QuantumChat
Post-quantum secure Zero-knowledge server Business & personal

Every conversation,
end to end β€” and quantum-safe.

QuantumChat is post-quantum, end-to-end encrypted video, messaging, and file sharing for businesses, teams, and the people they work with. The server connects people β€” it never sees your keys, your media, or your conversations.

ML-KEM-1024
Post-quantum KEM
AES-256-GCM
Per-frame media
Zero
Server-held keys
Secure call
Room 751b2438…3bbb Β· 2 participants
Post-quantum E2EE
Participant
Alex Rivera (you)
Security code matched
X8 3T P2 4R D8
Leave
Engineered for security-first teams
GDPR & US-state privacyAligned with Section 5 of the FTC Act (15 U.S.C. Β§ 45), which prohibits unfair or deceptive data practices.

EU GDPR-ready Β· U.S. state privacy acts

HIPAA-aligned design

Safeguards for PHI by architecture

Post-quantum hybrid

X25519 + ML-KEM-1024

Zero-knowledge relay

Server brokers, never decrypts

One secure platform

Everything a private conversation needs

Call, message, transfer, and store β€” each one end-to-end encrypted on the device, with the same post-quantum guarantees across the board.

Call

Encrypted video that proves who's on the line

Studio-grade video and audio over peer-to-peer WebRTC. Every frame is sealed individually with AES-256-GCM inside an isolated media worker, so the encryption boundary sits at the device β€” not the network. A short safety code lets both sides confirm there is no impostor in the middle.

  • Per-frame E2EE. Media is encrypted before it leaves the device and decrypted only on the peer's β€” relay servers carry ciphertext only.
  • Safety-code verification. A 10-character SAS confirms the post-quantum handshake matched on both ends.
  • Waiting room & moderation. The host admits each participant; sensitive rooms force a relay path and never downgrade.
  • Screen share & active speaker. Present a screen and highlight who's talking, with mute and camera controls and live reconnection.
AES-256-GCMPer frame
WebRTCPeer-to-peer
TURN/TLSNAT traversal
Secure call
Room 751b2438…3bbb Β· 2 participants Β· Moderator
1/1 linked
Participant
Alex Rivera (you)
Leave
Message

Messaging that's secure even when you're offline

Direct and group conversations built on a post-quantum PQXDH handshake and a Signal-style Double Ratchet. A recipient who's offline still receives messages as ciphertext queued by the zero-knowledge server, then decrypts them when they return β€” with forward secrecy on every message.

  • Post-quantum PQXDH. First contact derives a shared secret with hybrid ML-KEM-1024 + X25519 β€” no round-trip needed.
  • Double Ratchet forward secrecy. Every message advances the key chain, so a single compromise can't unlock the rest.
  • Authenticated groups. Sender-key broadcast with per-message ML-DSA-87 signatures, so members can't impersonate one another.
  • Disappearing messages. Optional timers travel inside the encrypted payload and expire on every participant's device.
PQXDHAsync handshake
Double RatchetForward secrecy
1:1 & groupDirect + sender-key

Message operations

Encrypted conversations

Identity
Pinned
Direct talks
1
Groups
0
Timer
Off
Message E2EE Synced now
Your ID 0Ar8i5FJ4cNFHhw5lWYV6Ah1r9E2

Deal Desk

3 members Β· end-to-end encrypted

Members
Term sheet's signed β€” sending the model over now.
M. Brooks Β· 12:01
Received and decrypted on my device. Numbers check out.
You Β· 12:02 Β· encrypted βœ“
Sent the signed LOI while you were offline β€” synced now. πŸ”’
D. Lewis Β· 12:03
Message…
Transfer

Large files, encrypted end-to-end and verifiable

Send contracts, case files, and large documents with a unique per-file key and SHA-256 integrity. Files are chunked and encrypted on the device; the server only ever holds opaque, unreadable chunks. Senders stay in control with revoke and expiry β€” and the recipient can prove the file arrived exactly as sent.

