Phantom is encrypted chat where messages travel directly between machines, sealed with keys only you hold. There is no server to subpoena, no account database to leak, and no company reading the room — including ours.
CURVE25519XSALSA20-POLY1305HYPERSWARM DHTOPEN WIRE FORMAT
◢ SIGNAL ACQUIRED ◣ENCRYPTION SCOPE — CH 1
LIVE · TYPE TO TRANSMIT
CIPHERTEXT ▸∅ waiting for signal…
NONCE 0x000000KEY EPHEMERALMITM NONE DETECTED
0x01 KEY_EXCHANGE
Your identity is a keypair
No email. No phone number. On first launch Phantom generates a Curve25519 keypair and seals the secret half inside your OS keystore. Your public fingerprint is who you are — verify it out-of-band once, and impersonation is mathematically off the table.
IDENTITY MODULE
FINGERPRINT — SHA-256 / PUBKEY
A7F20E9C4B1D83E6
Compare four groups in person, over a call, or by QR. Match = sealed channel. The key never leaves your machine.
0x02 CHAT
Rooms without a landlord
A room is a checksummed code — PH-XXXX-XXXX-XXXX-YY — hashed into a DHT topic. Anyone holding the code meets there; nobody hosts it. Channels, replies, pins, edits and delete-for-all all travel encrypted, and owner / admin permissions are enforced by every peer independently — there is no server to bribe.
ROOM — PH-7Q2M-V4XK-9DTL-3F
3 PEERS · ALL SESSIONS SEALED · 0 RELAYS
0x10 VOICE_OFFER
Voice that never touches a tower
Calls are direct WebRTC streams between peers — signaled over Phantom's own encrypted channel, never through a vendor's switchboard. Screen sharing asks you which window to expose, with an explicit picker. Nothing is captured silently.
VOICE CHANNEL — VU
P2P STREAM · OPUS · DTLS-SRTP
0x20 FILE_START
Files in sealed chunks
Transfers are sliced into 512 KB chunks, each one independently encrypted and streamed peer-to-peer — up to 512 MB per file. Hard buffer caps mean a hostile peer can't flood your memory or your disk. No cloud bucket ever sees a byte.
TRANSFER — blueprint_v3.pdf
0% · 512KB CHUNKS · EACH SEALED INDEPENDENTLY
0x31 SYNC_SUMMARY
History heals itself
Went offline? When you reconnect, peers exchange summaries of what they hold and quietly send back whatever you missed — encrypted, deduplicated, no relay involved. The room's memory lives in the room, not in a datacenter.
OFFLINE RECOVERY
SUMMARY ▸ REQUEST ◂ MESSAGES ▸ · MERGE BY MSG-ID
DIAGRAM THE TOPOLOGY IS THE SECURITY
Delete the middleman, delete the threat
Every "secure" platform with a server in the middle still owns your metadata: who talked, when, how often, from where. Phantom's answer is structural — there is nothing in the middle to compromise.
THEM — CLIENT / SERVER
logs who · when · from where
single point of seizure
terms can change overnight
PHANTOM — PEER / PEER
direct encrypted socket
DHT discovery — no broker
nothing to seize, nothing to leak
NAMEPLATE — SPECIFICATIONS
0SERVERS
0ACCOUNTS
0TRACKERS
0THE CURVE
0BIT TOPICS
0MB / FILE
PWR READY WHEN YOU ARE
Power on
One portable binary. No installer phoning home, no signup wall. Open it, pick a name, you're on the wire.