Technical Overview
How SecurityNet Works
SecurityNet is built around a simple principle:
secure communication should be direct, controlled, and independent of cloud platforms.
Direct Encrypted Sessions
When two authorised users communicate, SecurityNet establishes a temporary encrypted session between their devices. Each new session creates a new encrypted tunnel using a freshly generated, one-time encryption password.
Each data session within the encrypted tunnel has its own unique session ID and freshly generated, one-time encryption password. Encryption passwords are not reused between sessions.
If a transfer fails, SecurityNet automatically retries the transfer in the next processing cycle. The mediator is used again as needed to re-establish the secure connection.
No Central Message Storage
Direct messages and files are not stored on a central server. Encrypted content is exchanged between authorised devices.
SecurityNet does not maintain a central history of direct communications or retain copies of directly exchanged messages and files. Direct transfers are not queued centrally, so both endpoints must be online for the transfer to occur.
Group Chat is a separate, opt-in feature. Because group members may not all be online simultaneously, encrypted Group Chat data is temporarily stored centrally for retrieval by authorised group members. The server does not hold the encryption keys required to read that content.
Explicit Permission Model
Communication requires deliberate pairing between users.
No user can connect without mutual approval.
Within licensed networks, new users must be authorised by the License Owner before they can communicate. Permissions such as external invitations or group creation are disabled by default and must be explicitly enabled.
SecurityNet operates on a default-deny principle: access is granted intentionally, not assumed.
Runtime Integrity Protection
All SecurityNet executables are digitally signed.
At startup, each component verifies its own integrity and will refuse to run if modified or tampered with. This prevents altered software from participating in the network.
Detailed Architecture Documentation
A more detailed architectural overview of SecurityNet’s design, session model, and governance structure is available below.
This document outlines SecurityNet’s session model, encryption lifecycle, permission governance, and relay design for independent technical review.
Download the full Technical Architecture Overview (PDF, 7 pages)
Version 1.1 — March 2026