Security
Two promises, and what each one actually means.
End-to-end encrypted — our servers cannot hear your team
Audio is encrypted on the phone that speaks it and decrypted on the phones that hear it. The keys are generated on the devices and never leave them.
Our servers move encrypted packets between phones. They hold no key and can decrypt nothing. That is a property of how the system is built, not a policy we promise to follow.
Group keys are rotated whenever the membership of a group changes, so a phone that has been removed cannot decrypt one further second of audio.
Nothing is recorded or stored, anywhere
There is no recording feature, no archive and no playback. Audio is never written to disk — not on our servers, not on the phone, and not temporarily for debugging.
This is not a setting an administrator can turn on. It does not exist.
What we do hold
- Who is in which workspace and group, so the right phones receive a transmission.
- Device records, so a lost phone can be revoked.
- The fact that an emergency broadcast happened, and who raised it — because an alert that overrides everyone's mute needs to be accountable.
- Billing records: what was bought, when, and by whom.
We do not claim any third-party audit, certification or compliance standard. When one exists it will be named here, with the certificate.