Post-quantum secureZero-knowledge serverBusiness & personal
Every conversation, end to end β and quantum-safe.
PQTalk is post-quantum, end-to-end encrypted video, messaging, and file sharing for businesses, teams, and the people they work with. The server connects people β it never sees your keys, your media, or your conversations.
Studio-grade video and audio over peer-to-peer WebRTC. Every frame is sealed individually with AES-256-GCM inside an isolated media worker, so the encryption boundary sits at the device β not the network. A short safety code lets both sides confirm there is no impostor in the middle.
Per-frame E2EE. Media is encrypted before it leaves the device and decrypted only on the peer's β relay servers carry ciphertext only.
Safety-code verification. A 10-character SAS confirms the post-quantum handshake matched on both ends.
Waiting room & moderation. The host admits each participant; sensitive rooms force a relay path and never downgrade.
Screen share & active speaker. Present a screen and highlight who's talking, with mute and camera controls and live reconnection.
AES-256-GCMPer frame
WebRTCPeer-to-peer
TURN/TLSNAT traversal
Secure call
Room 751b2438β¦3bbb Β· 2 participants Β· Moderator
1/1 linkedPost-quantum E2EE
Participant
Alex Rivera (you)
Leave
Ephemeral room tools
Participants2 in room Β· Moderator
MessageEncrypted room chat
Verification
Signal
Linked
Peers
1/1
SAS
1/1
Media
PQC E2EE
Message
Messaging that's secure even when you're offline
Direct and group conversations built on a post-quantum PQXDH handshake and a Signal-style Double Ratchet. A recipient who's offline still receives messages as ciphertext queued by the zero-knowledge server, then decrypts them when they return β with forward secrecy on every message.
Post-quantum PQXDH. First contact derives a shared secret with hybrid ML-KEM-1024 + X25519 β no round-trip needed.
Double Ratchet forward secrecy. Every message advances the key chain, so a single compromise can't unlock the rest.
Authenticated groups. Sender-key broadcast with per-message ML-DSA-87 signatures, so members can't impersonate one another.
Disappearing messages. Optional timers travel inside the encrypted payload and expire on every participant's device.
PQXDHAsync handshake
Double RatchetForward secrecy
1:1 & groupDirect + sender-key
Message operations
Encrypted conversations
Identity
Pinned
Direct talks
1
Groups
0
Timer
Off
MessageE2EESynced now
Your ID0Ar8i5FJ4cNFHhw5lWYV6Ah1r9E2
Deal Desk
3 members Β· end-to-end encrypted
Members
Term sheet's signed β sending the model over now.
M. Brooks Β· 12:01
Received and decrypted on my device. Numbers check out.
You Β· 12:02 Β· encrypted β
Sent the signed LOI while you were offline β synced now. π
D. Lewis Β· 12:03
Messageβ¦
Transfer
Large files, encrypted end-to-end and verifiable
Send contracts, case files, and large documents with a unique per-file key and SHA-256 integrity. Files are chunked and encrypted on the device; the server only ever holds opaque, unreadable chunks. Senders stay in control with revoke and expiry β and the recipient can prove the file arrived exactly as sent.
Per-file key + SHA-256. Each transfer gets its own key; the hash detects any tampering or corruption end-to-end.
Chunked & opaque at rest. Multi-megabyte files move in encrypted chunks; storage never sees plaintext or keys.
Revoke & expiry. Pull back a transfer after sending, or set it to expire automatically.
Recipient-bound. Only the intended recipient's keys can unwrap the file key.
Incoming sealed packages appear here after refresh or background polling.
Server stores opaque chunks it cannot read
Vault
A private vault that only you can open
Store notes, files, and voice items behind an app-lock passphrase. A random vault key encrypts every item, and that key is wrapped by your passphrase and a one-time recovery phrase β so the server holds only sealed data, and even a lost device doesn't mean lost access.
App-lock passphrase. Derived with PBKDF2-SHA-512 at 600,000 iterations; the passphrase itself is never stored.
Recoverable by design. A one-time recovery phrase can re-wrap your vault key if you forget the passphrase.
Tamper-evident sealing. Each item binds owner, version, and position into its encryption β defeating splice and rollback.
QR device transfer & sharing. Move your vault key to a second device by QR, or share a single item over a post-quantum channel.
PBKDF2-600kApp-lock KDF
RecoveryRe-wrap key
AES-256-GCMPer item
Vault operations
Vault unlocked
Device-local, end-to-end encrypted store for notes, files, and recovery material β sealed against splice and rollback.
App lock
Verified
Items
4
Inbound shares
1
Sync
On
Your vault
App-lock verified Β· synced
Add item
Master recovery phrase12 words Β· re-wraps the vault keysealed
Engagement_Letter.pdf1.2 MB Β· AES-256-GCMsealed
ID_scan.png2.1 MB Β· per-item keysealed
Voice memo0:42 Β· sealed audiosealed
The post-quantum era
The standards are here. PQTalk already runs on them.
In 2024, the U.S. National Institute of Standards and Technology finalized its first post-quantum cryptography standards. PQTalk is built directly on them β ML-KEM (FIPS 203) for key encapsulation and ML-DSA (FIPS 204) for signatures β paired with proven classical cryptography in a hybrid design.
FIPS 203ML-KEM Β· key encapsulation
FIPS 204ML-DSA Β· signatures
HybridClassical + post-quantum
Security model
Quantum-safe today, not someday
Classical encryption can be harvested now and decrypted later by a quantum computer. PQTalk closes that window with a hybrid key exchange β classical and post-quantum together β so a break in either alone is not enough.
