Everything they do. On a server that cannot read it.
VaultComm is a complete communication ecosystem — chat, voice, video, communities and live audio — where your keys are generated on your device from a twelve-word phrase and never transmitted. We route ciphertext we are incapable of decoding. This is not a privacy policy. It is a property of the mathematics.
No phone number means no SIM-swap, no carrier order, and nothing for us to hand over.
Why this exists
Privacy and features are sold as a trade-off. They shouldn't be.
Every user is forced to pick one today. Most pick features and quietly accept the cost. Four structural problems make that choice feel inevitable — and all four are design decisions, not laws of nature.
The product
One app. Five modes. The same guarantee across all of them.
This is the surface area the incumbents have, plus the one they never built.
Every mode inherits the same six properties
The foundations
Six decisions that make the guarantee structural.
Self-sovereign identity
A BIP-39 phrase is your account. No phone number, no email — nothing for us to hand over or for an attacker to SIM-swap.
Signal-grade protocol
X3DH and Double Ratchet via libsignal for every message, call and file. No custom cryptography anywhere in the stack.
Zero-knowledge relay
Servers store public keys and encrypted blobs. A full database breach yields ciphertext and nothing else.
Decentralised media
Files are encrypted client-side, then pinned to IPFS. No single host stores your content or can be ordered to remove it.
Full feature parity
iOS, Android and web — chat, voice, video, communities, live spaces. One identity across every device you own.
Monetisation in-protocol
Paid spaces, subscriptions and creator calls settle without the platform ever reading the conversation.
How it works
Three layers. The middle one is deliberately blind.
The defensibility is architectural rather than contractual. We could not comply with a content request if we wanted to — and that is precisely the point.
- BIP-39 phrase derives a BIP-32 key tree
- Keychain, Secure Enclave, StrongBox
- libsignal — X3DH + Double Ratchet
- AES-256-GCM media encryption
- Routes sealed envelopes, nothing more
- Public key and pre-key directory
- WebRTC signalling (SDP / ICE)
- Presence in Redis, time-limited
- Encrypted blobs with enforced TTL
- Media pinned to IPFS by content ID
- Vault / KMS for server-side secrets
- No plaintext at rest, anywhere
Rust owns everything that touches key material — one shared library, called over FFI from every client, independently auditable by anyone who asks. An external cryptographic audit is scheduled before public beta, not after it.
Competitive landscape
We are honest about what the incumbents do well.
Signal's cryptography is excellent, and we use the same protocol. Telegram's product surface is genuinely good. The difference is what surrounds the encryption — and who holds identity.
| Capability | Telegram | Signal | Session | VaultComm | |
|---|---|---|---|---|---|
| E2EE on all messages by default | ● | ○ | ● | ● | ● |
| Audited, standard protocol | ● | ○ | ● | ◐ | ● |
| Works without a phone number | ○ | ○ | ○ | ● | ● |
| User holds key authority | ○ | ○ | ◐ | ● | ● |
| Communities at scale | ◐ | ● | ○ | ○ | ● |
| Live audio spaces | ○ | ○ | ○ | ○ | ● |
| Creator monetisation | ◐ | ● | ○ | ○ | ● |
| Voice & video calling | ● | ● | ● | ○ | ● |
Assessed September 2026 against each platform's published documentation and default settings.
The creator layer
Creators are not a revenue feature. They are the distribution strategy.
Messaging is a group-switching problem: nobody moves alone. A creator with an audience moves thousands of people in one decision — and gets paid to do it.
A creator joins
They bring an existing audience and a reason to be reached: paid spaces, bookable calls, subscriber-only channels.
The audience follows
Fans arrive for one creator and land in a full messenger. Acquisition is paid for by the creator's own promotion, not an ad budget.
The graph densifies
Those users message each other. Communities form. The network stops depending on the creator who seeded it.
The loop compounds
A dense audience attracts the next creator. The take rate funds the incentives. The flywheel becomes self-funding.
Where we are today
Not a deck and a plan. A working system.
We would rather tell you exactly what exists than imply more than it does. Here is the honest split.
- ✓ Auth service — refresh-token families, replay detection, session lifecycle
- ✓ API service — per-device keys, sealed envelopes, conversations
- ✓ Device registry, signed pre-key rotation, one-time pre-key pools
- ✓ Message router, WebRTC signalling, active call controller
- ✓ Flutter client — onboarding, chat, calls, discovery, payments UI
- → crypto-core — full audited libsignal integration
- → External cryptographic audit and first penetration test
- → Group E2EE via sender keys; multi-device key sync
- → Live spaces SFU at scale; creator payout rails
- → App Store and Google Play submission; public beta in Lagos
VaultComm is in private beta and has no public users yet. A full external security audit is scheduled ahead of public launch — for this product, an unaudited launch is not a launch.
Early access
Join the private beta.
We are onboarding creators, communities and regulated professionals in Lagos first, then the Nigeria–UK and Nigeria–US diaspora corridors. Tell us who you are and what you need to move, and we will get you in.