Public Beta — Available Now

Trust math. Not corporations.

Private messaging, secured by mathematics.

Keylane is an end-to-end encrypted messenger with no phone number and no account. Every chat and every group is protected against the quantum computers being built now — and when you lock the app, the key to everything stored on your phone is destroyed.

Free, with no ads and no account. All download options · Setup guide

No trackers on this site. No analytics. No cookies.

Keylane conversation list on a phone, showing chats identified by name with no phone numbers

The short version

Six things Keylane does, in plain words. Everything below this section is the same six claims with the evidence attached.

  • Nobody in between can read it

    Messages, files and calls are encrypted on your phone before they leave it, and only the person you are writing to can open them. There is no switch to turn this on, because it is never off.

  • No phone number. No email. No account.

    The first time you open the app it creates a key on your device, and that key is your identity. There is nothing to sign up for, nothing to verify, and nothing about you for us to keep.

  • Our servers know nothing worth taking

    They carry sealed envelopes they cannot open, and they do not record who sent them. If we were breached tomorrow, or ordered to hand over everything we hold, there is no message history and no map of who talks to whom to give.

  • Ready for quantum computers, today

    Encrypted traffic captured now can be stored until a machine exists that can break it. Every Keylane conversation, group chats included, uses encryption chosen to still hold when that day arrives.

  • A seized phone gives up nothing

    Lock Keylane and the key to your stored messages is destroyed inside the phone’s security hardware. Only your PIN brings it back — not a thief, not a forensics lab, not us. On by default, on every phone, with nothing to switch on.

  • An app you would actually choose

    Fast, modern, and designed with care. Privacy tools have a reputation for being unpleasant to use, and we never accepted that as the price of security.

What Keylane is

Keylane is a messenger for people who would rather not be a row in someone’s database. You install the app, it generates a key pair on your device, and that key pair is your account — there is nothing to sign up for and nothing to verify.

Messages are encrypted on your device before they leave it, using a hybrid handshake that combines classical elliptic-curve cryptography with post-quantum ML-KEM. The server that carries them is a relay: it holds sealed envelopes it cannot open, and it does not record who sent them.

We built it because we think a genuinely end-to-end secure messenger ought to exist by now — one that takes the device in your hand as seriously as it takes the server in the rack, treats privacy as architecture rather than policy, and still looks and behaves like an app you would choose to use rather than one you tolerate for the security. Most products get one or two of those. We are not willing to trade any of them away.

Keylane is built by Livotov Labs, a company registered in Bulgaria and operating under EU law. That jurisdiction covers the public relay we run, and it is a property of who operates a relay rather than of the app: once self-hosting ships, a relay you run answers to wherever you run it, not to us or to Bulgaria. Keylane is free to use, and it is not funded by advertising.

Identity
Key pair
Key exchange
PQXDH
Server retention
14 days max
Public relay jurisdiction
EU / Bulgaria
Price
Free

Principles

Nine commitments that shape every decision in the product. Each one is written so you can check whether we are keeping it.

  • End to end, with no way to turn it off

    Every message, attachment and call is encrypted on the sending device and decrypted on the receiving one. There is no plaintext mode, no opt-in secret chat to remember, and no server-side copy we could read if we were asked to.

  • No identity required

    Your account is a random cryptographic identity generated on your device — not a phone number, not an email address. We never ask, so we never know, and there is no identity for anyone to demand from us.

  • Zero-knowledge by architecture

    Servers hold encrypted envelopes, not conversations. The spooling database does not record who sent a message, so the social graph cannot be reconstructed from a database dump. Undelivered envelopes are purged on delivery, or after 14 days at the latest.

  • Post-quantum everywhere, not just the handshake

    Every conversation opens with a hybrid handshake — classical X25519 combined with post-quantum ML-KEM — and group messages are wrapped for each device the same way, so groups are covered rather than left classical. Identity keys are hybrid too: Ed25519 with ML-DSA. Traffic recorded today has to survive both an elliptic-curve break and a lattice break to stay secret.

  • Locked means locked

    When Keylane locks, the hardware key protecting your stored messages is destroyed in the Secure Enclave or Keystore, and only your PIN regenerates it. A phone seized in the state phones spend nearly all their time in — powered on, screen locked — yields ciphertext rather than conversations. This is the default on every platform, with nothing to enable and no passphrase to opt into.

  • Your infrastructure, your choice

    The protocol is federated by design: a private relay will exchange messages with the public network rather than forming an island, so no operator — including us — can lock you in. Running your own relay is in development and has not shipped; today everyone is on the public network.

  • You pay for infrastructure, never for privacy

    The app and the public network are free. Money comes from optional dedicated servers, on-premises deployments, and business features. Privacy is not a tier, and your data is not a product.

  • Verifiable, not asserted

    The protocol is documented in a public whitepaper, the cryptographic core is open source, and we publish a threat model that states plainly what Keylane does not protect against.

