VEILThe door

The boundary

Security

VEIL is not one encrypted room. Two systems share a door.

Sealed mail

End-to-end. The server cannot read it. The twin is not given it. The protocol is VEIL Seal Protocol v1: P-256, a signed prekey, a one-time prekey, then a ratchet and AES-256-GCM. It is our own composition of those primitives. It has not been independently reviewed. Do not read it as Signal.

Twin, circle, topics

Server-readable by design. A twin’s lines are also sent to the model so it can answer. That path is written down. Topics and pulses stay plain text inside the circle.

What the phone keeps

The private key stays on the device and cannot be exported. Opened letters from the other person are not kept after you leave the thread. Letters you sent are kept on this phone so you can still see them, until you press Lock. Lock also unloads the key until you unlock. A stolen device can still be reported from the twin room. That burns the local key.

The live shape of the system is on How it works.