harder problem, and we will not pretend it is solved.
The world it lives in
  • The law is not the same everywhere. What a messaging service may and must do differs enormously by country, and it is moving.
  • We will tell you where we stand. Plainly, for your jurisdiction, rather than a global claim that quietly is not true in half the world.
  • We would rather ship nothing than ship a promise we cannot keep. That has already stopped us building things, and it will again.
Interested

Tell us what you need it to carry.

If your business has conversations that currently have nowhere safe to happen, we would like to hear about them while this is still being shaped. It is the sort of thing that decides what gets built first.