Built from the ground up to protect you, with multiple layers of defense. Here is exactly how it works.
Every direct message is wrapped in both Curve25519 and post-quantum ML-KEM-768 (NIST FIPS 203). An attacker has to break both. Group chats use classical Sender Key encryption (X25519).
Curve25519 + ML-KEM-768Every message is encrypted with a unique key derived from a continuously evolving chain. Compromising a single key cannot decrypt your past or future messages.
Identity keys, signed pre-keys, and one-time pre-keys establish a shared secret between two people even when one of them is offline.
All local data is encrypted with AES-256-GCM using keys derived from your PIN. On iOS, key material lives in the Secure Enclave, never leaves the device, and is never included in iCloud backups.
AES-256-GCM ยท Secure EnclaveNo phone number, no name, no email. Accounts use anonymous IDs, and we collect no personal information about you.
An emergency PIN that instantly and silently wipes all data from the app. It is irreversible, and it is there for extreme situations.
Voice and video calls are end-to-end encrypted. We never store call content.
Everything that leaves your device travels over TLS 1.3 as encrypted blobs that our servers cannot read.
Your account is restored with a 12-word recovery phrase you save at signup. If you lose both your PIN and your recovery phrase, your data cannot be recovered. Not even by us.
Don't take our word for it. theSHFT's encryption core (the Signal-compatible protocol implementation with the ML-KEM-768 post-quantum hybrid layer) is open source on GitHub. Read the key derivation, the ratchet, and the hybrid construction yourself.
Private. Secure. Yours.
Questions about our security? Email support@theshft.app.