TRUST & BOUNDARIES

Know what you share.
And with whom.

One keyring connects the conversation to the services in a room. Trust is your decision, not a badge supplied by someone else.

v0.4.0 · Release milestone · Reviewed source · Release notes

A room gives context. Trust gives access.

A node shares a named service with a room. The host checks both its keyring and current room membership when a member connects. An invitation alone is not permission to reach the service.

The address is service.node.room.vox. The service name comes from its sharer; the node and room aliases are yours. The address identifies a service, not an SSH endpoint implied by a room or a node alone.

Removing a share or withdrawing trust cuts its live sessions. There is no extra per-service permission matrix. File sharing uses a room-bound service and a pull model; file data does not become a server-hosted chat attachment.

Service naming · Live-session revocation · File pull model

Classical and post-quantum, together

Vox’s hybrid design combines two families of algorithms. That describes a construction, not a guarantee that either family is infallible.

PurposeClassicalPost-quantum
Key agreementX25519ML-KEM-768
SignaturesEd25519ML-DSA-65

Keys protect content. Comparing fingerprints and choosing the right nodes to trust remain human responsibilities. A compromised endpoint can expose plaintext regardless of the algorithms used in transit.

Cryptographic policy · Identity model

No central messaging operator

Rooms live on member nodes. Reachable, user-run anchors help peers find one another, coordinate connections, and relay encrypted traffic when needed.

An anchor acting only as an intermediary holds no room keys or room log. A node can also be a room member; in that role it reads only according to the same keyring rules as other members. Being an anchor does not confer special read access.

Members that are never online together can exchange retained messages through another member that overlaps with both. An anchor that is not a member is not a store-and-forward mailbox.

Anchor storage boundary · Offline members · Reachability design

What encryption cannot promise

  • No read-receipt inference. A connection or a received sender key does not prove someone read a message.
  • No protection from a trusted recipient’s copy. Retention removes content from cooperating nodes. It cannot erase screenshots or copies elsewhere.
  • No anonymity guarantee. Traffic timing, volume, and connection information can remain observable.
  • No endpoint-compromise guarantee. Malware, a keylogger, or access to a running node can expose content and secrets.
  • No guaranteed reachability. Offline nodes, blocked paths, and unavailable intermediaries can delay or prevent delivery.

The daemon can run several attached nodes independently. Detaching one is not the same as locking the machine or stopping every other node. The keyring’s passphrase window concerns trust changes, not whether an attached node continues running.

Full threat model · Node lifecycle

What this release does, and does not

This page describes v0.4.0, which the installation guide and the one-line installer give you: the terminal client on x86_64 Linux and on Apple Silicon Macs with macOS 13 or later, and there Vox.app, the native Mac app, beside it. The homepage’s app study is illustrative, not a screenshot of the app.

The app shows a notification for each message in a room you are not looking at, grouped by room: who wrote, and whether it was to you, urgent or a file, never the message’s text. Its text and controls meet WCAG 2.1 AA contrast, with brighter colours when Increase Contrast is on; that is a claim about contrast only.

Each node keeps a 14-day record of what it refused and every change of access it decided, sealed at rest under the node’s identity and never sent anywhere. The family LAN puts a room’s trusted members on one subnet; on a Mac its helper is a system service that creates network interfaces for Vox and nothing else. Deniable mode is not part of the design, not advertised as a privacy guarantee.

Source inspection is not an independent security audit. Check the release milestone, the release notes and the implementation before relying on a capability.