Security

Security model overview.

Ares Chat is designed around local device keys, encrypted channel data, and accountless setup.

Your device Creates and holds keys locally
Encrypted envelope →
Ares relay Coordinates encrypted channel traffic
Encrypted envelope →
Recipient device Decrypts locally
Design boundaries

What the server can coordinate, and what it is designed not to receive.

Ares Chat avoids account identity and contact graph assumptions. The server coordinates setup and delivery state while encrypted content remains device-centered.

Ares servers may process

  • Encrypted envelopes
  • Channel identifiers
  • Delivery state
  • Setup session state

Designed not to receive

  • Message plaintext
  • Phone number identity
  • Contact book uploads
  • Public social profile

Local device keys

Device identity, signature, and envelope keys are used to claim channels and verify device actions.

Encrypted channel flow

Messages and protected file material are designed to remain encrypted before reaching Ares servers.

Generic notifications

Push notifications are intended as activity signals, not message previews.