Trust Boundary offers a communication stack that keeps messages, call signals, profiles, and media opaque to infrastructure, ensuring that servers never see plaintext content or private recovery keys. By using a storage‑agnostic “.xbk” continuity format and a dedicated relay path, the platform provides user‑owned recovery and strong operational isolation while still exposing only minimal network metadata. It is designed for developers who need secure, privacy‑first messaging and real‑time transport without relying on hosted contact graphs.
Funding
Funding not disclosed
Founders
Product
Problem
Organizations that require secure communications often rely on conventional messaging platforms where the service provider can access plaintext content, user profiles, media, and recovery credentials. This exposure creates a risk that infrastructure operators or compromised relays can read or tamper with sensitive data, while residual network metadata remains observable.
Solution
Trust Boundary offers the Xentrop platform, an encrypted communication service that isolates messages, call signals, profiles, media, and continuity data behind an opaque relay layer. All user data is encrypted end‑to‑end on the client device, and the relay never stores plaintext content, private keys, or a hosted contact graph. Continuity is maintained through a storage‑agnostic “.xbk” backup that users control, enabling account recovery without granting the server decryption authority. The architecture limits the information visible to the relay to encrypted blobs and minimal operational metadata such as connection timing and traffic volume. By design, the system provides a dedicated relay path that reduces exposure to infrastructure‑based threats while clearly stating the remaining metadata that may be observed.
Target Audience
Primary customers are enterprises, government agencies, and high‑risk organizations that need private communication channels where the service infrastructure is considered part of the threat model.
Features
- End‑to‑end encryption of messages, media, call signals, and profile data with no plaintext stored on relay servers
- User‑owned “.xbk” continuity files that are storage‑agnostic and enable self‑managed account recovery
- Opaque relay layer that does not maintain a readable contact graph or host recovery capsules
- Explicit handling of residual metadata (IP timing, blob size, traffic volume, push timing) with transparent documentation
- Capability‑bound access controls for profiles and media, ensuring only authorized participants can retrieve content
- Dedicated relay path architecture that isolates coordination events from infrastructure operators
- Support for secure contact establishment via QR codes, invite links, manual key exchange, or .xbk restore