// secure transport layer

Privacy is not a policy. It is mathematics.

A zero-trust messaging protocol where the server is mathematically incapable of accessing message content. Strategically hosted in Hong Kong to ensure data sovereignty.

Alice Encrypted

Alice: Are you still okay to look over the contract tonight?

You: Yes, send it over whenever you’re ready.

Alice: Here it is. Page four is the part I’m unsure about.

You: Reading it now. I’ll call you after nine.

01 / architecture

The server is a blind relay.

Traditional “secure” messengers act as trusted intermediaries. rChat removes trust from the equation entirely. The server sees nothing but opaque, encrypted bytes.

ciphertext = XChaCha20Poly1305(key=k_ratchet, msg=plaintext)
01 / key generation

Strictly on-device.

Private keys are generated on user hardware and never transmitted. The server possesses no cryptographic capability to decrypt payloads.

02 / metadata

Zero retention.

rChat utilizes opaque circuit identifiers to route packets. We do not maintain social graphs, timestamps, or sender-receiver logs.

03 / transport

TLS 1.3 tunneling.

All protocol traffic is encapsulated within standard HTTPS (TLS 1.3) frames, rendering it indistinguishable from standard web browsing.

02 / jurisdiction

Strategic independence. Hong Kong hosting.

Cryptography is only as strong as the legal jurisdiction holding the hardware. rChat infrastructure is legally domiciled and physically hosted in Hong Kong, placing it strictly outside the jurisdiction of Western intelligence sharing agreements.

Data sovereignty assurance We are not subject to National Security Letters from 5-Eyes nations.
03 / comparison

Verify the difference.

Feature rChat Signal Telegram
Server blind relay Yes No No
Jurisdiction Hong Kong USA (5 Eyes) UAE
Self-hostable Yes Difficult No
04 / ownership

Don’t trust us. Run your own node.

True security requires the ability to verify the infrastructure. rChat is 100% open source. You can audit the code, build the relay and run it on your own host.

The relay obtains and renews its own TLS certificate over TLS-ALPN-01 on port 443. No port 80, no reverse proxy.

View GitHub repository →
cargo build --release --bin rchat-server
# point an A/AAAA record for relay.example.com at this host
sudo install -m 0755 target/release/rchat-server /usr/local/bin/
# /etc/rchat/server.toml
[server]
bind_addr = "0.0.0.0:443"
[server.acme]
enabled  = true
domains  = ["relay.example.com"]
contacts = ["mailto:[email protected]"]
cache_dir = "/var/lib/rchat/acme"
sudo systemctl enable --now rchat-server
technical whitepaper · v1.0 · feb 2026

End-to-end encrypted messaging protocol

Read the whitepaper

Abstract

rChat is a secure messaging platform designed from the ground up for true end-to-end encryption (E2EE). Unlike existing solutions where service providers control key distribution, rChat employs a zero-trust architecture where the server is mathematically incapable of accessing message content.

  • Server-blind relay
  • Client-side key gen
  • Double Ratchet sessions
  • Verifiable security

Get rChat.