How the encryption works.

The protocol in full, from the handshake before your first message to the limits at the end.

One message, end to end

Follow a single message from your device to theirs.

  1. You write it

    The message is encrypted on your device under a key derived for that one message. If it cannot be encrypted it is not sent. There is no unencrypted fallback.

  2. We carry it

    What arrives on our servers is the encrypted version and the routing needed to deliver it. That is all we can hand to anyone.

  3. They open it

    Their device holds the only key that opens it, and each of their devices gets its own copy under its own key.

The handshake

What happens before your first message is sent.

X3DH to start a conversation

An extended triple Diffie-Hellman against the recipient's published keys, so the first message is already encrypted with nobody waiting online. Each device keeps a pool of 50 one-time keys, tops it up before it runs dry, and rotates its signed key weekly.

A Double Ratchet per thread

Every message advances a ratchet and is sealed under its own key. One key does not open the thread, and the chain heals after a compromise. Up to 2,000 keys are held back for messages that arrive out of order, so a long time offline still reads in full.

Sender keys in groups

One encryption per sender covers the whole group, up to 256 people. Someone leaving forces a new key generation and cannot read what comes after. Someone joining is admitted from the point they arrived and cannot read what came before.

Safety numbers you can check

A 60 digit number, 30 from each account, folded across every device each of you has. When a contact's keys change the app tells you, and it tells the two cases apart: a new device gets a note saying it is usually just that, and a replaced key gets a warning to verify before you share anything private.

Check it yourself

Two devices, one number. Compare it in person or over a call you trust.

Safety number

410932771460582319467720518863502419387612604481593772065038

Read it aloud together. If both sides match, nothing is in the middle.

The primitives

Every one is standard and can be looked up.

Key agreement
X25519 Diffie-Hellman
Signatures
Ed25519, on identity and signed prekeys
Key derivation
HKDF-SHA256, with HMAC-SHA256 chain keys
Message encryption
AES-256-GCM
Attachments
A fresh AES-256-GCM key per file, carried to each device inside the message envelope
Safety number
Iterated SHA-512, 5200 rounds, 30 digits per account
Backup key wrapping
scrypt N=65536, r=8, p=1, then AES-256-GCM
Recovery key
256 bits, 64 characters, in an alphabet with no I, L, O or U
Local key storage
IndexedDB, in a database only this origin can open, one namespace per signed-in account
Local history at rest
AES-256-GCM under a key generated non-extractable, so it cannot leave the browser

Nobody outside the company has audited this build, and its source is not published. Report anything you find to contact@surfplatforms.com.

What reaches our servers

Delivery needs a destination and a time. Everything else is sealed with the message.

What the server holds

Ciphertext, and the routing needed to deliver it: which conversation, which sender, which of their devices it is for, when, and what kind of message it is.

What it does not hold

The keys to an encrypted message. Private keys are generated on the device and stay there, so there is no key on our side that opens one.

Metadata is sealed too

A voice note keeps only its length. A shared post keeps only that it is a post. Locations, contact cards, stickers and document names are sealed in full. The list works as an allowlist, so a field is readable only if it is named as such.

Backups

Encrypted on your device first, under a key wrapped by a recovery key that never leaves it. Five wrong attempts start a lockout that doubles up to an hour.

The full list names what stays readable for each kind of message, and the features that switch themselves off in an encrypted chat so no request goes out on your behalf.

Your devices

Each one has its own keys.

Each device has its own identity

A new device generates its own keys. Messages are encrypted to each of yours separately, and the sending device keeps a copy sealed to itself so your own history is readable where you wrote it.

Linking is deliberate

A new device shows a code, as a QR or a string, that you scan or paste on a device you already use. What crosses is the key to your backup, never a device identity, and nothing moves until then.

History does not follow automatically

A device reads what it was there for, or what you restore from backup. When it cannot, the app counts the messages it could not open and offers the routes available: sync, restore, or link from another device.

Old devices are dropped

Five at a time, enforced on the server. A device unused for thirty days is dropped, except when it is the only one you have.

Where it stops

Six things end to end encryption does not cover.

A group stops at 256 people

Sender keys reach 256 members, so the database refuses a 257th. A group that was already larger when that cap arrived is stored readable, and the app shows no lock in it.

Messages from before encryption

Messages sent before end to end encryption shipped were stored readable, and nothing has gone back to seal them. Everything sent since is sealed.

A game played inside a chat

A shared board needs a referee to settle who moved and in what order. The server does that, so the moves are readable to it. A move is a cell number, and the messages around the game stay sealed.

Who wrote to whom

Encryption covers what a message says, not that it was sent. We can see which account wrote to which conversation, from which device, at what time, and whether it was text, a photo or a voice note.

The people you write to

Encryption protects a message in transit and at rest. It cannot stop someone in the conversation from screenshotting it. The app posts a notice when it detects one, and that notice is a plain system message we can read.

What a device has seen

Your history lives on the devices that received it. Losing all of them, and the recovery key to your backup, means losing it. Nobody can reissue that key, including us.