End-to-end encrypted
The messaging server receives encrypted message envelopes, not readable conversations.
PRIVATE COMMUNICATION, DELIBERATELY SMALL
VaultSec is an invitation-only messenger for people who want a quieter, more private place to communicate. No public sign-up. No discovery feed. Just your circle.
Your private keys stay on your device.
THE SECURITY MODEL
Every message is encrypted on the sender’s device before it leaves. Only the recipient’s device can decrypt it.
The messaging server receives encrypted message envelopes, not readable conversations.
Private messaging keys are created and protected on the device. The admin panel cannot view or create them.
Connections use HTTPS/TLS. The server needs limited delivery metadata, but never your message content or private keys.
A personal code unlocks one private download and one account registration. It is deleted after registration.
WHAT THE SERVER CAN AND CANNOT SEE
The server stores only the technical data needed to run the service: account names, public keys, encrypted message envelopes, encrypted image ciphertext and expiry times. Private conversation keys remain on the participating devices, so the server cannot turn the stored encrypted content back into readable chats or images.
SECURITY & BETA STATUS
This is a private Android alpha. The app and service are designed to keep message content and private message keys off the server. It is not yet a production release or a substitute for an independently audited messenger.
Invitation-only download, PIN lock, panic PIN, three failed PIN attempts erase local vault data, and username/password re-download for existing members.
Text messages are encrypted on the sending device and the receiving device decrypts them. The server delivers encrypted envelopes and keeps limited operational metadata.
A JPEG image is encrypted on the sending device before upload and can be claimed once by its intended recipient.
iOS support, video, files and broader encrypted media are later milestones. They are not included in this alpha.
Release signing, backup and recovery procedures, external security review and full admin access policy are required before any broad public launch.
PRIVATE ACCESS
An authorised administrator creates it for you.
The code opens one short-lived private download.
Use the same code in the app. It is then permanently deleted.
PRIVATE INVITATION
Your code is checked only to create one short-lived download link. It is not saved in this browser.
Android is available in the private alpha. The iOS app is in development.
RETURNING MEMBER
Enter your VaultSec username and account password to unlock one short-lived download. This does not sign you in or unlock your account; your device key and PIN are still required in the app.
ALPHA UPDATE
Images are encrypted on the sender's device before upload. The service stores ciphertext only and the recipient obtains it through a one-time claim.
The encrypted image can be claimed by its intended recipient once. After that claim, the server deletes the stored ciphertext.
The app displays the decrypted image only in memory, briefly, and clears it when the view closes or the app locks.
View-once reduces retained copies, but cannot prevent a recipient from using another camera or a compromised device.
Android alpha currently supports private view-once JPEG images. iOS and broader encrypted media remain later milestones.