VENTEX Connect / Security

Trust needs
evidence.

We do not describe security as an absolute. We break it into testable layers, documented boundaries and reproducible evidence.

Available in the MVPMeasurable architecture, not blanket promises
01E2EEContent layer
0215mShort-lived access token
030Advertising trackers
04Refresh-token rotation
01

Devices, not just passwords

Each installation has its own cryptographic identity. Private device keys are created as non-exportable and remain in the browser. New devices are visible, verifiable and individually revocable.

  • Device-bound keys
  • Safety numbers and strict verification
  • Targeted device removal
02

Sessions with an expiry

Short-lived access tokens are backed by rotating refresh tokens. Reusing an old token revokes the entire session family instead of failing silently.

  • Hashed token persistence
  • Login history
  • Global and per-device revocation
03

Encryption beyond message text

Messages, reactions, attachments, local history and selected preferences use distinct encryption paths. The Double Ratchet remains a controlled pilot, not an overstated universal claim.

  • AES-GCM and domain separation
  • Sender chains and ratchet pilot
  • Encrypted account-preference shadow
04

Verifiable delivery

Web releases are signed away from the server. Independent rebuilding compares every delivered byte; the service worker verifies the signed manifest before caching assets.

  • Reproducible builds
  • Signed release manifest
  • Public key bound through DNS
All capabilities

Security model and device protection / Capability matrix

01

Passkeys

Platform or hardware-backed second factor.

02

Panic mode

Controlled local wipe and server revocation.

03

Duress access

Discrete sign-in path that revokes other sessions.

04

Strict CSP

Restricts scripts and outbound browser targets.

05

Private storage

Short-lived signed object URLs.

06

Integrity watch

Continuously measures production files and scripts.

A green test is only as strong as the rule it actually verifies.

VENTEX security principle

Next chapterMission Rooms for operational teams
VENTEX CONNECT / CONTROLLED ACCESS

Security architecture without smoke and mirrors.

Boundaries, evidence and outstanding audit work are documented explicitly.

Open Connect