  • Per-file key + SHA-256. Each transfer gets its own key; the hash detects any tampering or corruption end-to-end.
  • Chunked & opaque at rest. Multi-megabyte files move in encrypted chunks; storage never sees plaintext or keys.
  • Revoke & expiry. Pull back a transfer after sending, or set it to expire automatically.
  • Recipient-bound. Only the intended recipient's keys can unwrap the file key.
SHA-256Integrity
Per-file keyUnique seal
RevokeSender control

Transfer operations

Verified encrypted delivery

Vault identity, recipient verification, package expiry, resumable activity, and revocation controls.

Vault posture
Unlocked
Inbox
1
Sent
3
Storage
Device only

Step 1–3

Prepare a secure package

counsel@firm.example
7 days
Select file
↑ Acquisition_Agreement.pdf Β· 8.4 MB72%

Step 4

Receive packages

NDA_Mutual_Executed.pdf

1.4 MB Β· sealed Β· SHA-256 verified

Accept Decline

Incoming sealed packages appear here after refresh or background polling.

Server stores opaque chunks it cannot read

Vault

A private vault that only you can open

Store notes, files, and voice items behind an app-lock passphrase. A random vault key encrypts every item, and that key is wrapped by your passphrase and a one-time recovery phrase β€” so the server holds only sealed data, and even a lost device doesn't mean lost access.

  • App-lock passphrase. Derived with PBKDF2-SHA-512 at 600,000 iterations; the passphrase itself is never stored.
  • Recoverable by design. A one-time recovery phrase can re-wrap your vault key if you forget the passphrase.
  • Tamper-evident sealing. Each item binds owner, version, and position into its encryption β€” defeating splice and rollback.
  • QR device transfer & sharing. Move your vault key to a second device by QR, or share a single item over a post-quantum channel.
PBKDF2-600kApp-lock KDF
RecoveryRe-wrap key
AES-256-GCMPer item

Vault operations

Vault unlocked

Device-local, end-to-end encrypted store for notes, files, and recovery material β€” sealed against splice and rollback.

App lock
Verified
Items
4
Inbound shares
1
Sync
On

Your vault

App-lock verified Β· synced

Add item
Master recovery phrase12 words Β· re-wraps the vault keysealed
Engagement_Letter.pdf1.2 MB Β· AES-256-GCMsealed
ID_scan.png2.1 MB Β· per-item keysealed
Voice memo0:42 Β· sealed audiosealed
The post-quantum era

The standards are here.
QuantumChat already runs on them.

In 2024, the U.S. National Institute of Standards and Technology finalized its first post-quantum cryptography standards. QuantumChat is built directly on them β€” ML-KEM (FIPS 203) for key encapsulation and ML-DSA (FIPS 204) for signatures β€” paired with proven classical cryptography in a hybrid design.

FIPS 203ML-KEM Β· key encapsulation
FIPS 204ML-DSA Β· signatures
HybridClassical + post-quantum
Security model

Quantum-safe today, not someday

Classical encryption can be harvested now and decrypted later by a quantum computer. QuantumChat closes that window with a hybrid key exchange β€” classical and post-quantum together β€” so a break in either alone is not enough.

  • Hybrid handshake. X25519 + ML-KEM-1024 derive every session key, transcript-bound and signed with ML-DSA-87 identities.
  • Zero-knowledge server. The relay brokers connections and stores only opaque ciphertext β€” never keys, media, messages, or files.
  • Verify the human, not the network. Short safety codes (SAS) let two people confirm there is no man-in-the-middle.
  • Fail-closed by default. If end-to-end encryption can't be established, the session is blocked β€” never silently downgraded.
X25519 + ML-KEM-1024Hybrid key agreement
ML-DSA-87Identity signatures
AES-256-GCMMedia & message sealing
Double RatchetForward secrecy
How a session is protected
Moderator Participant Relay server sees only ciphertext End-to-end encrypted channel Hybrid X25519 + ML-KEM-1024 Β· ML-DSA-87 Β· AES-256-GCM
How it works

Provisioned by your system, secured on the device

QuantumChat slots into your existing workflow without ever becoming a place where secrets live.

1

A room is provisioned

Your platform books the encounter and asks the service to create a room. No personal keys are ever sent to or generated by the server.

