Security overview.

A single briefing surface for how Blink protects messages, devices, and Spaces — encryption on device, ciphertext-only servers, wipe and duress controls, plus the limits we publish honestly.

Core layers

How security is structured

The baseline architecture every security review starts with.

On-device encryption

Messages and media are sealed with AES-256-GCM before they leave the device. Keys are agreed with ECDH P-256 and derived with HKDF-SHA256 — our servers never receive plaintext.

Ciphertext-only infrastructure

ScyllaDB stores scrambled ciphertext. Client-encrypted media lands in object storage already sealed. There is no server-side key that can open your content.

Forward secrecy

dm_v3 and group_v3 rotate to a fresh key epoch every seven days, so a compromised key does not reopen an unbounded message history.

Device and session control

Enrolled devices can be listed and remotely wiped. Sessions are revocable when a phone is lost, stolen, or retired from the fleet.

Controls

Defenses beyond the message body

Device, capture, and coercion controls that close gaps most messengers leave open.

Anti-keylogger keyboard

Blink’s keyboard takes over while you type so the system keyboard never watches passphrases, PINs, or message text.

Screen & capture protection

Screenshot and screen-recording blocks, plus app-switcher and proximity guards for sensitive moments.

Reverse-PIN duress wipe

A second PIN quietly erases everything under coercion while appearing to unlock normally.

Secure Locker

Files — including filenames — stay sealed in an encrypted vault so sensitive documents are not readable on our side.

Space lock & RBAC

High-risk Spaces get an extra seal. Superadmin, admin, owner, and member roles limit who can invite, lock, and wipe.

Disappearing messages

Time-boxed chats leave nothing readable once the timer ends — paired with ciphertext-only storage.

At a glance

Facts for a security brief

Message seal
AES-256-GCM on device
Key agreement / derivation
ECDH P-256 · HKDF-SHA256
Server storage
Ciphertext only (ScyllaDB + encrypted media)
Regions today
United States and India
Calls today
Secure media-server mediated (full E2EE on roadmap)
Residency roadmap
Switzerland + GDPR options planned and badged

Verification

How to keep verifying

Status page

Component health for messaging, media, identity, push/wipe, and calls — so you can verify service posture in real time.

Change log

Versioned engineering notes for security-relevant releases, not just marketing highlights.

Security briefing

Walk encryption, wipe, duress, and Spaces with your team using the live product.

Need this walked live?

Bring security and leadership to a briefing — or dig into cryptography and public status when you need the deeper stack.