Zero Trust, Vault & Compliance
Device, session, risk and content controls, a shared credential vault with MFA and one-time hand-off, and the compliance frameworks the platform is built and mapped against.
What the crypto is, and what the server can read.
For the security engineers doing the evaluation.
Chat and calls
- Signal protocol — X3DH key agreement and the Double Ratchet, giving forward secrecy and post-compromise security
- Attachments encrypted with AES-256-GCM; the content key travels inside the end-to-end envelope, never beside it
- The server stores and relays ciphertext. It is a relay, not a reader
Media
- 1:1 calls — peer-to-peer, DTLS-SRTP
- Group meetings — a hardened SFU under DTLS-SRTP, branded Standard Secure: hop-by-hop encrypted, with the SFU forwarding streams
- E2EE meetings (optional) — SFrame-style encoded-media encryption with a per-meeting group key on an MLS track. The SFU forwards frames it cannot decrypt
- In-meeting chat reuses the Signal-based chat stack rather than a second protocol
Why the SFU is not a weakness
For group media, an SFU is required to fan out streams at usable bandwidth. Standard Secure encrypts every hop; when a meeting is marked E2EE, the media is encrypted at the encoder with a key the SFU never holds, so the server forwards frames it cannot read. We do not claim every meeting is end-to-end encrypted — the distinction is the point.
Every request verified — not trusted on a prior login.
| Control group | Mechanisms |
|---|---|
| Device | Device trust and posture, certificate pinning, tamper / jailbreak / root detection, hardware-backed keys, secure-enclave usage, encrypted local storage |
| Session | Session isolation, continuous authentication, session recording and replay, remote wipe |
| Risk | Risk scoring, behaviour analysis, geo-fencing, impossible-travel detection |
| Content | Screen watermark, clipboard protection, anti-copy / anti-download, DLP |
Administrators govern actions. They never read content.
Permissions and limits are enforced on the server, per user, role and organization — the client is never the enforcement point. Admins decide which modules are enabled, what may be shared externally, retention, legal hold and geo restrictions.
What they cannot do is read end-to-end encrypted content. Control and surveillance are deliberately separated — and every action lands in an append-only, filterable, exportable audit trail.

Already supports the frameworks enterprise buyers ask for.
Even at this stage the platform already includes support for a wide range of enterprise security and compliance frameworks. Keeping the data on your own server removes the subprocessor chain that normally makes these hard to evidence.
Built in three days. Still beta. Moving fast.
This system was built in just three days. It is still in beta — but most of the functionality is already working, and it is progressing very quickly. The framework support below is part of what already exists, not a roadmap.
We are telling you it is beta on purpose. Ask us what is finished, what is in flight and what the evidence pack looks like for the specific framework in your scope — you will get a straight answer.
| Attestations | SOC 1 Type II · SOC 2 Type II · SOC 3 |
|---|---|
| ISO/IEC | 27001 · 27017 · 27018 · 27701 · 42001 (AI management) · 9001 · 22301 |
| Cloud / baseline | CSA STAR Level 2 · Cyber Essentials Plus |
| Privacy | GDPR · UK GDPR · Swiss FADP · CCPA/CPRA · LGPD · PIPEDA · EU–US DPF |
| Healthcare & payments | HIPAA/HITECH (BAA) · PCI DSS Level 1 |
| Government | FedRAMP (Moderate & High) · StateRAMP · TX-RAMP · IRAP · BSI C5 · ENS High |
| EU / industry | NIS2 · DORA · TISAX |
| AI & frameworks | NIST AI RMF · NIST CSF 2.0 · CIS v8 |
These are the frameworks the platform supports and is mapped against — the control set it is built to satisfy. They are not claims of completed third-party audits or issued certificates; where you need attested evidence, we will tell you exactly where that framework stands today.
Want this running inside your organization?
We scope the deployment in one meeting — sizing, identity integration, self-hosted or managed — and stand it up from there.
Start a project → See other work →