Trust Center

SKYTAL Security

SKYTAL is a P2P-first secure messenger with E2EE. Below is what is protected today, how delivery works, and the limits we describe honestly.

Confirmed capabilities

Active security mechanisms are marked as available. Direct P2P for messages and client-side attachment E2EE are development directions — not current public claims.

Messages

Personal messages are encrypted on the sender device and decrypted on the recipient device. The server relays ciphertext and is not intended to store plaintext.

Calls

WebRTC P2P-first: a direct connection between devices when possible. When a direct route is unavailable, a protected relay fallback is used.

Files

Attachments are transferred and stored in encrypted form through the server media layer. Direct device-to-device file transfer is a development direction, not a current feature.

Keys

Private keys are generated and stored on the device. Public keys required for exchange are sent to the server.

Delivery architecture

SKYTAL architecture overviewDeviceDeviceRelayInfrastructure

P2P-first architecture diagram

Server role

The server enables encrypted delivery, call signaling, and fallback route coordination. It does not replace on-device E2EE.

Metadata

SKYTAL minimizes the role of server infrastructure and the volume of technical data required to operate the service. Infrastructure may process metadata needed for routing and delivery.

Invitations

Access to SKYTAL starts with an invitation. An invitation does not verify identity, employer, job title, or organizational membership.

What we do not claim

  • SKYTAL is not a fully decentralized messenger
  • Infrastructure may process metadata required for routing
  • Messages and files are not delivered directly P2P between devices today