End-to-end encrypted messenger for organisations · self-hosted

Anthill

Not even the server
can read your messages.

Locked on the sender’s device, opened only on the recipient’s.

Own engine in Rust · MLS (RFC 9420)

0messages the server can read
9420IETF standard: MLS RFC
245automated tests
3supported platforms
01 How it works

The keys live only on the devices.

The relay server’s code contains no decryption module. Not “we don’t look” โ€” “we can’t.”

SaaS Your talk piles up on someone else’s server
RISK Their breach becomes your breach
LOCK Someone else sets the price and the end date
Anthill
On your infrastructureKeys on the devicesThe data is yours
02 Features

If it is awkward, people go elsewhere.

Everything a work messenger needs, kept inside the ciphertext.

Direct · group · broadcast

Keys roll automatically when members change

Threads · mentions · pins

Even the structure stays encrypted

Encrypted attachments

Files are locked on the device before upload

Voice · video calls

Signalling is end-to-end encrypted too

Web · iOS · Android

One Rust engine drives all three

Multi-device

One QR scan registers a new device

Account takeover defence

Registration lock and a recovery key

Key transparency

A public log exposes any silent key swap

Verifiable reporting

Unreadable to the server, still provable

03 Security design

We do not ask you to trust us.

Standards, structure and verification instead.

RFC 9420

Standard cryptography

Built on openmls, a reviewed implementation of the IETF MLS standard. We write no cryptography of our own.

STRUCTURE

A structurally blind server

The relay is a separate codebase and ships without any decryption module.

RFC 6962

Key transparency

Every key change lands in a public log. Monitors compare signed checkpoints and catch any substitution.

AUDIT

Testing and audit

245 automated tests and repeated adversarial review. A third-party cryptographic audit runs before you go live.

04 Rollout

Built to fit your infrastructure.

01

Requirements

We scope it around your size and your authentication policy.

02

Deploy and verify

The server goes up; web and mobile clients are configured.

03

Handover

Backups and monitoring in place, then operations pass to you.

05 Contact
“Own your messenger. Don’t rent it.”

The server, the data and the keys are all yours. Tell us what worries you about the messenger you use today.

support@naholosoft.com