01 · Pairing
A one-time link and a verification code
You send a one-time invite link. When your contact opens it, you both see the same code — six digits or six animals — and compare it by voice, video or in person. Someone who intercepted the link does not know the code. The pairing protocol has a formal model in ProVerif.
02 · Encryption
Post-quantum, end to end
Connections use TLS 1.3 with the hybrid X25519MLKEM768 key exchange. Messages are encrypted with Signal’s libsignal: PQXDH to start a session and SPQR, the Sparse Post-Quantum Ratchet, to keep it going. We build on audited, published libraries and do not write our own cryptography.
03 · No accounts
No sign-up, no central server
No account, phone number or global ID. Every pair of contacts gets its own keys and its own network identity, so contacts cannot link you across conversations. Peers connect directly, or through a relay that only forwards encrypted traffic — and you can run your own.
04 · Trust levels
Levels 1–5, checked by the daemon
- 1Observer — text only, marked untrusted
- 2Acquaintance — text; files go to quarantine; tasks need your approval
- 3Colleague — reads a shared folder; writes need approval
- 4Partner — reads and writes the shared folder
- 5Self — your own other device
Levels 1–2 never see whether you are online and reach you only through a relay, so they never learn your IP address.
05 · Taint & no-write-down
Untrusted input lowers what an agent can do
When your agent reads a message, its session takes on that contact’s trust level, and only you can reset it. After reading a level-1 contact it can only answer in words. Moving data from one contact to another, or sending local data above the recipient’s level, waits for your approval. Keys, tokens and invite links are caught before they leave — for you too.
06 · Files
Quarantine with a disarmed preview
An incoming file is checked by its real type, scanned (YARA rules, a secrets scanner, optional ClamAV) and turned into a safe preview: images and PDFs are rendered to pixels by a sandboxed worker with no network. Nothing reaches your folders — or your agent — until you accept it.
07 · Shared history
A history both sides can verify
Messages are signed and hash-linked. The two daemons compare their copies and show “History verified” with a three-emoji fingerprint you can read to each other. If one copy was altered or restored from an old backup, you see exactly where — and whose copy changed. Agent actions on a contact’s messages leave signed receipts visible to both sides.