Hybrid handshake. X25519 + ML-KEM-1024 derive every session key, transcript-bound and signed with ML-DSA-87 identities.
Zero-knowledge server. The relay brokers connections and stores only opaque ciphertext β never keys, media, messages, or files.
Verify the human, not the network. Short safety codes (SAS) let two people confirm there is no man-in-the-middle.
Fail-closed by default. If end-to-end encryption can't be established, the session is blocked β never silently downgraded.
X25519 + ML-KEM-1024Hybrid key agreement
ML-DSA-87Identity signatures
AES-256-GCMMedia & message sealing
Double RatchetForward secrecy
How a session is protected
How it works
Provisioned by your system, secured on the device
PQTalk slots into your existing workflow without ever becoming a place where secrets live.
1
A room is provisioned
Your platform books the encounter and asks the service to create a room. No personal keys are ever sent to or generated by the server.
2
Devices run a quantum-safe handshake
Each participant authenticates, then peers derive a shared secret with a hybrid post-quantum key exchange and confirm a short safety code.
3
Everything flows encrypted
Video, messages, and files move end-to-end encrypted β peer-to-peer where possible. The server relays opaque data it cannot read.
256-bitAES-GCM session keys
ML-KEM-1024NIST post-quantum KEM
0Keys or plaintext on the server
E2EECiphertext may transit a TURN relay
Why PQTalk
How it compares
Most tools encrypt only in transit. PQTalk encrypts end-to-end, adds post-quantum protection, and keeps the server blind β for any conversation that has to stay private.
Capability
PQTalk
Standard E2EE appsE2EE
Conventional video toolsVideo
End-to-end encryption
Post-quantum (hybrid) cryptography
Zero-knowledge server
Ready for regulated industries (health, legal, finance)
Application-layer E2EE on direct and TURN-relayed media
Safety-code (SAS) identity verification
End-to-end encrypted file transfer
Encrypted personal vault
Fail-closed media policy + reduced-protection labels
Role-aware network diagnostics + in-panel SAS
Live participant signal status in-room
Extensible in-call toolbox (Poll, qMask)
Background replace + qMask privacy blur
Readable screen-share modes (faces preserved)
Anti-conscription group invites (explicit accept)
Unified account across Call, Message, Transfer & Vault
Supported Varies / partial Not typical
PQTalk
Secure messaging platform
Coming Soon
Platform Availability
PQTalk platform availability is controlled by release evidence. Web/PWA remains the current public-access surface; native mobile and tablet clients open only after their production-readiness gates pass.
Platform
Current status
Release type
Version target
Distribution
Android
Coming Soon
Public Beta
Android 10.0+
β Coming Soon
iOS & iPadOS
Coming Soon
Beta
iOS 16.0+
β Coming Soon
macOS
Coming Soon
Alpha
macOS 13.0+
β Coming Soon
Windows
Coming Soon
Early Access
Win 10 / 11 (64-bit)
β Coming Soon
Linux
Coming Soon
Early Access
Ubuntu 22.04+
β Coming Soon
Browser
Call
Message
Transfer
Vault
Install
Google Chrome
Desktop Β· 88+
Microsoft Edge
Desktop Β· 88+
Chrome
Android Β· 88+
Safari
macOS Β· 16+ *
Safari
iOS & iPadOS Β· 16+ *
Mozilla Firefox
Desktop Β· 97+ **
FullLimitedFresh feature-specific browser matrix evidence is required before public promotion.
* Safari (macOS Β· iOS): protected post-quantum call media is not currently admitted; the Call capability remains Limited and must not silently downgrade; screen share and push are unavailable on iOS. ** Firefox: protected post-quantum call media is not currently admitted; the Call capability remains Limited and must not silently downgrade. Minimums reflect the app build (ES2022 + WebRTC Encoded Transform): Chrome/Edge 88+, Chrome for Android 88+, Safari 16+, Firefox 97+.
End-to-end encryptedQuantum-safe by design
Status as of 29 July 2026 pre-release validation Β· browser claims require fresh matrix evidence
Questions
Frequently asked
What does "post-quantum" actually mean here?
Today's classical encryption (like the elliptic-curve key exchange used across the web) could one day be broken by a large quantum computer β and encrypted data captured now could be decrypted then. PQTalk combines classical X25519 with ML-KEM-1024, a NIST-standardized post-quantum algorithm, so a session stays secure even if one of the two is later broken.
Can PQTalk read my calls or messages?
No. Encryption and decryption happen on your device. The server is a zero-knowledge relay: it brokers connections and stores opaque ciphertext, but it never holds your keys or sees your media, messages, or files.
Can I use it for regulated or sensitive data?
PQTalk can support regulated or sensitive workflows when your organization completes its own security, legal, and contractual review. Its zero-knowledge, end-to-end architecture can help reduce exposed plaintext, but this website does not represent a certification, legal opinion, or automatic compliance claim. The cryptographic core is also intended to undergo independent third-party review.
Which platforms are supported?
PQTalk runs as a secure web application and installable progressive web app (PWA) on modern desktop and mobile browsers. Native mobile and tablet applications open only after each iOS, iPadOS, Android, and Android tablet release target has fresh production-readiness evidence.
How do I get access?
PQTalk is rolling out to organizations and individuals from a waitlist. Use the contact below to request access for your team.
Early access
Get early access
PQTalk is rolling out to businesses, teams, and individuals. Join the early-access list and our team will reach out to get you set up.