01
Content stays unreadable
Veilcord uses the pinned MLS X-Wing profile: hybrid post-quantum confidentiality with classical Ed25519 authentication. The server cannot recover message content.
Private communication / direct first
Veilcord is a private space that prefers the direct path and keeps encryption at the edge—even when an opaque relay carries a message.
No ads. No analytics. No third-party scripts.
01 / The route
Veilcord races for the direct peer-to-peer path and promotes it as soon as it is proven. A separate memory-only relay can keep encrypted messages moving while restrictive networks prevent direct contact.
The browser uses WebRTC; installed apps add stronger native path discovery. If direct remains unavailable, free relay covers messages. Relayed calls and files require a plan or your own relay.
02 / The boundary
01
Veilcord uses the pinned MLS X-Wing profile: hybrid post-quantum confidentiality with classical Ed25519 authentication. The server cannot recover message content.
02
Peers may see network addresses needed for a direct connection. That is a property of peer-to-peer networking, and Veilcord states it plainly.
03
TURN is not offered. The application relay forwards MLS ciphertext only, keeps no message history, and yields to direct P2P. Cloudflare and the operator can still observe connection metadata.
03 / The promise
A smaller surface. A sharper protocol. A communicator built to keep the path between you and the people you choose.
Ready when you are
Start instantly in the browser, or install native direct for stronger NAT traversal.
Every client prefers direct P2P. Encrypted message relay is the fallback; relayed calls and files require a plan or self-hosting.