Consumer

VPX Secure

Encrypted messaging and calls with no account, no phone number and no password. Your identity is a recovery phrase only you hold, so no one, us included, can read your messages or sign in as you. Use it free in your browser, upgrade in crypto, or deploy it across your organisation.

BIP39 recovery phrase, Ed25519 keypair; server stores only the public keyIdentity
Challenge signed by your key, no password stored; authenticator second factorSign-in
Double Ratchet protocol, end-to-end encryptedMessaging
DTLS-SRTP, encrypted device to deviceVoice & video
Overview

What it
does

Every mainstream secure messenger still begins by learning who you are. Signal wants your phone number, others want an email, all of them want an account, and that account is the thread that ties your private conversations back to your real identity, and the thing we could be compelled to hand over.

VPX Secure removes the thread. There is no account, no phone number, no email and no password. Your identity is a recovery phrase generated on your device, and we store only the matching public key. You sign in by signing a challenge with a key only your phrase can produce, so there is nothing on our side that can read your messages or log in as you.

Use it free in your browser and pay in crypto from your own wallet, so no bank or card processor ever learns you use it (the standalone browser edition is launching soon). It is also available inside the VoicePro app, and can be deployed across an organisation for legal, healthcare and financial teams, where confidentiality is a regulatory obligation. All of it on open, independently audited standards.

How It Works

The process,
step by step

From a recovery phrase to a sealed conversation, here is why no one in the middle, including us, can read your messages or become you.

01

A phrase, not an account

You start with a recovery phrase generated on your device. It derives your keys; we only ever see the matching public key. No phone number, no email, no password.

02

Sign in by signature

To log in, your device signs a one-time challenge with a key only your phrase can produce. We hold no password and no secret that could authenticate as you, plus an authenticator code as a second factor.

03

Keys that never leave you

Your messages are end-to-end encrypted with the open Double Ratchet protocol, and your calls with DTLS-SRTP. The keys live only on your devices and in your encrypted backup, so our servers carry ciphertext they cannot open.

04

You are the recovery

Your phrase restores everything from an encrypted backup we hold only as ciphertext. Keep the phrase and you keep your account; lose it and no one, us included, can restore it. No backdoor, by design.

Capabilities

Built for
performance

Privacy from architecture, not a policy. Each of these is a property of how Secure is built, not a promise we ask you to trust.

01Zero PII

No identity to hand over

No phone number, email or password. Your identity is a phrase only you hold, so there is nothing on our side that links Secure to the real you.

02

We cannot add a device

Every device must be authorized by a signature only your recovery phrase can produce, and we hold only your public key. There is no device we can create that reads your messages or acts as you.

03

End-to-end encrypted

Messages, calls and files are encrypted on your device on open, independently audited standards (the Double Ratchet protocol, DTLS-SRTP). The network only ever sees ciphertext.

04

Pay without being seen

Pay in crypto from your own wallet. No card, no bank, no processor, so the payment never becomes a record of who you are.

05

Zero content retention

Calls and messages are never logged or stored. We keep no content, and signalling metadata is minimised and configurable to zero.

06

Yours to hold, or your team's to deploy

Self-custody for individuals, or a dedicated and on-premises deployment for an organisation that needs to run it under its own controls.

Technical Specs

Under the
hood

IdentityBIP39 recovery phrase, Ed25519 keypair; server stores only the public key
Sign-inChallenge signed by your key, no password stored; authenticator second factor
MessagingDouble Ratchet protocol, end-to-end encrypted
Voice & videoDTLS-SRTP, encrypted device to device
Backup & recoveryAn encrypted key backup only your recovery phrase can unlock; we hold only ciphertext
PaymentCrypto, self-custodied from your own wallet, for the standalone edition
PricingFree £0 (capped history and rooms, no calls); Premium £12.99/month in crypto (uncapped, with calls); £9.99/month in-app or included on Business+ Elite
DeploymentStandalone browser, in the VoicePro app, or dedicated / on-premises for organisations
ComplianceGDPR Art. 32, HIPAA technical safeguards, ISO 27001-aligned (not yet certified)
RetentionZero content; signalling metadata minimised and configurable to zero
Integration

Hold it yourself, or deploy it

Use it in your browser with your own keys, build it into your product over API and SDK, or run it for a whole organisation. Open standards throughout, so nothing depends on trusting a black box.

Open, audited protocols
Double Ratchet encryption
DTLS-SRTP calls
BIP39 recovery phrase
REST API & SDK
Dedicated infrastructure
On-premises gateway
GDPR & HIPAA aligned
Who it is for

Built for
your operation

For anyone who wants encrypted communication without handing over an identity to get it, from one person to a whole organisation.

PRIVACY01

People who want no account

Encrypted messaging and calls with nothing that ties them to your real identity. A phrase, a browser, and no phone number to give up.

Get in touch
HIGH-RISK02

Journalists & sources

No account record to subpoena, no device we can add, no metadata retained beyond the minimum. Content unreadable to us by construction.

Get in touch
REGULATED03

Legal, healthcare & finance

Deploy the same encryption across your organisation on dedicated or on-premises infrastructure, where confidentiality is a compliance obligation, not a feature.

Get in touch
No Security Theatre

What it
doesn't do

Encryption is a precise promise, not a magic shield. Any product that claims to put you beyond the reach of a determined state actor is not being straight with you.

Content is private. Metadata is being solved.

The server can still see that a message happened and when, though never what was said. We keep zero content and minimise signalling metadata to zero now, and remove the single-operator view as routing decentralises onto the VPX network. We will say so plainly until that ships.

It protects the line, not the phone.

Encryption stops us, your carrier and the network reading you. It cannot protect a device already taken over by spyware or left unlocked, which is true of every encrypted app.

Start a Discussion

Ready to activate Secure?

Free in your browser, or £12.99 a month in crypto for Premium, launching soon. Also £9.99 in the VoicePro app or included on Business+ Elite, and deployable across your organisation.

Join the waitlist