Post-quantum already, not "on the roadmap"
Every session key is derived from X25519 and ML-KEM-768 together, so
recording today's traffic to break later does not work — there is no
classical-only path to attack. It costs almost nothing.
3.3 ms per full handshake, both sides
Instant, because there is nowhere to keep it
A message is sealed on your device and opened on theirs. Nothing is spooled,
queued or archived on the way, which is why there is no store to subpoena,
breach or quietly mine.
0.42 ms to seal and open a message
No account, no phone number, no directory
You are a key, not a row in a table. Nobody operates a lookup of who may talk
to whom — you exchange keys directly and compare a fingerprint out loud, the
one check an attacker in the middle cannot pass.
Identity in hardware (HEM) or sealed locally
The introduction node never sees your words
Nodes exist to introduce two people and then get out of the way: the
conversation upgrades to a direct channel, and what does pass a node is
ciphertext on a room name derived from your two keys.
Direct WebRTC, relay only as fallback