RenkerVault
TypeScript · open source

End-to-end encrypted chat with a content-blind relay — privacy by architecture, not by trust.

A relay operator should have no plaintext access, ever. RenkerVault is built so the server sees only ciphertext and there is no server-side content to scan or classify.

View on GitHubRead the README

What it does

Content-blind relay

The server handles ciphertext only; there is nothing in message content to evaluate server-side.

Post-quantum hybrid handshake

X25519 combined with ML-KEM-768.

Double ratchet

1:1 chats use an X3DH hybrid handshake (X25519 + ML-KEM-768) into a Double Ratchet, giving forward secrecy and post-compromise security.

Groups and channels

Epoch-key groups and read-only broadcast channels. Groups are structurally weaker than 1:1 chats: no forward secrecy within an epoch and no sender authentication between members, so use them for small, mutually trusting groups.

Duress alarm

A first-class feature of the design.

Honest limits

Read this first. A security-conscious prototype/MVP. The Double Ratchet composition is not externally audited, groups are weaker than 1:1 chats, and nothing here is “unhackable”. Read SECURITY.md for the full list of stated limitations.