All evidenceGRD-03 / Content protection

How does Connect protect messages and files?

Are messages and files in VENTEX Connect end-to-end encrypted?

Direct answer

Connect protects messages, files, reactions, locations and additional content types on the client. Since 6 September 2026, the controlled version-3 path has combined X25519 with ML-KEM-1024 in hybrid PQXDH session establishment for capable devices and then continued protection through Double Ratchet. A downgrade guard prevents silent fallback for a device pair; devices that are not yet capable remain on a documented, versioned compatibility path. VENTEX claims neither complete post-quantum protection across all ratchet steps nor Signal equivalence.

Content encryption, key distribution, upload validation and private object storage.
Claim ledger06 ENTRIES
CRY-01Implemented

Message, file and reaction content has protected client payloads.

Evidence basis

Encryption libraries, API contracts and cryptography/multi-device tests.

Deliberate boundary

The running service still needs routing, membership and timing information; metadata-free operation is not claimed.

CRY-02Internally evidenced

Double Ratchet is the default send path without a conversation allowlist; device envelopes, epochs and a downgrade guard support rotation and multi-device operation.

Evidence basis

Rotation, device, double-ratchet and membership proofs in the test stack.

Deliberate boundary

Internal evidence is not an independent protocol and implementation audit.

CRY-04Internally evidenced

For capable devices, the version-3 path uses hybrid PQXDH session establishment combining X25519 and ML-KEM-1024; the derived secret becomes the root key of the Double Ratchet.

Evidence basis

Automated cryptography and key-service tests, 308 mapped counter-tests, 19 real-browser runs with 189 checks, multi-device and downgrade scenarios, single-use prekey allocation and a controlled production walkthrough on 6 September 2026; re-run on 9 September 2026.

Deliberate boundary

The post-quantum component protects session establishment, not a continuously post-quantum ratchet. Rollout remains device-dependent and has not yet received an independent external audit.

CRY-05Limited

Profile images require authentication and are protected at rest, but they are not end-to-end encrypted.

Evidence basis

Protected retrieval route, authenticated byte retrieval in the client and current production claim verification.

Deliberate boundary

The service can read profile images. Retrieval requires authentication but does not require an existing communication relationship when an exact account identifier is resolved.

META-03Internally evidenced

Direct identifiers have been removed from several stored communication paths or replaced by opaque conversation-scoped references.

Evidence basis

No senderId in message rows, signed authorship inside ciphertext, HMAC direct-chat values, recipient marks instead of device IDs in key envelopes, memberRef for reactions, favourites and mentions, and new read state without new receipt rows. In the current source/test state, the cold-start path reconstructs the identifier directory from encrypted account state and does not treat an empty proof set as success. History transfers there use one computed opaque target mark and skip older unmarked envelopes rather than guessing their destination.

Deliberate boundary

The running service still requires limited account, relationship and technical metadata for authorisation and delivery. The live signed runtime was not updated by this website task; the new cold-start and history-transfer corrections apply there only after a separate app release and migration. Historical time/device references and retained security records remain visible until their defined refresh or cleanup path runs. Metadata minimisation is not metadata absence.

FIL-03Implemented

Uploads are bound to a user and conversation and do not use public buckets.

Evidence basis

Upload grants, size/MIME/checksum validation and short-lived download URLs.

Deliberate boundary

Malware scanning, DLP and server-side video transcoding are not active.

What does not follow
  • No equivalence with Signal or an audited standard protocol.
  • No invisibility of all metadata from the operator.
  • No protection from an unlocked or compromised endpoint.
Evaluate before adoption
  1. 01Which content and metadata arise in the specific use case?
  2. 02Are external audit, DLP or malware scanning mandatory before the intended deployment?
  3. 03How will key rotation, device loss and member removal be exercised?
FAQ / FACTS

Short answers

Are messages and files in VENTEX Connect end-to-end encrypted?

No. The architecture is Signal-inspired but independently implemented, not Signal-compatible and not equivalent to libsignal. Without an independent cryptographic and implementation audit, an equivalence claim would not be defensible.

No. Version 3 adds hybrid post-quantum protection to new session establishment for capable devices. The following Double Ratchet is not a fully post-quantum ratchet; that remains a separate, unimplemented stage.

No. The intended architecture uses private object storage and short-lived signed access paths.