SECURITY & PRIVACY

We cannot read your messages even if we wanted to. Message and file contents are encrypted end-to-end, and SecurityNet does not store copies on its servers.

SecurityNet Threat Model

SecurityNet is designed to protect the confidentiality of message and file contents against interception, inspection, logging, moderation, or analysis by service providers, intermediaries, or third parties.

Message and file contents are encrypted end-to-end between participating devices. Communication is direct device-to-device where possible, with SecurityNet's infrastructure assisting connection establishment when required.

Please note: SecurityNet cannot conceal the existence of network connections or protect against compromised endpoints, malware on user devices, or global traffic analysis by network operators.

View our statement on Regional Availability and Compliance.

Key Security Features

SecurityNet is engineered to protect your data and privacy. Here’s a quick overview of the key features that make SecurityNet one of the most secure communication platforms:

  • End-to-End Encryption: Messages and files are encrypted on your device before transmission, ensuring only the intended participants can read them — not even SecurityNet.      
  • No Metadata Tracking: SecurityNet does not use communication metadata for tracking, advertising, profiling, or analytics.    
  • No Backdoors: SecurityNet contains no backdoors and does not provide special access mechanisms.                                        
  • Encrypted Private Tunnel: Communication between participants is protected by an encrypted tunnel, with direct device-to-device connections used where possible.                                      
  • Strong Authentication: Optional two-factor authentication (2FA) provides additional login security.                                                                
  • Secure, Private Access: Each SecurityNet ID is encrypted and not linked to personal identity.      

End-to-End Encryption 

SecurityNet protects message and file contents with end-to-end encryption between participating devices.

Communication content is:

  • Encrypted before transmission
  • Protected while travelling between devices
  • Decrypted only on the receiving device
  • Not stored as a readable copy on the mediator
  • Not accessible to SecurityNet

Encryption keys are:

  • Generated for the communication process
  • Not retained by the mediator
  • Not available to SecurityNet as a means of reading your communications

Network observers may still be able to see that encrypted traffic is taking place, together with ordinary network-level information such as IP addresses, timing and data volume.

SecurityNet protects the contents of your communication. Network-level privacy can be strengthened separately by using a VPN.

Metadata Protection

Metadata Protection

SecurityNet is designed to minimise and compartmentalise metadata exposure.

Not stored centrally:

  • File contents
  • Message contents
  • Per-file delivery keys
  • Contact lists
  • Communication history
  • Connection logs
  • Session encryption keys                                                                           

Stored in encrypted form (for licensing & identity control only):

  • Your SecurityNet ID (AES-encrypted at rest)
  • License entitlement information

No plaintext SecurityNet IDs are stored centrally.

The connection mediator does not intentionally create or retain application-level activity logs.

Our published Privacy Verification evidence documents the mediator's logging configuration and the checks used to verify this behaviour.

Our Policy — No Central Activity Logging

SecurityNet does not intentionally create or retain central application-level logs of your communication activity.

Messages and files are not stored on the connection mediator, and SecurityNet does not maintain a central history of who communicated with whom or what was exchanged.

For your convenience, SecurityNet maintains a local Activity Log on your own computer showing communication activity such as file transfers. This information remains under your control and is not transmitted to the mediator as a central activity record.

Network-level visibility is different. Your Internet Service Provider, VPN provider, or other network infrastructure may still observe ordinary connection information such as IP addresses, timing and data volume. This lies outside SecurityNet's application-level logging controls.

Our mediator configuration and logging controls are documented in our published Privacy Verification evidence.

Network Visibility & Traffic Analysis:

An ISP can see that encrypted traffic is occurring and the destination IP address being contacted, but cannot see message content, identities, files, or encryption keys.

What is NOT visible:

  • Message content
  • Files or file contents
  • User identities
  • Contact lists
  • Encryption keys
  • Application-layer metadata

Encrypted sessions use standard TLS (HTTPS), so the traffic appears as encrypted web traffic at the network layer.

