Where messages are encrypted
New message bodies are encrypted in the browser before they are sent. The server stores and delivers encrypted data; decryption happens on the recipient’s device. Chat attachments are also encrypted before upload, and their keys are sent inside encrypted messages.
Messages use the Matrix protocol’s Olm/Megolm encryption. The client uses the official Matrix library matrix-sdk-crypto-wasm 18.9.0. HTTPS protects the connection between the browser and the server.
Why twelve words?
Recovery words follow BIP-39, the standard used by cryptocurrency wallets. The 12 English words help you recover your account and are also used to restore encrypted history. They are never uploaded, and the server cannot reproduce them for you.
Write them down in order and keep them offline. Do not photograph them and send them to others or enter them on unfamiliar websites. Anyone who knows these words can control your account. If you lose both your password and your recovery words, recovery is impossible.
Confirming who you are chatting with
The safety numbers in a chat help you confirm the other person's identity. Compare them through a channel you already trust, not only inside the chat you are trying to verify.
Message bodies are end-to-end encrypted, but you still need to protect your devices and recovery credentials. Someone who can operate a device that is no longer locked can read the content directly on its screen.
What encryption protects
New message bodies and the contents of chat attachments are protected by end-to-end encryption. Delivery information, avatars, group names, group announcements, friend request greetings and contact notes are handled as described in the privacy policy. Older plain-text messages sent before encryption was enabled are not automatically converted to encrypted data.
Using the web app requires you to trust the page you open and its code. Anyone who can modify the page’s code may read what you enter before it is encrypted. Use the official chat address and keep your browser and operating system up to date.
Reporting a security issue
Do not submit passwords, recovery words, sign-in tokens or other people’s private messages. Where possible, describe the issue using test accounts and examples that contain no private information.
Send a description of the issue to support@vantachat.org. Avoid publishing other people’s private data or exploitable details of issues that have not yet been fixed in public channels.