TypeScript · open source
End-to-end encrypted chat with a content-blind relay — privacy by architecture, not by trust.
A relay operator should have no plaintext access, ever. RenkerVault is built so the server sees only ciphertext and there is no server-side content to scan or classify.
View on GitHubRead the READMEWhat it does
Content-blind relay
The server handles ciphertext only; there is nothing in message content to evaluate server-side.
Post-quantum hybrid handshake
X25519 combined with ML-KEM-768.
Double ratchet
1:1 chats use an X3DH hybrid handshake (X25519 + ML-KEM-768) into a Double Ratchet, giving forward secrecy and post-compromise security.
Groups and channels
Epoch-key groups and read-only broadcast channels. Groups are structurally weaker than 1:1 chats: no forward secrecy within an epoch and no sender authentication between members, so use them for small, mutually trusting groups.
Duress alarm
A first-class feature of the design.
Honest limits
Read this first. A security-conscious prototype/MVP. The Double Ratchet composition is not externally audited, groups are weaker than 1:1 chats, and nothing here is “unhackable”. Read SECURITY.md for the full list of stated limitations.