2

Devices run a quantum-safe handshake

Each participant authenticates, then peers derive a shared secret with a hybrid post-quantum key exchange and confirm a short safety code.

3

Everything flows encrypted

Video, messages, and files move end-to-end encrypted β€” peer-to-peer where possible. The server relays opaque data it cannot read.

256-bitAES-GCM session keys
ML-KEM-1024NIST post-quantum KEM
0Keys or plaintext on the server
E2EECiphertext may transit a TURN relay
Why QuantumChat

How it compares

Most tools encrypt only in transit. QuantumChat encrypts end-to-end, adds post-quantum protection, and keeps the server blind β€” for any conversation that has to stay private.

Capability QuantumChatQuantumChat Standard E2EE appsE2EE Conventional video toolsVideo
End-to-end encryption
Post-quantum (hybrid) cryptography
Zero-knowledge server
Ready for regulated industries (health, legal, finance)
Application-layer E2EE on direct and TURN-relayed media
Safety-code (SAS) identity verification
End-to-end encrypted file transfer
Encrypted personal vault
Fail-closed media policy + reduced-protection labels
Role-aware network diagnostics + in-panel SAS
Live participant signal status in-room
Extensible in-call toolbox (Poll, qMask)
Background replace + qMask privacy blur
Readable screen-share modes (faces preserved)
Anti-conscription group invites (explicit accept)
Unified account across Call, Message, Transfer & Vault
Supported Varies / partial Not typical
QuantumChat
QuantumChat
Secure messaging platform
Coming Soon

Platform Availability

QuantumChat is in active development across every platform. All clients are on the way β€” access opens as each platform reaches public release.

Platform Current status Release type Version target Distribution
Android Coming Soon Public Beta Android 10.0+ β†’ Coming Soon
iOS & iPadOS Coming Soon Beta iOS 16.0+ β†’ Coming Soon
macOS Coming Soon Alpha macOS 13.0+ β†’ Coming Soon
Windows Coming Soon Early Access Win 10 / 11 (64-bit) β†’ Coming Soon
Linux Coming Soon Early Access Ubuntu 22.04+ β†’ Coming Soon
End-to-end encrypted Quantum-safe by design
Status as of pre-release Β· subject to change
Questions

Frequently asked

What does "post-quantum" actually mean here?

Today's classical encryption (like the elliptic-curve key exchange used across the web) could one day be broken by a large quantum computer β€” and encrypted data captured now could be decrypted then. QuantumChat combines classical X25519 with ML-KEM-1024, a NIST-standardized post-quantum algorithm, so a session stays secure even if one of the two is later broken.

Can QuantumChat read my calls or messages?

No. Encryption and decryption happen on your device. The server is a zero-knowledge relay: it brokers connections and stores opaque ciphertext, but it never holds your keys or sees your media, messages, or files.

Can I use it for regulated or sensitive data?

Yes. QuantumChat is a general-purpose secure communications platform for businesses and individuals, and regulated industries β€” healthcare, legal, finance β€” are among the use cases it serves. Its zero-knowledge, end-to-end design is HIPAA-aligned and GDPR-ready. In the U.S. there is no single federal privacy law: requirements vary by state (for example, the CCPA/CPRA in California and comparable acts elsewhere), so state-level compliance is scoped together with your security and legal teams. The cryptographic core is also intended to undergo independent third-party review.

Which platforms are supported?

QuantumChat runs as a secure web application and installable progressive web app (PWA) on modern desktop and mobile browsers. Native mobile applications are on the roadmap.

How do I get access?

QuantumChat is rolling out to organizations and individuals from a waitlist. Use the contact below to request access for your team.

Early access

Get early access

QuantumChat is rolling out to businesses, teams, and individuals. Join the early-access list and our team will reach out to get you set up.

  • Guided onboarding for your team
  • No credit card β€” we'll contact you directly
I'm requesting access as

Your email stays confidential β€” see our . No spam.

Privacy

Your details stay private

A short notice for the early-access form. For the complete policy, read our Privacy Policy.

To access, correct, or delete your information, email support@quantumchat.cloud.