theSHFT

Security

Built from the ground up to protect you, with multiple layers of defense. Here is exactly how it works.

Post-quantum message encryption

Every direct message is wrapped in both Curve25519 and post-quantum ML-KEM-768 (NIST FIPS 203). An attacker has to break both. Group chats use classical Sender Key encryption (X25519).

Curve25519 + ML-KEM-768

Forward secrecy

Every message is encrypted with a unique key derived from a continuously evolving chain. Compromising a single key cannot decrypt your past or future messages.

Asynchronous key agreement

Identity keys, signed pre-keys, and one-time pre-keys establish a shared secret between two people even when one of them is offline.

Data at rest

All local data is encrypted with AES-256-GCM using keys derived from your PIN. On iOS, key material lives in the Secure Enclave, never leaves the device, and is never included in iCloud backups.

AES-256-GCM ยท Secure Enclave

Anonymous by design

No phone number, no name, no email. Accounts use anonymous IDs, and we collect no personal information about you.

Duress PIN

An emergency PIN that instantly and silently wipes all data from the app. It is irreversible, and it is there for extreme situations.

Encrypted calls

Voice and video calls are end-to-end encrypted. We never store call content.

Encrypted in transit

Everything that leaves your device travels over TLS 1.3 as encrypted blobs that our servers cannot read.

You hold the keys

Your account is restored with a 12-word recovery phrase you save at signup. If you lose both your PIN and your recovery phrase, your data cannot be recovered. Not even by us.

Open-source encryption

Don't take our word for it. theSHFT's encryption core (the Signal-compatible protocol implementation with the ML-KEM-768 post-quantum hybrid layer) is open source on GitHub. Read the key derivation, the ratchet, and the hybrid construction yourself.

Get theSHFT on the App Store

Private. Secure. Yours.

Questions about our security? Email support@theshft.app.