Uncompromising zero-knowledge messaging. Engineered with hardware-ratcheted Curve25519 cryptography, zero cloud plaintext, anonymous 10-digit Liquid IDs, and direct WebRTC peer-to-peer audio & video calling.
KEY AGREEMENT
Curve25519 (X25519)
AUTHENTICATED CIPHER
AES-256-GCM + Poly1305
MEDIA CHANNELS
WebRTC DTLS-SRTP P2P
CLOUD FOOTPRINT
0 Plaintext Bytes
Test real-time Double-Ratchet key handshakes and payload encryption directly in your browser. Tap any command chip or enter custom commands.
A comprehensive breakdown of the low-level mathematical primitives guarding every byte of communication.
Montgomery curve over the prime 2^255 - 19. Provides 128-bit security level against brute force. Designed to be completely immune to side-channel timing attacks by avoiding data-dependent branches.
Combines a symmetric-key ratchet driven by HKDF-SHA256 and a Diffie-Hellman ratchet based on Curve25519. Provides Forward Secrecy and Break-in Recovery on every exchanged message.
Galois/Counter Mode with 256-bit encryption keys. Every packet incorporates a unique 96-bit CSPRNG initialization vector (IV) and generates a 128-bit Poly1305 authentication tag.
Cryptographic pseudo-random key derivation function based on HMAC-SHA256. Securely derives multiple cryptographically strong sub-keys from ephemeral shared secrets.
Direct audio and video calls connect browser-to-app and phone-to-phone with zero intermediate recording servers. STUN/TURN hole punching acts solely as an encrypted transit pipe.
Local database on Android and web clients is encrypted at rest with AES-256 and 100,000 PBKDF2 HMAC-SHA256 iterations. Enforces hardware-backed PIN and biometric app lockdown.
Engineered from silicon up to withstand physical inspection, network wiretapping, and relay node seizures.
Never surrender your phone number, email, or Google identity. Liquid Chat assigns an untraceable 10-digit ID generated from your local cryptographic keypair in device RAM.
Every message advances both a Diffie-Hellman and symmetric key ratchet. Compromising a single key mathematically reveals zero past or future communications.
Encrypted voice and HD video streams travel directly peer-to-peer using DTLS-SRTP. Zero audio or video frames ever touch or record on relay servers.
Granular burn countdowns from 5 seconds to 24 hours. Messages zeroize from memory buffers and local physical disk blocks with zero forensic trace.
Lock individual sensitive chats or the entire application behind a hardware PIN. Protects your conversations against physical device inspection or seizure.
Link your Android APK with your desktop browser instantly using encrypted QR handshake. Sessions persist securely and can be revoked remotely at any moment.
Group channels are protected with epoch-based cryptographic key rotation. Member rosters and message envelopes remain completely opaque to relay operators.
All conversation history is sealed strictly on device storage in an encrypted keystore. If our servers are confiscated, attackers acquire zero usable intelligence.
How Liquid Chat systematically outperforms legacy centralized messengers across critical privacy vectors.
| SECURITY CAPABILITY | LIQUID CHAT PRO | SIGNAL | TELEGRAM | SESSION | |
|---|---|---|---|---|---|
| Default E2EE Across All Chats | YES (Curve25519) | YES | NO (Cloud Chats) | YES | YES |
| No Phone Number / SIM Required | YES (10-Digit ID) | NO (SIM Required) | NO (SIM Required) | NO (SIM Required) | YES |
| Direct WebRTC P2P Audio & Video | YES (Zero Media Relay) | Server Mediated | Server Mediated | Server Mediated | Limited P2P |
| Local Encrypted Keystore (PIN Vault) | YES (SQLCipher + PIN) | OS Sandbox | NO (Plain Cloud) | Google Drive/iCloud | OS Sandbox |
| Standalone APK (No Google Play) | YES (100% De-Googled) | Website APK only | Website APK only | NO (Google Play) | YES (F-Droid) |
| Post-Compromise Break-in Recovery | YES (Double Ratchet) | YES | NO | YES | Partial |
| Zero Cloud Plaintext Storage | YES (0 Bytes Retained) | YES | NO (Everything in Cloud) | Backups in Clear | YES |
| Post-Quantum Roadmap (Kyber-1024) | YES (Phase 05 Active) | YES (PQXDH) | NO | Not Announced | In Research |
Download the standalone universal APK directly onto your Android device. Engineered with zero Google Play Services dependency, universal ARM64/x86_64 architecture support, and zero third-party telemetry libraries.
Get-FileHash .\LiquidChat.apk -Algorithm SHA256sha256sum LiquidChat.apkshasum -a 256 LiquidChat.apksha256sum /sdcard/Download/LiquidChat.apkOpen My Files > Downloads > tap LiquidChat.apk. If prompted, toggle "Allow from this source" under Settings.
Open Files by Google > tap APK. In the "Install Unknown Apps" pop-up, enable Chrome / Files permission.
Launch File Manager > select LiquidChat.apk. Accept security warning (zero trackers) and tap "Install anyway".
Tap the download notification. Choose "Install Unknown Sources" in System Security settings to proceed.
Used solely for WebRTC video calling and scanning device pairing QR codes.
Used solely for WebRTC audio calls with local noise suppression.
Incoming call heads-up alerts waking the app with looping ringtones.
ZERO ACCESS REQUESTED FOR: Contacts, SMS, GPS Location, Phone State (IMEI), or External Storage Browsing.
A chronological progression of our sovereign architectural releases.
Implementation of pure Curve25519 ECDH key generation paired with AES-256-GCM symmetric streams and Poly1305 MAC tag verification.
STUN/TURN direct hole punching without relay media recording. Zero voice or video frames recorded on intermediate network hops.
Hardware-level PIN lockout protecting sensitive chats. Client storage migrated entirely to locally encrypted SQLite database.
Full universal distribution with zero Google Play dependencies, pairing QR codes, and in-browser standalone WebClient.
Hybrid quantum-resistant algorithms safeguarding against harvest-now-decrypt-later attacks by state-sponsored surveillance actors.
Direct, uncompromising answers to all architectural, cryptographic, and operational security questions.
When you send a message, your local browser or Android device generates an ephemeral Curve25519 (X25519) key agreement and derives an isolated 256-bit symmetric key via HKDF-SHA256. The plaintext is encrypted locally on your silicon using AES-256-GCM with a 128-bit Poly1305 authentication tag. The relay servers only receive an opaque, high-entropy ciphertext blob. Because our servers possess zero private keys and store zero decryption material, decrypting messages on the server is mathematically impossible.