BlackBoxNG is an invitation-only workspace for the most consequential conversations inside regulated institutions — board deliberations, M&A, crisis response. It delivers the two things no incumbent offers together: confidentiality the operator cannot break and governance a regulator will accept.
STATUS — IN ACTIVE DEVELOPMENT · CORE CRYPTOGRAPHY PROVEN
Every existing option fails an institution in one of three ways — and firms have paid multi-billion-dollar fines discovering it.
WhatsApp and Signal encrypt well but offer no organisational identity, no membership control, no audit trail — and phone-number discovery leaks who is talking to whom. Using them puts regulated firms in breach.
Teams and Slack answer to compliance — because the vendor holds the keys. Content is readable by the provider, subpoenable through them, and one compromised admin exposes everything.
For EU institutions, Gulf sovereigns and defence-adjacent firms, the question isn’t only who reads the message — it’s whose cloud, in whose jurisdiction, the server sits in at all.
The product's unit is the decision room — a small, membership-controlled space where a specific group deliberates and shares documents. Not a chat app with channels; a sealed room with a roster.
Inside a room: end-to-end encrypted messaging, encrypted document sharing (files are encrypted on your device before upload; the server stores ciphertext it cannot read), a member list that names every device in the room, and a retention policy chosen at creation.
Around the rooms: invitation-only identity — no public signup, no phone numbers, members come only from your organisation's directory — and multi-device support where every laptop and phone is its own removable cryptographic identity.
The server coordinates but cannot read. It is structurally incapable of accessing content — no keys, no plaintext, an audit log with no content column by design.
The left column is what a compliance officer needs. The right column is what an adversary wants — and what the operator cannot produce, because it never exists server-side. Read the full threat model →
End-to-end encryption on MLS (RFC 9420), the IETF's group-messaging standard, via one Rust core — natively tested, compiled to every platform. The value is an auditable implementation, not a novel protocol that would fail review.
No public signup, no phone numbers. A user is their set of devices — each one individually visible, verifiable, and removable from every room it touches.
“Who was in the room, when, from which device” — answerable. “What did they say” — answerable by no one. Accountability and confidentiality, usually opposites, delivered together.
No key escrow means no compellable backdoor. A single static server binary and per-organisation data model make on-prem and air-gapped deployment a first-class path, not a retrofit.
Provable confidentiality with institutional governance — for organisations that can’t get both from anyone else. The moat is that the line has never been crossed.