IslandicSystems
Private beta · Lagos first

Everything they do. On a server that cannot read it.

VaultComm is a complete communication ecosystem — chat, voice, video, communities and live audio — where your keys are generated on your device from a twelve-word phrase and never transmitted. We route ciphertext we are incapable of decoding. This is not a privacy policy. It is a property of the mathematics.

Your identity · derived on device
source12-word BIP-39 phrase
derivationBIP-32 key tree, offline
storageSecure Enclave / StrongBox
phone number email address account to subpoena

No phone number means no SIM-swap, no carrier order, and nothing for us to hand over.


Why this exists

Privacy and features are sold as a trade-off. They shouldn't be.

Every user is forced to pick one today. Most pick features and quietly accept the cost. Four structural problems make that choice feel inevitable — and all four are design decisions, not laws of nature.

01
Platforms hold the key authority
Even where end-to-end encryption is switched on, the platform controls key distribution, backup and identity. One policy change, subpoena or breach reaches every conversation at once.
02
Metadata is the real product
Who spoke to whom, when, how often, from where. Collected even when content is encrypted — and frequently more revealing than the messages themselves.
03
Identity is rented, not owned
Accounts can be suspended, deleted or handed over without notice. Tie one to a phone number and a SIM swap takes your entire social graph with it.
04
Leaving costs you your network
Switching is not an individual decision — it is a group one. Nobody moves alone, so nobody moves. That inertia is the moat the incumbents actually own.

The product

One app. Five modes. The same guarantee across all of them.

This is the surface area the incumbents have, plus the one they never built.

01
Messaging
1:1 and group chat · voice notes · disappearing messages · reactions · replies · media
02
Voice & video
1:1 and group calls to 500 participants · screen share · SRTP/DTLS encrypted media
03
Communities
Channels · roles · permissions · discovery · up to 10,000 members per community
04
Live spaces
Public and private audio rooms to 10,000 listeners · ticketed entry · record and replay
05
Creator calls
Bookable paid 1:1 sessions · subscriptions · tipping · instant payout rails

Every mode inherits the same six properties

Zero-knowledge server
End-to-end encrypted
No metadata retention
No content scanning
No backdoor, by design
Independently auditable

The foundations

Six decisions that make the guarantee structural.

Self-sovereign identity

A BIP-39 phrase is your account. No phone number, no email — nothing for us to hand over or for an attacker to SIM-swap.

Signal-grade protocol

X3DH and Double Ratchet via libsignal for every message, call and file. No custom cryptography anywhere in the stack.

Zero-knowledge relay

Servers store public keys and encrypted blobs. A full database breach yields ciphertext and nothing else.

Decentralised media

Files are encrypted client-side, then pinned to IPFS. No single host stores your content or can be ordered to remove it.

Full feature parity

iOS, Android and web — chat, voice, video, communities, live spaces. One identity across every device you own.

Monetisation in-protocol

Paid spaces, subscriptions and creator calls settle without the platform ever reading the conversation.


How it works

Three layers. The middle one is deliberately blind.

The defensibility is architectural rather than contractual. We could not comply with a content request if we wanted to — and that is precisely the point.

Client
Flutter · iOS, Android, Web
  • BIP-39 phrase derives a BIP-32 key tree
  • Keychain, Secure Enclave, StrongBox
  • libsignal — X3DH + Double Ratchet
  • AES-256-GCM media encryption
Everything secret happens here.
Relay
Go services · zero-knowledge
  • Routes sealed envelopes, nothing more
  • Public key and pre-key directory
  • WebRTC signalling (SDP / ICE)
  • Presence in Redis, time-limited
Sees ciphertext and public keys.
Storage
Postgres · Cassandra · IPFS
  • Encrypted blobs with enforced TTL
  • Media pinned to IPFS by content ID
  • Vault / KMS for server-side secrets
  • No plaintext at rest, anywhere
A full breach yields noise.

Rust owns everything that touches key material — one shared library, called over FFI from every client, independently auditable by anyone who asks. An external cryptographic audit is scheduled before public beta, not after it.


Competitive landscape

We are honest about what the incumbents do well.

Signal's cryptography is excellent, and we use the same protocol. Telegram's product surface is genuinely good. The difference is what surrounds the encryption — and who holds identity.

Capability WhatsApp Telegram Signal Session VaultComm
E2EE on all messages by default
Audited, standard protocol
Works without a phone number
User holds key authority
Communities at scale
Live audio spaces
Creator monetisation
Voice & video calling
Yes Partial or conditional No

Assessed September 2026 against each platform's published documentation and default settings.


The creator layer

Creators are not a revenue feature. They are the distribution strategy.

Messaging is a group-switching problem: nobody moves alone. A creator with an audience moves thousands of people in one decision — and gets paid to do it.

01

A creator joins

They bring an existing audience and a reason to be reached: paid spaces, bookable calls, subscriber-only channels.

02

The audience follows

Fans arrive for one creator and land in a full messenger. Acquisition is paid for by the creator's own promotion, not an ad budget.

03

The graph densifies

Those users message each other. Communities form. The network stops depending on the creator who seeded it.

04

The loop compounds

A dense audience attracts the next creator. The take rate funds the incentives. The flywheel becomes self-funding.


Where we are today

Not a deck and a plan. A working system.

We would rather tell you exactly what exists than imply more than it does. Here is the honest split.

Built and working
  • Auth service — refresh-token families, replay detection, session lifecycle
  • API service — per-device keys, sealed envelopes, conversations
  • Device registry, signed pre-key rotation, one-time pre-key pools
  • Message router, WebRTC signalling, active call controller
  • Flutter client — onboarding, chat, calls, discovery, payments UI
Next, before public beta
  • crypto-core — full audited libsignal integration
  • External cryptographic audit and first penetration test
  • Group E2EE via sender keys; multi-device key sync
  • Live spaces SFU at scale; creator payout rails
  • App Store and Google Play submission; public beta in Lagos
6
backend services running today
15
feature modules in the client
3
platforms from one codebase
0
plaintext records at rest

VaultComm is in private beta and has no public users yet. A full external security audit is scheduled ahead of public launch — for this product, an unaudited launch is not a launch.

Early access

Join the private beta.

We are onboarding creators, communities and regulated professionals in Lagos first, then the Nigeria–UK and Nigeria–US diaspora corridors. Tell us who you are and what you need to move, and we will get you in.