Secure and independent communications

RAZ

Secure communication—beyond message encryption

Introduction

RAZ: secure communication in a broader sense

Many communication tools reduce security to encrypting message text. MSENSE takes a broader view: communication is more secure when control over the conversation, identity, membership, and related data remains with the participants as far as possible.

RAZ is a private MSENSE messenger for individuals, circles, and teams that do not want communication built on phone numbers, public accounts, or searchable networks. Invitation-based entry, end-to-end content encryption, and identity-data minimization are central to this approach.

RAZ is not designed to replace everyday entertainment platforms. Its purpose is to reduce dependence on systems that govern communication on behalf of users and to return meaningful control to the participants.

01Invitation-only entry without phone number or email
02Closed, controlled community
03End-to-end encryption for messages and files
04Minimized identity data and metadata
Secure communicationInvitation-basedPrivacy control

RAZ communication scenarios

One principle for groups with different needs

These scenarios describe intended design and deployment. Final security and continuity depend on version, infrastructure, and operating policy.

01

Families

Personal privacy and trust-based circles

An invitation-based family space where membership and entry remain under the control of the family or a trusted operator.

  • Reduced unsolicited entry and contact
  • Children’s circles limited to trusted people
  • Deployment on infrastructure selected by the family or operator
02

Friends and private communities

Genuine closeness without public exposure

Closed, invitation-based spaces for conversation and file sharing instead of searchable public networks.

  • Invitation rather than public discovery
  • No phone number or public account required
  • Internal or dedicated hosting options
03

Education and research

An academic space governed by the institution

Schools, universities, and research groups can create controlled classes and scientific circles while keeping drafts and data in their own environment.

  • Controlled classroom and research groups
  • Encrypted message and file exchange
  • Internal continuity when local networking is configured
04

Businesses and financial institutions

Operational confidentiality and infrastructure independence

Professional teams can separate internal channels from public networks and operate the server in infrastructure they select.

  • Closed, invitation-based channels
  • End-to-end encrypted content transfer
  • On-premises or dedicated data-center deployment
05

Organizations and institutions

Governance over channels, membership, and servers

Institutions that require greater control can keep membership, infrastructure, and access policies within their own administrative boundary.

  • Controlled membership and access
  • End-to-end encrypted content
  • Internal-network operation where supported by deployment architecture
THE RAZ PROMISEControl remains with the communicating group.

RAZ: reclaiming control of communication.

Current product status

What is implemented in RAZ today

This describes capabilities present in the code, not future promises. Public readiness still requires release testing, security review, and operational approval.

01
Identity and entryPrivate membership without phone numbers or email
  • Time-limited, single-use invitations
  • RAZ ID without a public directory
  • On-device key generation and mobile recovery
  • English, Persian, and Arabic interfaces
02
Encryption and trustMessage content is not readable by the server
  • End-to-end encryption based on X3DH and Double Ratchet
  • In-person contact verification through safety numbers
  • Encrypted envelopes with store-and-forward delivery
  • Sender-key group encryption and optional sender privacy
03
Messaging and groupsCore communication across web and mobile
  • One-to-one and group conversations with realtime delivery
  • Encrypted voice notes, text editing, and forwarding
  • Replies, reactions, disappearing messages, and urgent alerts—primarily on mobile
  • Session-health indicators when a safety number changes
04
Files and mediaFiles are encrypted before leaving the device
  • Only ciphertext is uploaded
  • Removal after successful download or expiry
  • Chunk-integrity validation and relay support
  • Mobile gallery, camera, file, compression, and preview support
05
Calls and notificationsAudio and video calling on mobile
  • Mobile WebRTC with encrypted signaling
  • Push and incoming-call notifications
  • Sound, vibration, ringtone, and mute controls
  • Web calling is not yet a complete product feature
06
Local privacy and resilienceProtection for data stored on the device
  • Strengthened local lock and protected view for sensitive content
  • Encrypted local mobile backup
  • Local key and store destruction on sign-out
  • High-level network resilience capabilities
07
Administration and deploymentOperator-controlled server and communication policies
  • Invitation, account, contact, and system-notice management
  • Multi-admin approval for sensitive operations and audit logging
  • Docker Compose deployment on operator infrastructure
  • Operational profiles, encrypted backups, and release gates
08
Operations and qualityMonitoring, testing, and operational readiness
  • Health and readiness checks
  • Metrics, dashboards, and redacted structured logs
  • Dependency and build-chain security scanning
  • Load testing, threat model, recovery exercises, and trilingual guidance

Platforms

Coverage in current versions

Core capabilities available

Web (React)

Activation, chat, files, groups, settings, phone companion, and administration

Most complete current client

Android (Flutter)

Core features plus calling, media, push, local backup, and network resilience

Not complete

iOS

A complete product version is not yet available

Not complete

Independent multi-device

Companion is the current web-to-phone path; the final independent model is unfinished

Threat-model transparency

Encrypting content does not make all metadata invisible.

Under the current architecture, the server does not see message plaintext, private keys, the local lock pattern, SAS verification state, or sensitive-content labels. It may still observe account existence, message timing and size, and—in the classic route—the sender-to-recipient relationship. These claims require independent review before external assurance.

Current product boundary

Designed, but not yet complete or default

Mandatory sender privacy for everyoneLive post-quantum transportComplete web callingMLS groupsIndependent multi-device modelLocal AI assistantFull physical high availabilityComplete search, typing, and last-seen features

Core capabilities

What this product is designed to do

This list reflects currently defined capabilities and does not by itself claim final readiness.

01

Invitation-based entry without phone or email

02

End-to-end encrypted messaging and files

03

Membership and communication-space controls

04

Identity and auxiliary-data minimization

Workflow

From input to a reviewable result

The product process is divided into understandable, controllable stages.

01

Receive an invitation

02

Create a local identity

03

Communicate through encrypted sessions

04

Manage membership and privacy

Audiences

Families and groups of friends

Communities, institutions, and professional teams

Deployment

Dedicated environment with mobile and web access

Commitment boundary

Performance details, requirements, and availability are confirmed after version stabilization and operational testing.