In development. RVNT is pre-release — not yet security-audited. Source code, public builds, and the iOS / App Store release aren’t available yet. See the roadmap →

Blog

Technical writing about cryptography, privacy, and the surveillance state we are building tools to resist.

centralizationsovereigntyinfrastructure
Read article →

Sealed Sender: Hiding Who Talks to Whom

A technical deep-dive on RVNT's sealed sender: how encrypting the sender certificate to the recipient hides the from-to routing pair, and how forgery, replay, and abuse are handled.

sealed-sendermetadatadeep-diveanonymitythreat-model
Read

Meta Won in Court. NSO Allegedly Kept Hacking Anyway.

In June 2026 Meta asked a US court to hold NSO Group in contempt for defying the injunction that bars it from targeting WhatsApp. The case is a stress test of whether courts can stop mercenary spyware — and a reminder that the endpoint, not the encryption, is the battleground.

nso-groupspywarepegasuswhatsappendpoint-securityaccountability
Read

Metadata Is the Message

"It's just metadata" is a dangerous phrase. Who you talk to, when, and how often can reveal more than what you said — and RVNT is built to minimize it.

metadatasealed-sendertormixnettraffic-analysis
Read

Can Your Employer Read Your Messages? Workplace Surveillance Explained

Can my employer read my messages? Yes for work email, Slack and Teams DMs, and company devices. Here's what they legally can and can't see in 2026 — and how to separate personal from work.

workplace surveillanceemployee monitoringbosswareECPAencryptionprivacy
Read

Nobody Broke the Encryption: Inside the 2026 Vishing Breach Wave

Charter, Carnival, DentaQuest — millions of records gone this spring, and not one attacker touched the cryptography. They phoned an employee. Why the centralized account, not the cipher, is the real attack surface.

data-breachsocial-engineeringcentralizationshinyhuntersvishing
Read

RVNT vs Signal: An Honest Comparison

Signal is the gold standard for encrypted messaging. Here is where RVNT agrees, where it diverges, and the honest tradeoffs of each — no strawmen.

signalcomparisonthreat-modelpost-quantummetadata
Read

How to Contact a Journalist Securely: A Source's Guide

How to contact a journalist securely: SecureDrop, Signal usernames, the metadata problem, OPSEC, and the honest limits no encryption tool can fix.

securedropsignalwhistleblowingmetadataopsecsource-protection
Read

The Phishers Stopped Attacking Signal's Crypto and Started Attacking Its Users

In May 2026 Signal shipped anti-impersonation warnings, and a phishing campaign began tricking journalists into pasting their 64-character recovery key into chat. When the cipher is unbreakable, the attack moves to recovery and device-linking. What that means for anyone who designs a PIN.

signalphishingsocial-engineeringrecovery-keyaccount-security
Read

How to Remove Your Information From Data Brokers

A practical 2026 guide to remove your information from data brokers: the free DIY opt-out process, California's DROP, paid services, and why removal is ongoing.

data brokersopt-outprivacyCCPApeople-searchDROP
Read

Crossing a Border With Your Phone: A Field Guide

A calm, practical field guide for journalists and high-risk travelers facing device searches at borders: minimize, prepare, and know exactly where tools help.

border-securitythreat-modelduress-pindata-minimizationtravel
Read

The Dependency Is the Backdoor: Anatomy of the TanStack npm Compromise

On 11 May 2026, attackers published 84 malicious versions across 42 TanStack packages — and exfiltrated stolen secrets over an encrypted messenger. A walkthrough of how a CI misstep becomes a supply-chain backdoor, and why it shapes how RVNT is built and verified.

supply-chainnpmci-cdreproducible-buildsmemory-safetyoidc
Read

Instagram Just Removed Encryption Because Too Few People Used It

Meta is discontinuing end-to-end encryption for Instagram DMs as of 8 May 2026, citing low adoption. It's a perfect demonstration of why optional encryption is fragile — and why defaults and decentralization decide who is actually protected.

metainstagramend-to-end-encryptiondefaultsdecentralization
Read

VPN vs Tor: Does a VPN Actually Make You Anonymous?

Does a VPN make you anonymous? No — it shifts trust to one provider. How VPNs differ from Tor's 3-relay model, no-logs limits, and when each tool actually helps.

vpntoranonymityprivacyfingerprintingthreat-model
Read

They Don't Need Your Phone: Tracking Targets Through the Telecom Network Itself

Citizen Lab's April 2026 'Bad Connection' report documents surveillance actors geolocating people through SS7 and Diameter signaling — below the apps, below the encryption. A breakdown of how it works and why no messenger can fix it alone.

ss7diameterlocation-trackingmetadatatelecomsimjacker
Read

What Is Tor and How Does It Actually Work?

How does Tor work? An honest explainer on onion routing, guard/middle/exit relays, what each can and can't see, .onion services, Tor vs VPN, and Tor's real limits.

toronion-routinganonymityprivacyexplainers
Read

What Is the Double Ratchet? Forward Secrecy, Explained

A beginner-friendly but technically correct explainer of the Double Ratchet: forward secrecy, break-in recovery, why deleting keys matters, and how RVNT uses it.

double-ratchetforward-secrecyencryptionkey-managementmessaging
Read

What Is End-to-End Encryption? A Plain-English Guide

What is end-to-end encryption? A plain-English guide to how E2EE works, how it differs from TLS, who can and can't read your messages, and what it does not protect.

end-to-end-encryptionencryptionprivacymetadatamessaging-security
Read

The EU Just Let Chat Control Expire — For Now

On 26 March 2026 the European Parliament voted 311–228 against extending the law that let platforms scan your private messages. The legal basis lapsed on 3 April. What actually happened, and why the fight isn't over.

chat-controleuclient-side-scanningencryption-lawcsam-regulation
Read

RVNT Protocol: A Technical Deep Dive

A detailed walkthrough of the RVNT cryptographic protocol — hybrid X3DH key exchange with ML-KEM-768, the Double Ratchet with AES-256-GCM, sealed sender metadata protection, and Tor-based transport.

cryptographyprotocolpost-quantumtechnical
Read

The Quantum Clock Just Moved: Google Shrinks the Cost of Breaking ECC

A March 2026 Google Quantum AI paper estimates that breaking 256-bit elliptic-curve cryptography needs ~1,200 logical qubits and under 500,000 physical ones — an order-of-magnitude drop. The machine still doesn't exist. Here's what that actually means for your encrypted messages.

post-quantumelliptic-curveharvest-now-decrypt-laterml-kem-768key-exchange
Read