Security Threat Model

This threat model defines the security goals, adversaries considered, trust assumptions, and explicit limitations of SecurityNet’s design.

SecurityNet is designed to protect the confidentiality and integrity of communications between explicitly authorised participants.

This document outlines:

  • What SecurityNet protects
  • Who it protects against
  • The architectural assumptions it relies on
  • The threats it does not attempt to mitigate

SecurityNet prioritises controlled, private communication between trusted participants without relying on cloud communication infrastructure.

1. Scope & Security Objectives

Primary Objective

To ensure that:

  • Message and file contents remain confidential
  • Encryption passwords are freshly generated for each session and are never reused
  • Communication content remains encrypted and unreadable to intermediaries
  • No central SecurityNet system has access to readable communication content


Security Goals

SecurityNet is designed so that:

  • Only explicitly paired participants can communicate
  • Each encrypted tunnel uses a freshly generated, one-time encryption password
  • Each data session within the tunnel has its own unique session ID and freshly generated, one-time encryption password
  • No message or file content is stored centrally
  • No central metadata database storing communication history exists

SecurityNet assumes a default-deny model: communication must be explicitly permitted.

2. Assets Protected

SecurityNet is designed to protect the following assets:

  • Message contents
  • File contents
  • Session encryption passwords
  • Per-data-session encryption passwords
  • Permission pairings between users
  • Session integrity

Message and file contents, together with their encryption passwords, are not stored centrally. Permission and identity information required to establish authorised connections is handled separately from communication content.

SecurityNet ID Records

SecurityNet stores limited identity and licensing information required to operate the service:

  • SecurityNet ID, stored in encrypted form
  • Licensing and authorisation information

Central SecurityNet systems do not store:

  • Message contents
  • File contents
  • Session encryption passwords
  • Per-data-session encryption passwords
  • Communication content or communication history

The SecurityNet ID is stored in encrypted form and is not transmitted as part of communication sessions.

3. Adversaries Considered 

SecurityNet is designed to protect against:

Network-Level Observers

  • ISPs
  • Network intermediaries
  • Deep Packet Inspection systems

  • Hosting providers

  • Passive traffic monitors

These entities may observe that encrypted traffic is taking place, together with ordinary network-level information such as IP addresses, timing and data volume, but cannot read the encrypted communication content.


Mediator Infrastructure Operators

SecurityNet uses a lightweight mediator to introduce trusted devices. The mediator facilitates connection establishment between authorised devices but does not store message or file content.

The mediator server:

  • Facilitates connection establishment between authorised devices
  • Handles the temporary connection information required for that process
  • Does not retain application-level communication activity after connection establishment

The mediator does not:

  • Store message content
  • Store file content
  • Store encryption passwords

  • Maintain communication logs

All encryption and decryption occur on endpoint devices.


Unauthorised Users

SecurityNet prevents connection attempts without:

  • Mutual SecurityNet ID pairing

  • License owner authorisation within a licensed network

There is no public discovery mechanism.

4. Threats Explicitly NOT Mitigated

SecurityNet does not claim to protect against:

  • Compromised user devices

  • Malware on endpoints

  • Physical device seizure
  • Global traffic correlation attacks
  • Nation-state mass surveillance capabilities
  • Malicious insiders within an authorised licensed network

If an endpoint is compromised, SecurityNet cannot guarantee confidentiality.

5. Trust Assumptions

SecurityNet relies on the following assumptions:

  • User devices are not compromised

  • Cryptographic primitives remain secure

  • TLS infrastructure is not broken
  • Mediator and relay infrastructure does not retain application-level communication activity logs
  • License Owners verify and explicitly authorise new users before communication is permitted

SecurityNet is not anonymous-by-default. It is private-by-design within controlled networks.

6. Network Visibility & Traffic Analysis

External network observers may be able to see:

  • That encrypted traffic is taking place

  • The destination IP address of the mediator server or peer device

  • Connection timing and data volume

They cannot see from the encrypted SecurityNet traffic:

  • Message content

  • File contents

  • Encryption passwords
  • SecurityNet IDs
  • Contact lists

SecurityNet communication is encrypted and carried within standard TLS traffic.

Users requiring additional destination privacy may choose to use a VPN or privacy network as part of their broader network configuration.

7. Architectural Boundaries

SecurityNet separates responsibilities:

  • Website infrastructure (UK hosted)

  • VPS mediator infrastructure (Iceland hosted)

  • Endpoint encryption engines (user devices)

Encrypted content never passes through or is stored by the website infrastructure.

The mediator facilitates connection establishment between authorised devices and does not store communication content.

All content encryption and decryption occurs on endpoint devices.

8. Design Philosophy

SecurityNet is not:

  • A social messaging platform

  • A cloud communication service

  • A metadata-harvesting system

It is a controlled, encrypted communication environment built around trusted participants and peer-to-peer connections where possible.

SecurityNet minimises central infrastructure to reduce attack surface.