Security overview.
A single briefing surface for how Blink protects messages, devices, and Spaces — encryption on device, ciphertext-only servers, wipe and duress controls, plus the limits we publish honestly.
Core layers
How security is structured
The baseline architecture every security review starts with.
On-device encryption
Messages and media are sealed with AES-256-GCM before they leave the device. Keys are agreed with ECDH P-256 and derived with HKDF-SHA256 — our servers never receive plaintext.
Ciphertext-only infrastructure
ScyllaDB stores scrambled ciphertext. Client-encrypted media lands in object storage already sealed. There is no server-side key that can open your content.
Forward secrecy
dm_v3 and group_v3 rotate to a fresh key epoch every seven days, so a compromised key does not reopen an unbounded message history.
Device and session control
Enrolled devices can be listed and remotely wiped. Sessions are revocable when a phone is lost, stolen, or retired from the fleet.
Controls
Defenses beyond the message body
Device, capture, and coercion controls that close gaps most messengers leave open.
Anti-keylogger keyboard
Blink’s keyboard takes over while you type so the system keyboard never watches passphrases, PINs, or message text.
Screen & capture protection
Screenshot and screen-recording blocks, plus app-switcher and proximity guards for sensitive moments.
Reverse-PIN duress wipe
A second PIN quietly erases everything under coercion while appearing to unlock normally.
Secure Locker
Files — including filenames — stay sealed in an encrypted vault so sensitive documents are not readable on our side.
Space lock & RBAC
High-risk Spaces get an extra seal. Superadmin, admin, owner, and member roles limit who can invite, lock, and wipe.
Disappearing messages
Time-boxed chats leave nothing readable once the timer ends — paired with ciphertext-only storage.
At a glance
Facts for a security brief
- Message seal
- AES-256-GCM on device
- Key agreement / derivation
- ECDH P-256 · HKDF-SHA256
- Server storage
- Ciphertext only (ScyllaDB + encrypted media)
- Regions today
- United States and India
- Calls today
- Secure media-server mediated (full E2EE on roadmap)
- Residency roadmap
- Switzerland + GDPR options planned and badged
Verification
How to keep verifying
Status page
Component health for messaging, media, identity, push/wipe, and calls — so you can verify service posture in real time.
Change log
Versioned engineering notes for security-relevant releases, not just marketing highlights.
Security briefing
Walk encryption, wipe, duress, and Spaces with your team using the live product.
Need this walked live?
Bring security and leadership to a briefing — or dig into cryptography and public status when you need the deeper stack.