Security
Security is a launch gate, not a marketing shortcut.
MsgYap Web uses client-side identity keys, encrypted local storage, authenticated relay sessions and end-to-end encrypted personal messaging flows. The system is still unaudited.
Client-side identity
Identity and signing keys are created and protected client-side.
Authenticated relay
Clients prove possession of their signing identity before authenticated routing actions.
Encrypted messages
Personal message payloads are encrypted before relay transport.
Encrypted local vault
Sensitive local account material is protected at rest.
Safety verification
Conversation fingerprints help detect identity changes.
Rate and origin controls
The relay includes origin validation, size limits, rate limiting and ownership checks.
What we do not claim yet
- Independent cryptographic audit completion.
- Production-grade true multi-device synchronization.
- Signal Protocol compatibility or Signal-equivalent assurance.
- Large encrypted group-call infrastructure.
- Native Android/iOS cryptographic parity with the web app.
Do not use the current beta for highly sensitive or regulated communications until planned independent review and production launch gates are complete.