Security you can
actually stand behind
No impossible promises. Just honest, layered protection, and a clear account of what we protect, how, and what we can't promise.
What we promise, honestly
Claims we're willing to put in writing, because they're true.
End-to-end encrypted
Message, call and file content is encrypted on your device with the audited Matrix protocol (Olm/Megolm). We don't hold the keys, so we can't read it.
Your server, offshore
Run on a dedicated instance in a jurisdiction of your choosing. Your data doesn't sit inside a Big Tech cloud.
Minimal data by design
We collect as little as possible: no phone number required. What we don't have can't be leaked, sold, or handed over.
Audited, open protocol
We don't invent cryptography. Matrix is open and independently reviewed, used by the French state and the German armed forces.
Hardened infrastructure
TLS everywhere, HSTS, security headers, firewalling, fail2ban, automatic security updates and encrypted backups.
Reachable over Tor
The whole app, not just the API, runs as a Tor onion service. Open it in Tor Browser and sign in normally: your network and your provider see a Tor connection, not who you are talking to.
Closed registration
Public sign-up is switched off. Accounts are created by us, per client. Nobody can register themselves on your instance.
We describe exactly what we protect, how, and where the limits are. Every claim on this page is one you can check.
What we protect, and what we don't
Security is defense in depth, not a magic checkbox. Here's the honest picture.
| What | How it's protected |
|---|---|
| Content (messages, calls, files) | End-to-end encrypted (Olm/Megolm); we don't hold the keys |
| Data in transit | TLS 1.2+/1.3, HSTS, modern ciphers |
| The server | Container hardening, firewall, fail2ban, automatic updates |
| Your identity | No phone number, minimal data, private registration |
| Metadata (who talks to whom, when) | Reduced, but not fully hidden, an honest limitation |
| A compromised user device | We can't protect a phone or laptop that's already infected |
Defense in depth: the layers
No single control is enough. Protection comes from stacking them.
Cryptography
E2E by default, cross-signing, encrypted key backup and device verification.
Transport
Automatic TLS, HSTS preload, and a strict set of security headers (CSP, X-Frame-Options, nosniff, Referrer-Policy).
Application
Third-party trackers and error reporting off, guest access off, nothing phoning home.
Server
Public registration off, federation off (your server does not talk to other Matrix servers), rate limiting on login and sign-up.
Infrastructure
no-new-privileges, database never exposed publicly, isolated volumes, random credentials.
Operations
Encrypted off-site daily backups, monitoring, and a written incident-response plan.
Responsible disclosure
Found a vulnerability? We want to hear from you. Report it to security@sovryk.com (see /.well-known/security.txt). We don't take legal action against good-faith security researchers.
Security is a process, not a checkbox; this posture is updated with every infrastructure change.
Stealth mode: Sovryk over Tor
Encryption hides what you say. It does not hide that you connected, or from where. Tor closes that gap.
What it is
Sovryk runs as a Tor onion service. The full app and the homeserver answer on one address, so your network operator, your internet provider and anyone watching the line see a Tor connection and nothing else. They cannot tell that you are using Sovryk, let alone with whom.
How to use it
On a computer, open Tor Browser. On a phone, run Orbot and open the address in your browser. Sign in exactly as usual. Same account, same messages, nothing to configure.
http://qfh2qsuuscuwafcnbocklcfwr4mjsyq3ddvpcn7iydlu3f335taxlqyd.onion
Optional. The normal address works fine for most firms, and it is simpler. Tor is there for when the fact of the connection is itself sensitive.