Why we build this way
Off-network, over Tor, with post-quantum encryption.
The person we build for is outmatched. Every one of these choices takes something off the table that the adversary is counting on.
The thesis
We build for one individual or a small team standing against an adversary who owns the network and can fund the wait. You have to be right every day; they have to be lucky once. Our choices exist to change that math — each one closes a door the adversary, or simple entropy, assumes will be open.
We don’t fight on their ground.
The network is the adversary’s home turf. A connection is three things at once — an attack surface, a dependency, and a beacon — and for the people we build for the third is the worst. The content of a message is rarely the prize. The metadata is: who spoke to whom, from where, at what time, how often. A device that does its work without reaching out gives none of that away.
So offline-first is not a constraint we tolerate. It is the point. Capability that dies without a signal is capability that dies exactly when the signal is jammed, watched, or gone — which is exactly the moment it was carried for.
We don’t put your data in someone else’s hands.
A cloud service is a promise made by a company you do not control, and that promise can end without notice. The service shuts down. It gets acquired, and the terms you agreed to belong to someone new. It moves your data to a jurisdiction you would never have chosen. And while it lasts, what matters to you lives on hardware run by strangers — administrators, contractors, whoever breaches it next, whoever serves it a subpoena. “Deleted” means gone from your view, not from their backups. Every breach headline is someone who trusted a third party to hold what mattered.
We do not design that dependency in. What the device holds, the device keeps. There is no account to close, no server to raid, no company whose bad quarter or bad actor becomes your exposure. The data has one custodian: the person it belongs to.
We separate the message from the messenger.
Sometimes you have to reach out. When you do, the words are almost never the crown jewels. The prize is the two facts a connection usually carries for free: who you are, and where you are. That is what a stalker is trying to establish, what a surveillance team is paid to confirm, and what gets an undercover officer killed. Ordinary encryption hides the message and leaves both facts in plain view.
Tor breaks the link between them. A connection can carry what you need to say without carrying the sender — no return address, no line drawn on a map back to a person. We route this way not for anonymity as a slogan, but because for our users the tie between name and place is the whole exposure.
We build for an adversary who can wait.
Time favours the well-funded. Encrypted traffic is being harvested and stored right now — not to read today, but to read later, when the mathematics protecting it has aged out and a machine exists that can unwind it. The industry calls it “harvest now, decrypt later.” For most software that is a distant abstraction. For a protected identity, a covert program, or a person whose exposure has to stay buried for twenty years, it is the entire threat.
So we encrypt against the computer that does not exist yet, because the secret has to outlive the one that does.
The through-line
Four assumptions an adversary counts on: that you will be on the network, that someone else will be holding your data when it matters, that your messages will name you, and that your secrets only have to keep until the math ages out. We design each one out — before the first breach, not after it.
Aware and Informed