PRODUCTION RELEASE • v2.0.1 PRO • STANDALONE ANDROID APK & WEB

SOVEREIGN
COMMUNICATION

Uncompromising zero-knowledge messaging. Engineered with hardware-ratcheted Curve25519 cryptography, zero cloud plaintext, anonymous 10-digit Liquid IDs, and direct WebRTC peer-to-peer audio & video calling.

KEY AGREEMENT

Curve25519 (X25519)

AUTHENTICATED CIPHER

AES-256-GCM + Poly1305

MEDIA CHANNELS

WebRTC DTLS-SRTP P2P

CLOUD FOOTPRINT

0 Plaintext Bytes

CLIENT-SIDE HARDWARE EMULATOR

LIVE CRYPTOGRAPHIC CONSOLE

Test real-time Double-Ratchet key handshakes and payload encryption directly in your browser. Tap any command chip or enter custom commands.

liquid-sovereign-shell ~ zsh
ECDH: READY
Quick:
[SYS_INIT] Liquid Sovereign Core v2.0.1 initialized.
[ECDH_X25519] Ephemeral keypair generated on silicon co-processor.
[AES_GCM_256] Symmetric key stream synchronized with peer node.
[POLY1305] 128-bit authentication tag validated. Zero telemetry.
[STATUS] Sovereign ratcheted channel active and verified.
liquid@client:~$
MATHEMATICAL BLUEPRINT

CRYPTOGRAPHIC ARCHITECTURE

A comprehensive breakdown of the low-level mathematical primitives guarding every byte of communication.

X25519 (ECDH)RFC 7748

Elliptic Curve Key Agreement

Montgomery curve over the prime 2^255 - 19. Provides 128-bit security level against brute force. Designed to be completely immune to side-channel timing attacks by avoiding data-dependent branches.

Constant-time multiplication
Zero timing leaks
256-bit ephemeral keys
Double RatchetSignal Protocol Derivation

Continuous Key Ratchet

Combines a symmetric-key ratchet driven by HKDF-SHA256 and a Diffie-Hellman ratchet based on Curve25519. Provides Forward Secrecy and Break-in Recovery on every exchanged message.

Per-message key deletion
Post-compromise healing
Out-of-order message handling
AES-256-GCMNIST SP 800-38D

Authenticated Symmetric Cipher

Galois/Counter Mode with 256-bit encryption keys. Every packet incorporates a unique 96-bit CSPRNG initialization vector (IV) and generates a 128-bit Poly1305 authentication tag.

Confidentiality & integrity
Hardware AES-NI acceleration
Nonce collision protection
HKDF-SHA256RFC 5869

Extract-and-Expand KDF

Cryptographic pseudo-random key derivation function based on HMAC-SHA256. Securely derives multiple cryptographically strong sub-keys from ephemeral shared secrets.

Zero seed reuse
Entropy amplification
Chain key isolation
WebRTC DTLS 1.2 / SRTPRFC 5764 & RFC 3711

P2P Media Channel Encryption

Direct audio and video calls connect browser-to-app and phone-to-phone with zero intermediate recording servers. STUN/TURN hole punching acts solely as an encrypted transit pipe.

Direct peer-to-peer audio/video
Zero media server logs
Mirrored hardware pipeline
SQLCipher (PBKDF2)RFC 2898

Hardware Keystore Encryption

Local database on Android and web clients is encrypted at rest with AES-256 and 100,000 PBKDF2 HMAC-SHA256 iterations. Enforces hardware-backed PIN and biometric app lockdown.

Zero plaintext on disk
100k PBKDF2 rounds
Dual-layer PIN lock
SOVEREIGN CAPABILITIES

EIGHT PILLARS OF PRIVACY

Engineered from silicon up to withstand physical inspection, network wiretapping, and relay node seizures.

IDENTITY

10-Digit Anonymous ID

Never surrender your phone number, email, or Google identity. Liquid Chat assigns an untraceable 10-digit ID generated from your local cryptographic keypair in device RAM.

RATCHET

Double-Ratchet Protocol

Every message advances both a Diffie-Hellman and symmetric key ratchet. Compromising a single key mathematically reveals zero past or future communications.

CALLS

Direct WebRTC P2P Calls

Encrypted voice and HD video streams travel directly peer-to-peer using DTLS-SRTP. Zero audio or video frames ever touch or record on relay servers.

EPHEMERAL

Self-Destruct Streams

Granular burn countdowns from 5 seconds to 24 hours. Messages zeroize from memory buffers and local physical disk blocks with zero forensic trace.

SECURITY

Dual-Layer PIN Vault

Lock individual sensitive chats or the entire application behind a hardware PIN. Protects your conversations against physical device inspection or seizure.

LINKED

E2EE QR Multi-Device

Link your Android APK with your desktop browser instantly using encrypted QR handshake. Sessions persist securely and can be revoked remotely at any moment.

ROOMS

Zero-Metadata Groups

Group channels are protected with epoch-based cryptographic key rotation. Member rosters and message envelopes remain completely opaque to relay operators.

ANTI-LOG

Zero Cloud Plaintext

All conversation history is sealed strictly on device storage in an encrypted keystore. If our servers are confiscated, attackers acquire zero usable intelligence.

TRANSPARENT SECURITY AUDIT

COMPREHENSIVE PROTOCOL COMPARISON

How Liquid Chat systematically outperforms legacy centralized messengers across critical privacy vectors.

