Two phones.
One You. One vault
no one can crack.
DevoraX2 is trust infrastructure built around resilient communication continuity. A post-quantum cryptographic architecture intentionally distributed across two devices — so trust never depends on a single point of failure. If Your primary device is lost, stolen, or compromised, the Guardian device locks it, wipes it, and restores continuity remotely. Recovery strengthens continuity instead of creating vulnerability.
Your words, unreadable by design.
ML-KEM-1024 (NIST FIPS 203) wrapped with X25519. A classical curve sealing the post-quantum layer.
Two devices, one continuity.
Device A is Your daily surface. Device B is the Guardian — separate trust path, recovery keys, integrity monitoring.
Trust is the infrastructure.
DevoraX2 is the architectural reference — the proof of how trust is built, before it is sold. Built by one developer, for architects, security researchers, and thoughtful participants evaluating cryptographic infrastructure for the systems they protect. Security should survive real life. Trust should not depend on a single device. Recovery should strengthen continuity instead of creating vulnerability. The network strengthens through participation — every citizen is a node, and the more of us there are, the harder it is to switch off.
Built so security survives real life.
Every architectural decision exists because someone, somewhere, was harmed by its absence. This is not a chat app. It is a trust infrastructure — designed for environments where failure has consequences.
Hybrid post-quantum encryption
Every message is wrapped in two cryptographic layers — ML-KEM-1024 (NIST FIPS 203) and X25519. Confidentiality survives the arrival of quantum-capable adversaries.
Guardian Kernel
A second device on a separate trust path. Lock, locate, and remote-wipe execute through the Guardian — never through the compromised device. Trust does not depend on a single device.
Bounded persistence
Messages exist only as long as the conversation requires — 1s to 90d, then vanish from endpoints and servers. Communication should reduce cognitive stress, not increase it.
Plausible deniability
Disguise the app as a calculator. Decoy account under coercion. The architecture assumes adversaries with physical access — not only network attackers.
Private Worlds
End-to-end encrypted communities — channels, voice rooms, roles. Encryption applied at the architectural level, not bolted on at the application layer.
Surface minimization
The architecture exposes nothing the system does not need to function. No device model. No OS version. No region. No telemetry. No analytics.
Cryptographic identity proof
Conversational endpoints are proven, not assumed. Interception is mathematically impossible — not unlikely, impossible.
GraphPIN — five doors, one fortress
A graphical pattern combined with per-circle digits and letters. Brute-forcing it would take billions of years. But the real magic is what happens at each door — five separate PINs, five entirely different outcomes.
Trust should not
depend on a single device.
Pickpockets, malware, lost-and-stolen, coercion, jurisdiction seizure — a single device is one point of failure. DevoraX2 splits the trust path between two. Compromise of either device alone cannot break the system.
An ChaCha20-Poly1305 + ML-KEM-wrapped vault for files and notes. Worlds are end-to-end encrypted communities with role-based channels and voice rooms — encryption applied at the architectural level.
Encryption protects content. Plausible deniability protects the fact that anything is being encrypted at all. Three architectural layers operate independently — Hidden, Decoy, Panic.
The device You use every day — full messaging, Worlds, vault. Bio-behavioral signature combined with pattern unlock makes forgery require both physical and behavioral biometrics.
Double Ratchet over PQXDH. Forward secrecy and post-compromise security applied at the protocol level: a single key exposure does not unseal messages before or after.
The Guardian maintains an append-only log of every significant event on Device A — unlock attempts, session changes, key rotations, location shifts. Visible to You alone, signed and timestamped.
A separate device on a separate trust path. Holds recovery keys, monitors integrity signals from the primary, and executes Cross-Guard actions when threat conditions are met. Architecturally isolated — compromise of Device A does not propagate.
channel
We are many.
The network is Yours.
Every DevoraX2 device is a node. Messages route through the strongest available paths — between Your phone, Your Guardian, and the citizens around You. The more of us there are, the harder it is to switch off. You don't use the network. You are the network.
That network has an honest price: yearly fuel for the relays it depends on, monthly subscription for the product I build alone. No ads. No data brokers. No investor exits. The architecture cannot sell what it does not have.
No free tier. No ads. No investor exits. The honest price of a network that survives.
- Unlimited E2EE messages & calls
- Guardian companion (Device B)
- Up to 3 private Worlds
- 5 GB encrypted vault
- Hidden & Decoy modes
Total · $130.80 / year
- Everything in Personal
- Up to 10 Worlds & channels
- 20 GB encrypted vault
- Anti-fingerprinting + zero telemetry
- Custom panic codes
- Priority support
Total · $203.04 / year (paid yearly)
- Everything in Pro
- 50 GB encrypted vault
- SAML / SSO & SCIM provisioning
- Compliance audit logs (immutable)
- Dedicated security engineer
Total · $395.04 / seat / year (paid yearly)
Trust isn't a feature.
It's the whole architecture.
Citizenship in a network that survives Your operator, Your jurisdiction, and Your political season.
Four domains, one architecture.
Each domain carries a distinct voice for a distinct audience. The architecture remains one.