Security

Security is a launch gate, not a marketing shortcut.

MsgYap Web uses client-side identity keys, encrypted local storage, authenticated relay sessions and end-to-end encrypted personal messaging flows. The system is still unaudited.

Client-side identity

Identity and signing keys are created and protected client-side.

Authenticated relay

Clients prove possession of their signing identity before authenticated routing actions.

Encrypted messages

Personal message payloads are encrypted before relay transport.

Encrypted local vault

Sensitive local account material is protected at rest.

Safety verification

Conversation fingerprints help detect identity changes.

Rate and origin controls

The relay includes origin validation, size limits, rate limiting and ownership checks.

What we do not claim yet

  • Independent cryptographic audit completion.
  • Production-grade true multi-device synchronization.
  • Signal Protocol compatibility or Signal-equivalent assurance.
  • Large encrypted group-call infrastructure.
  • Native Android/iOS cryptographic parity with the web app.
Do not use the current beta for highly sensitive or regulated communications until planned independent review and production launch gates are complete.