How the encryption works.
The protocol in full, from the handshake before your first message to the limits at the end.
One message, end to end
Follow a single message from your device to theirs.
You write it
The message is encrypted on your device under a key derived for that one message. If it cannot be encrypted it is not sent. There is no unencrypted fallback.
We carry it
What arrives on our servers is the encrypted version and the routing needed to deliver it. That is all we can hand to anyone.
They open it
Their device holds the only key that opens it, and each of their devices gets its own copy under its own key.
The handshake
What happens before your first message is sent.
X3DH to start a conversation
An extended triple Diffie-Hellman against the recipient's published keys, so the first message is already encrypted with nobody waiting online. Each device keeps a pool of 50 one-time keys, tops it up before it runs dry, and rotates its signed key weekly.
A Double Ratchet per thread
Every message advances a ratchet and is sealed under its own key. One key does not open the thread, and the chain heals after a compromise. Up to 2,000 keys are held back for messages that arrive out of order, so a long time offline still reads in full.
Sender keys in groups
One encryption per sender covers the whole group, up to 256 people. Someone leaving forces a new key generation and cannot read what comes after. Someone joining is admitted from the point they arrived and cannot read what came before.
Safety numbers you can check
A 60 digit number, 30 from each account, folded across every device each of you has. When a contact's keys change the app tells you, and it tells the two cases apart: a new device gets a note saying it is usually just that, and a replaced key gets a warning to verify before you share anything private.
Check it yourself
Two devices, one number. Compare it in person or over a call you trust.
Safety number
Read it aloud together. If both sides match, nothing is in the middle.
The primitives
Every one is standard and can be looked up.
- Key agreement
- X25519 Diffie-Hellman
- Signatures
- Ed25519, on identity and signed prekeys
- Key derivation
- HKDF-SHA256, with HMAC-SHA256 chain keys
- Message encryption
- AES-256-GCM
- Attachments
- A fresh AES-256-GCM key per file, carried to each device inside the message envelope
- Safety number
- Iterated SHA-512, 5200 rounds, 30 digits per account
- Backup key wrapping
- scrypt N=65536, r=8, p=1, then AES-256-GCM
- Recovery key
- 256 bits, 64 characters, in an alphabet with no I, L, O or U
- Local key storage
- IndexedDB, in a database only this origin can open, one namespace per signed-in account
- Local history at rest
- AES-256-GCM under a key generated non-extractable, so it cannot leave the browser
Nobody outside the company has audited this build, and its source is not published. Report anything you find to contact@surfplatforms.com.
What reaches our servers
Delivery needs a destination and a time. Everything else is sealed with the message.
What the server holds
Ciphertext, and the routing needed to deliver it: which conversation, which sender, which of their devices it is for, when, and what kind of message it is.
What it does not hold
The keys to an encrypted message. Private keys are generated on the device and stay there, so there is no key on our side that opens one.
Metadata is sealed too
A voice note keeps only its length. A shared post keeps only that it is a post. Locations, contact cards, stickers and document names are sealed in full. The list works as an allowlist, so a field is readable only if it is named as such.
Backups
Encrypted on your device first, under a key wrapped by a recovery key that never leaves it. Five wrong attempts start a lockout that doubles up to an hour.
The full list names what stays readable for each kind of message, and the features that switch themselves off in an encrypted chat so no request goes out on your behalf.
Your devices
Each one has its own keys.
Each device has its own identity
A new device generates its own keys. Messages are encrypted to each of yours separately, and the sending device keeps a copy sealed to itself so your own history is readable where you wrote it.
Linking is deliberate
A new device shows a code, as a QR or a string, that you scan or paste on a device you already use. What crosses is the key to your backup, never a device identity, and nothing moves until then.
History does not follow automatically
A device reads what it was there for, or what you restore from backup. When it cannot, the app counts the messages it could not open and offers the routes available: sync, restore, or link from another device.
Old devices are dropped
Five at a time, enforced on the server. A device unused for thirty days is dropped, except when it is the only one you have.
Where it stops
Six things end to end encryption does not cover.
A group stops at 256 people
Sender keys reach 256 members, so the database refuses a 257th. A group that was already larger when that cap arrived is stored readable, and the app shows no lock in it.
Messages from before encryption
Messages sent before end to end encryption shipped were stored readable, and nothing has gone back to seal them. Everything sent since is sealed.
A game played inside a chat
A shared board needs a referee to settle who moved and in what order. The server does that, so the moves are readable to it. A move is a cell number, and the messages around the game stay sealed.
Who wrote to whom
Encryption covers what a message says, not that it was sent. We can see which account wrote to which conversation, from which device, at what time, and whether it was text, a photo or a voice note.
The people you write to
Encryption protects a message in transit and at rest. It cannot stop someone in the conversation from screenshotting it. The app posts a notice when it detects one, and that notice is a plain system message we can read.
What a device has seen
Your history lives on the devices that received it. Losing all of them, and the recovery key to your backup, means losing it. Nobody can reissue that key, including us.