End-to-end encrypted
Per-message forward secrecy via Double Ratchet. AES-256-GCM bulk. ECDSA-signed envelopes. Audited primitives only.
SecureComm is a P2P-first encrypted messenger. Messages, calls, and files flow directly between devices over WebRTC — no relay reads them, no server stores them. Your keys never leave the browser.
Per-message forward secrecy via Double Ratchet. AES-256-GCM bulk. ECDSA-signed envelopes. Audited primitives only.
Direct WebRTC DTLS between devices. Signaling and relay only carry blobs they can't decrypt. Falls back gracefully behind NAT.
ML-KEM-768 layered with classical ECDH so today's traffic stays safe even if quantum hardware lands tomorrow.
Hardware passkey recovery via WebAuthn. No central key escrow. Lose your device, keep your identity.
Tap Install for Android above on your phone. The browser will ask if you want to keep the file — accept.
Open the downloaded APK. If Android blocks it, grant Install unknown apps for your browser, then retry.
First launch creates a fresh identity. Pair your passkey in Settings → Recovery so you can restore on any device.
# verify after download $ shasum -a 256 securecomm-*.apk # expected: $ —