Trust Center
SKYTAL Security
SKYTAL is a P2P-first secure messenger with E2EE. Below is what is protected today, how delivery works, and the limits we describe honestly.
Confirmed capabilities
Active security mechanisms are marked as available. Direct P2P for messages and client-side attachment E2EE are development directions — not current public claims.
Messages
Personal messages are encrypted on the sender device and decrypted on the recipient device. The server relays ciphertext and is not intended to store plaintext.
Calls
WebRTC P2P-first: a direct connection between devices when possible. When a direct route is unavailable, a protected relay fallback is used.
Files
Attachments are transferred and stored in encrypted form through the server media layer. Direct device-to-device file transfer is a development direction, not a current feature.
Keys
Private keys are generated and stored on the device. Public keys required for exchange are sent to the server.
Server role
The server enables encrypted delivery, call signaling, and fallback route coordination. It does not replace on-device E2EE.
Metadata
SKYTAL minimizes the role of server infrastructure and the volume of technical data required to operate the service. Infrastructure may process metadata needed for routing and delivery.
Invitations
Access to SKYTAL starts with an invitation. An invitation does not verify identity, employer, job title, or organizational membership.
What we do not claim
- SKYTAL is not a fully decentralized messenger
- Infrastructure may process metadata required for routing
- Messages and files are not delivered directly P2P between devices today