  • Secure and pleasant, not one or the other

    A tool people give up on protects nobody. Keylane is built to look and behave like a messenger you would pick on the merits, with the cryptography underneath the experience rather than in front of it.

Secure doesn’t have to mean sparse

A messenger you would actually want to use every day — with the encryption guarantees you can’t see, and the polish you can.

A Keylane conversation with a photo and a file attachment, both end-to-end encrypted
Conversations, photos and files
An outgoing Keylane call labelled end-to-end encrypted
Voice and video, encrypted
Keylane contact list, with names and no phone numbers anywhere
Contacts without phone numbers
The Keylane secure notebook, showing a vault of passwords, wallets and links
Secure notebook and vault

How a message actually travels

Encryption happens before anything leaves your device. The server only ever sees a sealed envelope.

  1. 1

    Sender’s device

    The message is encrypted locally with a key only the recipient can derive.

  2. 2

    Sealed envelope

    Ciphertext and a destination device ID — nothing else — cross the wire.

  3. 3

    Blind relay

    The server routes the envelope without holding the keys needed to open it.

  4. 4

    Recipient’s device

    Only the recipient’s device holds the key to decrypt it, locally.

Read the full cryptography whitepaper →

Don’t take our word for it

Security through obscurity doesn’t work. Here is everything we publish so you can check the claims on this page.

Cryptography whitepaper
Every primitive and protocol decision written up in detail — identity, key exchange, payload encryption, routing, attachments, and push.
Threat model
What Keylane defends against, and — just as importantly — what it does not. No security product protects against everything.
Kodium crypto core
The cryptographic core is public under the Apache License 2.0. The full client source is being prepared for release; we won’t claim it’s open until it is.
Transparency report
Government and law-enforcement requests received, and what we were able to produce in response. Updated on a fixed schedule.
Vulnerability disclosure
How to report a security issue, what is in scope, and the safe-harbour commitment we make to researchers who follow it.
Changelog
What shipped, when, and what changed about security behaviour in each release.

In development

Own your infrastructure

Keylane’s public network is free and open to everyone. For teams, law firms, and organizations that need their own relay, we are building managed hosting, an on-premises container image, and a plug-and-play appliance for small deployments.

Frequently asked questions

Does Keylane need my phone number?

No. Your account is a key pair generated on your device. Keylane never asks for a phone number, an email address, or any other real-world identifier — which also means there is nothing of that kind for us to lose, sell, or be compelled to hand over. See Keylane ID for how identity works.

What can the server actually see?

An encrypted envelope and a destination device ID. It does not see message content, and the spooling database does not record who sent a message. Undelivered envelopes are purged when the recipient acknowledges delivery, or after 14 days at the latest — whichever comes first. The full detail is in server security.

How is Keylane different from Signal or Matrix?

Signal is more mature than Keylane and far better audited, and for most people it is the right choice — we say so plainly on the comparison page rather than pretending otherwise. Where Keylane differs: identity is a key pair rather than a phone number, post-quantum protection covers every chat and every group instead of the opening handshake alone, and locking the app destroys the key to everything stored on the device. Matrix is federated but keeps substantial room state on the server, which a Keylane relay never holds. A detailed side-by-side, including the rows where we lose, is on the comparison page.

If Keylane is free, how does it make money?

Right now it does not. Keylane is paid for out of our own pocket — no investors, no advertising, no data sales — and messaging on the public network stays free for as long as we can afford it. Revenue will come from optional paid infrastructure: dedicated and managed servers, on-premises deployments, and business features. The one exception on the free network is voice and video calling, which costs us real money per minute to relay. We never charge for privacy or security. The full picture.

Is Keylane open source?

Partly, and we would rather be precise about it than round up. Kodium — the cryptographic core — is public under the Apache License 2.0 today. The full client application source is being prepared for release. Independently of the source, the protocol itself is fully documented in the whitepaper.

What happens if my phone is stolen or seized?

If Keylane was locked, the key protecting your stored messages no longer exists on the device — it is destroyed in the phone’s secure hardware the moment the app locks, and only your PIN brings it back. A forensic extraction taken at that point recovers encrypted records, plus some structure we leave in the clear around them: timestamps, ordering, and your contacts’ Keylane IDs. If the phone is taken while Keylane is open, assume everything on screen was read — no app can help with that. Choosing a longer PIN, or a passphrase, is the single setting that matters most here. How on-device storage works.

What happens if I lose my device?

Your Keylane ID lives on one device today, and if you lose it the ID cannot be recovered — there is no password reset, because there is no account for us to reset. That is a direct consequence of us not holding your keys. Multi-device linking and an offline recovery key are both on the roadmap; neither has shipped. How to prepare for this.

Can I run my own Keylane server?

Not yet — self-hosting is in active development. Because Keylane instances federate, a self-hosted relay will be able to exchange messages with the public network and with other private instances. Progress is tracked on the server setup page.