Security posture

Security you can
actually stand behind

No impossible promises. Just honest, layered protection, and a clear account of what we protect, how, and what we can't promise.

What we promise, honestly

Claims we're willing to put in writing, because they're true.

End-to-end encrypted

Message, call and file content is encrypted on your device with the audited Matrix protocol (Olm/Megolm). We don't hold the keys, so we can't read it.

Your server, offshore

Run on a dedicated instance in a jurisdiction of your choosing. Your data doesn't sit inside a Big Tech cloud.

Minimal data by design

We collect as little as possible: no phone number required. What we don't have can't be leaked, sold, or handed over.

Audited, open protocol

We don't invent cryptography. Matrix is open and independently reviewed, used by the French state and the German armed forces.

Hardened infrastructure

TLS everywhere, HSTS, security headers, firewalling, fail2ban, automatic security updates and encrypted backups.

Reachable over Tor

The whole app, not just the API, runs as a Tor onion service. Open it in Tor Browser and sign in normally: your network and your provider see a Tor connection, not who you are talking to.

Closed registration

Public sign-up is switched off. Accounts are created by us, per client. Nobody can register themselves on your instance.

We describe exactly what we protect, how, and where the limits are. Every claim on this page is one you can check.

What we protect, and what we don't

Security is defense in depth, not a magic checkbox. Here's the honest picture.

WhatHow it's protected
Content (messages, calls, files)End-to-end encrypted (Olm/Megolm); we don't hold the keys
Data in transitTLS 1.2+/1.3, HSTS, modern ciphers
The serverContainer hardening, firewall, fail2ban, automatic updates
Your identityNo phone number, minimal data, private registration
Metadata (who talks to whom, when)Reduced, but not fully hidden, an honest limitation
A compromised user deviceWe can't protect a phone or laptop that's already infected
If our server were ever breached: your content is still end-to-end encrypted, so an attacker cannot read your messages or calls. They'd see minimal metadata and could disrupt service. That's exactly why E2E plus minimal data is the real shield: it limits the damage even in the worst case.

Defense in depth: the layers

No single control is enough. Protection comes from stacking them.

Cryptography

E2E by default, cross-signing, encrypted key backup and device verification.

Transport

Automatic TLS, HSTS preload, and a strict set of security headers (CSP, X-Frame-Options, nosniff, Referrer-Policy).

Application

Third-party trackers and error reporting off, guest access off, nothing phoning home.

Server

Public registration off, federation off (your server does not talk to other Matrix servers), rate limiting on login and sign-up.

Infrastructure

no-new-privileges, database never exposed publicly, isolated volumes, random credentials.

Operations

Encrypted off-site daily backups, monitoring, and a written incident-response plan.

Responsible disclosure

Found a vulnerability? We want to hear from you. Report it to security@sovryk.com (see /.well-known/security.txt). We don't take legal action against good-faith security researchers.

Security is a process, not a checkbox; this posture is updated with every infrastructure change.

Stealth mode: Sovryk over Tor

Encryption hides what you say. It does not hide that you connected, or from where. Tor closes that gap.

What it is

Sovryk runs as a Tor onion service. The full app and the homeserver answer on one address, so your network operator, your internet provider and anyone watching the line see a Tor connection and nothing else. They cannot tell that you are using Sovryk, let alone with whom.

How to use it

On a computer, open Tor Browser. On a phone, run Orbot and open the address in your browser. Sign in exactly as usual. Same account, same messages, nothing to configure.

http://qfh2qsuuscuwafcnbocklcfwr4mjsyq3ddvpcn7iydlu3f335taxlqyd.onion

Optional. The normal address works fine for most firms, and it is simpler. Tor is there for when the fact of the connection is itself sensitive.