Skip to content

Security

Encryption you can reason about

EKIP is built so that private conversation content is encrypted on your device and cannot be decrypted by the infrastructure that carries it.

How a message travels

  1. 1

    Alice

    writes a message

  2. 2

    Plaintext

    exists only on Alice's device

  3. 3

    Local encryption

    on-device, before sending

  4. 4

    Ciphertext

    what leaves the device

  5. 5

    P2P / encrypted mailbox

    transport

  6. 6

    Ciphertext

    what the server can see

  7. 7

    Local decryption

    on Bob's device

  8. 8

    Bob

    reads the message

Messages are encrypted on your device before leaving it. EKIP infrastructure is designed so it cannot decrypt private conversation content.

Client-side encryption

X25519 key agreement, Ed25519 signatures and XSalsa20-Poly1305 authenticated encryption.

Peer-to-peer delivery

When both devices are online, messages travel directly over an encrypted WebRTC DataChannel.

Encrypted offline mailbox

Offline messages are stored as ciphertext only; the server never receives the message key.

Self-hosted ICE

Voice and P2P use self-hosted STUN/TURN — no public STUN or third-party relay.

Frequently asked questions

Can EKIP read my messages?
Messages are encrypted on your device before leaving it. EKIP infrastructure is designed so it cannot decrypt private conversation content.
Where are my private keys stored?
Private keys remain client-side. In the browser they are wrapped with a non-extractable AES-GCM key held in IndexedDB and are never written to localStorage, sessionStorage or cookies.
What happens when a contact is offline?
The message is encrypted on your device and queued in an encrypted mailbox. The server stores ciphertext only and cannot decrypt it. When the contact reconnects, their device decrypts it locally and acknowledges delivery.