An ISP can see:

  • That encrypted data is being transmitted
  • The destination IP address
  • Session timing and data volume

But not:

  • Who you are communicating with (at the application level)
  • What is being sent
  • The contents of any messages or files
  • The meaning of the traffic

Optional Network Privacy Layer

SecurityNet protects message content, not network routing visibility.

If additional network-level privacy is required, users may choose to use a VPN or anonymising network as part of their general Internet configuration.

This can:

  • Reduce visibility of destination IP addresses from the local ISP
  • Mask the user's public IP address from destination services
  • Add an additional network privacy layer

However, this shifts routing trust to the VPN provider and does not replace endpoint security.

Infrastructure & Server Model

SecurityNet’s architecture separates software ownership, website hosting, and mediator infrastructure.

  • SecurityNet is operated by a UK-registered company.
  • The public website is hosted in the United Kingdom. This website holds the Licensing and Payments functions as well as background operational functionality.
  • The VPS infrastructure used for session discovery and encrypted key exchange is hosted in Iceland.
  • The SecurityNet application runs on users' own Windows or macOS computers.

The Connection Mediator:

  • Facilitates connection setup between authorised devices
  • Assists in encrypted session key exchange
  • Does not store messages or files
  • Does not retain encryption keys
  • Does not maintain central message history
  • Does not intentionally create or retain application-level connection activity logs

Where a direct connection can be established, encrypted communication flows directly between participating devices.

SecurityNet’s confidentiality model does not rely on trusting server infrastructure or hosting jurisdiction. Message contents remain protected through end-to-end encryption, and session keys are not stored server-side.

Even if a hosting provider were compelled to cooperate with authorities, the infrastructure is not designed to hold readable copies of message or file contents.

Your SecurityNet ID 

Your SecurityNet ID is your private address inside the system — chosen by you.

  • Must be unique (like an email address)
  • Stored only in encrypted form
  • One ID per device (for multi-user licenses)
  • Not tied to personal identity
  • Only shared with people you choose to communicate with

Your SecurityNet ID does not need to contain your real name, phone number, or other real-world identity.

Optional 2FA for the Desktop App

SecurityNet includes built-in Two-Factor Authentication for the desktop app.

  • Automatically generates a QR code
  • Works with Google/Microsoft Authenticator
  • Protects the desktop login itself
  • Stored locally (never uploaded)
  • No SMS, no email codes
  • Even if someone steals your laptop, the app remains locked

This protects your local device, not your cloud account — because we don’t use the cloud.

What We Do NOT Collect

SecurityNet does not collect or centrally retain:

  • Files
  • Messages
  • Contact lists
  • Your metadata
  • Location data
  • Usage analytics
  • Communication data for advertising or profiling
  • Central communication activity logs

Data retained for identity, licensing and support includes:

  • Encrypted SecurityNet ID
  • License record (for purchase/support only)

Why "End-to-End Encrypted" is no longer enough

For years, “end-to-end encryption” has been presented as the gold standard for private communication.

Today, however, proposals for client-side scanning demonstrate that protecting data in transit does not necessarily protect it from inspection on the device itself.

  • Client-side scanning can inspect messages or files before they are encrypted for transmission.
  • This can turn the endpoint itself into a potential inspection point.
  • End-to-end encryption therefore protects only one part of the communication path; endpoint behaviour matters too.
  • SecurityNet is designed without cloud message storage and without dependence on a mobile operating-system messaging ecosystem.

Why It Matters

Encryption protects content. Privacy also depends on what happens around that content.

SecurityNet is designed to reduce the amount of communication data exposed beyond the participating devices — by avoiding cloud message storage, central communication histories, and application-level activity logging on the mediator.

Whether you're:

  • coordinating sensitive business projects
  • sharing confidential documents
  • communicating privately inside restrictive jurisdictions
  • protecting family conversations
  • working in environments hostile to privacy

SecurityNet was designed around a simple principle: your private communications should remain under the control of the people participating in them — not become stored content on someone else's communication platform.

Private. Direct. Under Your Control.