SECURITY & PRIVACY

We cannot read your messages even if we wanted to, because the keys never leave your device and no data touches our servers.

SecurityNet Threat Model

SecurityNet is designed to protect the confidentiality of message and file contents against interception, inspection, logging, moderation, or analysis by service providers, intermediaries, or third parties.

All communication is encrypted end-to-end and travels directly between participating devices, making message contents cryptographically opaque to network inspection.

Please note: SecurityNet cannot conceal the existence of network connections or protect against compromised endpoints, malware on user devices, or global traffic analysis by network operators.

View our statement on Regional Availability and Compliance.

Key Security Features

SecurityNet is engineered to protect your data and privacy. Here’s a quick overview of the key features that make SecurityNet one of the most secure communication platforms:

  • End-to-End Encryption: All messages and files are encrypted from the moment they leave your device, ensuring only the sender and recipient can read them — not even SecurityNet.      
  • No Metadata Tracking: SecurityNet does not track activity or store communication metadata.    
  • No Backdoors: SecurityNet contains no backdoors and does not provide special access mechanisms.                                        
  • Encrypted Private Tunnel: Each connection uses a direct peer-to-peer encrypted tunnel wrapped in TLS 1.3.                                      
  • Strong Authentication: Optional two-factor authentication (2FA) provides additional login security.                                                                      
  • Secure, Private Access: Each SecurityNet ID is encrypted and not linked to personal identity.      

End-to-End Encryption 

  • One-time-use encryption key for every session
  • Never reused
  • Never stored
  • Never visible to any server 
  • Destroyed after each connection
  • Wrapped inside TLS 1.3
  • World-class protection
  • Hides metadata
  • Hides DNS lookups (via built-in DoH)
  • To ISPs and censors, it looks like ordinary encrypted web traffic — there are no readable contents, no protocol markers, and nothing to inspect.

Only the sender and the recipient can decrypt anything. No one in between — not even SecurityNet.

Metadata Protection

Metadata Protection

SecurityNet is designed to minimise and compartmentalise metadata exposure.

Not stored centrally:

  • File contents
  • Message contents
  • Per-file delivery keys
  • Contact lists
  • Communication history
  • Connection logs
  • Session encryption keys                                                                           

Stored in encrypted form (for licensing & identity control only):

  • Your SecurityNet ID (AES-encrypted at rest)
  • License entitlement information

No plaintext identifiers are stored.

No communication metadata is retained after session termination.

The connection mediator is designed not to retain communication activity after a connection has been established.

Our Policy — No Logs, No Metadata 

SecurityNet never collects or stores metadata on any server.
No message logs, timestamps, or IP records are ever stored centrally — your activity remains private between peers.

For your convenience, SecurityNet keeps a local log on your own computer showing your connections and delivered files. This log is fully private, never transmitted, and can be deleted at any time.

Note: Your Internet Service Provider (ISP) or VPN may still see limited technical details, such as SecurityNet's IP address, connection times, or total data volume. This is standard for all Internet traffic and lies outside SecurityNet’s control.

In general Internet usage, a VPN may reduce the visibility of connection details to an Internet Service Provider by routing traffic through an encrypted intermediary. This is a general characteristic of VPN technology and operates independently of SecurityNet.

Your privacy within the SecurityNet network is designed to be fully contained — no external systems or servers store who you connected with or what you shared.

Click here for more info...

Network Visibility & Traffic Analysis:

An ISP can see that encrypted traffic is occurring and the destination IP address being contacted, but cannot see message content, identities, files, or encryption keys.

What is NOT visible:

  • Message content
  • Files or file contents
  • User identities
  • Contact lists
  • Encryption keys
  • Application-layer metadata

Encrypted sessions are wrapped in standard TLS (HTTPS), making SecurityNet traffic functionally indistinguishable from normal secure web traffic.

An ISP can see:

  • That encrypted data is being transmitted
  • The destination IP address
  • Session timing and data volume

But not:

  • Who you are communicating with (at the application level)
  • What is being sent
  • The contents of any messages or files
  • The meaning of the traffic

Optional Network Privacy Layer

SecurityNet protects message content, not network routing visibility.

If additional network-level privacy is required, users may choose to use a VPN or anonymising network as part of their general Internet configuration.

This can:

  • Reduce visibility of destination IP addresses from the local ISP
  • Mask the user’s public IP address
  • Add an additional network privacy layer

However, this shifts routing trust to the VPN provider and does not replace endpoint security.

Infrastructure & Server Model

SecurityNet’s architecture separates software ownership, website hosting, and mediator infrastructure.

  • SecurityNet is operated by a UK-registered company.
  • The public website is hosted in the United Kingdom. This website holds the Licensing and Payments functions as well as background operational functionality.
  • The VPS infrastructure used for session discovery and encrypted key exchange is hosted in Iceland.
  • The SecurityNet application itself is hosted on user PCs (or macOS devices).

The Connection Mediator:

  • Facilitates connection setup between authorised devices
  • Assists in encrypted session key exchange
  • Does not store messages or files
  • Does not retain encryption keys
  • Does not maintain central message history
  • Does not log IP addresses or session metadata

Once a session is established, encrypted communication flows directly between participating devices.

SecurityNet’s confidentiality model does not rely on trusting server infrastructure or hosting jurisdiction. Message contents remain protected through end-to-end encryption, and session keys are not stored server-side.

Even if any hosting provider were compelled to cooperate with authorities, encrypted message contents would remain cryptographically inaccessible.

Your SecurityNet ID 

Your SecurityNet ID is your private address inside the system — chosen by you.

  • Must be unique (like an email address)
  • Stored only in encrypted form
  • One ID per device (for multi-user licenses)
  • Not tied to personal identity
  • Only shared with people you choose to communicate with

SecurityNet never stores your real name, phone, or personal identity.

Optional 2FA for the Desktop App

SecurityNet includes built-in Two-Factor Authentication for the desktop app.

  • Automatically generates a QR code
  • Works with Google/Microsoft Authenticator
  • Protects the desktop login itself
  • Stored locally (never uploaded)
  • No SMS, no email codes
  • Even if someone steals your laptop, the app remains locked

This protects your local device, not your cloud account — because we don’t use the cloud.

What We Do NOT Collect

SecurityNet does not collect:

  • Files
  • Messages
  • IP addresses
  • Your metadata
  • Device identifiers
  • Location data
  • Usage analytics
  • Server-side logs

The only data stored is:

  • Encrypted SecurityNet ID
  • License record (for purchase/support only)

Why "End-to-End Encrypted" is no longer enough

For years, “end-to-end encryption” has been presented as the gold standard for private communication.

Today, however, new regulatory approaches are shifting surveillance from the network to the device itself — especially on mobile platforms — through what is known as client-side scanning, undermining what that promise really means.

  • Modern “secure” messengers can be compelled to scan messages before encryption.
  • This turns your own device into a surveillance point.
  • True privacy requires that no central platform can be forced to perform such scanning.
  • SecurityNet is designed, by architecture, with no cloud, no central service, and no mobile OS dependency.

Why It Matters

Most tools encrypt messages.
SecurityNet encrypts everything — the messages, the tunnel, the metadata, the DNS, and the very existence of your communication.

Whether you're:

  • coordinating sensitive business projects
  • sharing confidential documents
  • communicating privately inside restrictive jurisdictions
  • protecting family conversations
  • working in environments hostile to privacy

SecurityNet keeps your data private — from everyone.

Only sender and recipient ever see anything.
Not even us. Never us!