👉 Swipe table horizontally to inspect all vectors
SECURITY CAPABILITYLIQUID CHAT PROSIGNALTELEGRAMWHATSAPPSESSION
Default E2EE Across All ChatsYES (Curve25519)YESNO (Cloud Chats)YESYES
No Phone Number / SIM RequiredYES (10-Digit ID)NO (SIM Required)NO (SIM Required)NO (SIM Required)YES
Direct WebRTC P2P Audio & VideoYES (Zero Media Relay)Server MediatedServer MediatedServer MediatedLimited P2P
Local Encrypted Keystore (PIN Vault)YES (SQLCipher + PIN)OS SandboxNO (Plain Cloud)Google Drive/iCloudOS Sandbox
Standalone APK (No Google Play)YES (100% De-Googled)Website APK onlyWebsite APK onlyNO (Google Play)YES (F-Droid)
Post-Compromise Break-in RecoveryYES (Double Ratchet)YESNOYESPartial
Zero Cloud Plaintext StorageYES (0 Bytes Retained)YESNO (Everything in Cloud)Backups in ClearYES
Post-Quantum Roadmap (Kyber-1024)YES (Phase 05 Active)YES (PQXDH)NONot AnnouncedIn Research
OFFICIAL PRODUCTION RELEASE

ANDROID DEPLOYMENT & SIDELOADING

SIZE: 7.4 MB • ANDROID 8.0+

Download the standalone universal APK directly onto your Android device. Engineered with zero Google Play Services dependency, universal ARM64/x86_64 architecture support, and zero third-party telemetry libraries.

OFFICIAL SHA-256 BINARY CHECKSUM783ed32b54a61b8ee58a4691ecfc612a6899d353daa503b1b590165d80737c6e
1-Click Verification Commands:
Windows (PowerShell)Get-FileHash .\LiquidChat.apk -Algorithm SHA256
Linux (Bash)sha256sum LiquidChat.apk
macOS (Terminal)shasum -a 256 LiquidChat.apk
Android (Termux)sha256sum /sdcard/Download/LiquidChat.apk
OEM INSTALLATION GUIDELINES
SAMSUNG GALAXY
One UI 5 / 6

Open My Files > Downloads > tap LiquidChat.apk. If prompted, toggle "Allow from this source" under Settings.

GOOGLE PIXEL
Stock Android 13-15

Open Files by Google > tap APK. In the "Install Unknown Apps" pop-up, enable Chrome / Files permission.

XIAOMI / REDMI
MIUI / HyperOS

Launch File Manager > select LiquidChat.apk. Accept security warning (zero trackers) and tap "Install anyway".

ONEPLUS / OPPO
OxygenOS / ColorOS

Tap the download notification. Choose "Install Unknown Sources" in System Security settings to proceed.

PERMISSIONS TRANSPARENCY AUDITAUDITED CLEAN
CAMERA

Used solely for WebRTC video calling and scanning device pairing QR codes.

MICROPHONE

Used solely for WebRTC audio calls with local noise suppression.

NOTIFICATIONS

Incoming call heads-up alerts waking the app with looping ringtones.

ZERO ACCESS REQUESTED FOR: Contacts, SMS, GPS Location, Phone State (IMEI), or External Storage Browsing.

ROADMAP & EVOLUTION

THE CRYPTOGRAPHIC ROADMAP

A chronological progression of our sovereign architectural releases.

PHASE 01 • COMPLETEDQ1 2025

Ephemeral Double-Ratchet Handshake

Implementation of pure Curve25519 ECDH key generation paired with AES-256-GCM symmetric streams and Poly1305 MAC tag verification.

PHASE 02 • COMPLETEDQ2 2025

Direct Peer-to-Peer WebRTC Audio/Video

STUN/TURN direct hole punching without relay media recording. Zero voice or video frames recorded on intermediate network hops.

PHASE 03 • COMPLETEDQ3 2025

Local SQLite Keystore & PIN Lockdown

Hardware-level PIN lockout protecting sensitive chats. Client storage migrated entirely to locally encrypted SQLite database.

PHASE 04 • CURRENT PRODUCTIONQ1 2026

Universal Android APK (v2.0.1) & PWA Web Client

Full universal distribution with zero Google Play dependencies, pairing QR codes, and in-browser standalone WebClient.

PHASE 05 • IN DEVELOPMENTQ4 2026

Post-Quantum Kyber1024 Key Encapsulation

Hybrid quantum-resistant algorithms safeguarding against harvest-now-decrypt-later attacks by state-sponsored surveillance actors.

KNOWLEDGE BASE

SECURITY & PRIVACY FAQ

Direct, uncompromising answers to all architectural, cryptographic, and operational security questions.

How does Liquid Chat guarantee zero plaintext is ever stored on servers?

When you send a message, your local browser or Android device generates an ephemeral Curve25519 (X25519) key agreement and derives an isolated 256-bit symmetric key via HKDF-SHA256. The plaintext is encrypted locally on your silicon using AES-256-GCM with a 128-bit Poly1305 authentication tag. The relay servers only receive an opaque, high-entropy ciphertext blob. Because our servers possess zero private keys and store zero decryption material, decrypting messages on the server is mathematically impossible.

Why does Liquid Chat not require a phone number or SMS verification?
Can I use Liquid Chat simultaneously on Android and Desktop Web browsers?
How are WebRTC audio and video calls protected against surveillance?
What is the Double-Ratchet Protocol and how does it protect past and future messages?
What happens if a Liquid Chat relay server is seized or subpoenaed?
How does the Dual-Layer PIN Vault protect data stored on physical devices?
How can I verify that the downloaded Android APK has not been tampered with?
Does Liquid Chat require Google Play Services or Google Mobile Services (GMS)?
How does ephemeral message destruction work?
How are files, videos, and media encrypted before transmission?
What is Liquid Chat's roadmap for Post-Quantum Cryptography (Kyber-1024)?