VENTEX Connect / Security

Trust needs
evidence.

We do not describe security as an absolute. We break it into testable layers, documented boundaries and reproducible evidence.

AVAILABLE NOW · CONTROLLED RELEASEMeasurable architecture, not blanket promises
01E2EEContent layer
0215mShort-lived access token
03PQHybrid session setup
041×Refresh-token rotation
VENTEX / PUBLIC EVIDENCEProduct claims with evidence
CRY-04For capable devices, the version-3 path uses hybrid PQXDH session establishment combining X25519 and ML-KEM-1024; the derived secret becomes the root key of the Double Ratchet.Internally evidenced
Evidence basis

Automated cryptography and key-service tests, 308 mapped counter-tests, 19 real-browser runs with 189 checks, multi-device and downgrade scenarios, single-use prekey allocation and a controlled production walkthrough on 6 September 2026; re-run on 9 September 2026.

Deliberate boundary

The post-quantum component protects session establishment, not a continuously post-quantum ratchet. Rollout remains device-dependent and has not yet received an independent external audit.

Open full evidence
IAM-02Refresh tokens rotate and reuse revokes the affected token family.Internally evidenced
Evidence basis

Session logic and automated reuse/revocation tests.

Deliberate boundary

An already compromised unlocked endpoint remains a separate risk.

Open full evidence
META-03Direct identifiers have been removed from several stored communication paths or replaced by opaque conversation-scoped references.Internally evidenced
Evidence basis

No senderId in message rows, signed authorship inside ciphertext, HMAC direct-chat values, recipient marks instead of device IDs in key envelopes, memberRef for reactions, favourites and mentions, and new read state without new receipt rows. In the current source/test state, the cold-start path reconstructs the identifier directory from encrypted account state and does not treat an empty proof set as success. History transfers there use one computed opaque target mark and skip older unmarked envelopes rather than guessing their destination.

Deliberate boundary

The running service still requires limited account, relationship and technical metadata for authorisation and delivery. The live signed runtime was not updated by this website task; the new cold-start and history-transfer corrections apply there only after a separate app release and migration. Historical time/device references and retained security records remain visible until their defined refresh or cleanup path runs. Metadata minimisation is not metadata absence.

Open full evidence
01

Devices, not just passwords

Each installation has its own cryptographic identity. Signing keys remain non-exportable. Exchange keys are preferably held as non-exportable CryptoKey objects; where iOS/WebKit cannot persist them reliably, the client uses a documented JWK fallback and migrates back when support becomes available. New devices are visible, verifiable and individually revocable.

  • Device-bound keys
  • Safety numbers and strict verification
  • Targeted device removal
02

Sessions with an expiry

Short-lived access tokens are backed by rotating refresh tokens. Reusing an old token revokes the entire session family instead of failing silently. Device revocation ends related sessions and push subscriptions; on the next eligible sign-in path, the client selectively removes account-scoped local security state.

  • Hashed token persistence
  • Login history
  • Global and per-device revocation
03

Hybrid post-quantum protection for new sessions

Since 6 September 2026, the controlled version-3 path has used hybrid PQXDH session establishment for capable device pairs: X25519 is combined with ML-KEM-1024 and the resulting secret feeds only the Double Ratchet. One-time prekeys, signed prekeys and a device-pair downgrade guard limit reuse and silent fallback. Conversations containing devices that are not yet capable remain on an explicitly documented, versioned compatibility path.

  • X25519 + ML-KEM-1024 in hybrid PQXDH
  • Double Ratchet for ongoing message protection
  • Controlled rollout with a per-device-pair downgrade guard
04

Less linkable metadata at rest

The current privacy architecture separates identity from communication records: messages no longer store a sender ID, while authorship is signed inside encrypted content; direct-chat pair keys are server-side HMACs; key envelopes store opaque recipient marks instead of device IDs; reactions, favourites and mentions use conversation-scoped member references. Opaque membership references are bound to possession proofs, while sealed membership names and encrypted account preferences reduce further plaintext. New read state creates no individual receipt rows, affected timestamps are reduced to minute granularity and realtime output is constrained to the public contract. Local drafts, interface preferences and safety verification are account-scoped. The membership table still retains an account identifier for authorisation and transition, the primary display name remains stored with the account, and legacy receipt rows remain until retention expiry; these limits are published explicitly.

  • Signed authorship inside ciphertext
  • Opaque, conversation-scoped references
  • No claim of a metadata-free service
05

Verifiable delivery

Web releases are signed away from the server. Independent rebuilding compares every delivered byte; the service worker verifies the signed manifest before caching assets.

  • Reproducible builds
  • Signed release manifest
  • Public key bound through DNS
All capabilities

Security model and device protection / Capability matrix

01

Passkeys

Platform or hardware-backed second factor.

02

Panic mode

Controlled local wipe and server revocation.

03

Duress access

Discrete sign-in path that revokes other sessions.

04

Strict CSP

Restricts scripts and outbound browser targets.

05

Private storage

Short-lived signed object URLs.

06

Integrity watch

Continuously measures production files and scripts.

07

Safety numbers

Expose key changes and optionally block unverified devices.

08

History protection

Encrypt local history and ratchet state within the account scope.

09

Controlled protocol review

Signal-inspired architecture, independently implemented; detailed material is available only within an expressly agreed confidential review or audit scope.

“A green test is only as strong as the rule it actually verifies.”

VENTEX security principle

Next chapterMission Rooms for operational teams
VENTEX CONNECT / CONTROLLED ACCESS

Security architecture without smoke and mirrors.

Boundaries, evidence and outstanding audit work are documented explicitly.

Request an intro call20 minutes · no obligationOpen Connect