🔐 S·OS Secure — end-to-end encrypted

Messages are encrypted on YOUR device with X25519 + AES-256-GCM. The server stores and delivers only ciphertext — it cannot read a single word.

How it works: your private key never leaves this device. Your public key is registered; the other party's public key is fetched; a shared secret is derived; every message is encrypted before it leaves your browser. Even if the server were fully compromised, your messages stay unreadable.

1 · Identity

Not registered yet.

2 · Chat

Register your identity first, then send an encrypted message to another registered user (e.g. david).

🔍 Proof of encryption (for the sceptical)

The ciphertext stored on the server is base64 of the AES-GCM blob. The plaintext never exists server-side — it is created in your browser, encrypted, and only the recipient (who has the shared secret) can decrypt it. You can inspect the raw stored message at /secure-api/api/secure/inbox/<user> — it will be unreadable.

🏴󠁧󠁢󠁳󠁣󠁴󠁿 Darren Houston Limited · S·OS · 🏳️‍🌈 Everyone welcome · Love is love · No one left behind