SKYTAL

Trust Center

SKYTAL Security

A P2P-first secure messenger with E2EE. Below is what is protected today and the limits we describe honestly.

Confirmed capabilities

Active security mechanisms are marked as available. Direct P2P for messages and client-side attachment E2EE are development directions — not current public claims.

Messages

Personal messages are encrypted on the sender device and decrypted on the recipient device. The server relays ciphertext and is not intended to store plaintext.

Calls

WebRTC P2P-first: a direct connection between devices when possible. When a direct route is unavailable, a protected relay fallback is used.

Files

Attachments are transferred and stored in encrypted form through the server media layer. Direct device-to-device file transfer is a development direction, not a current feature.

Keys

Private keys are generated and stored on the device. Public keys required for exchange are sent to the server.

Delivery architecture

Calls connect directly between devices when possible; otherwise a protected relay is used. Messages and files are delivered through server infrastructure in encrypted form.

P2P-first architecture diagram

SKYTAL architecture overviewDeviceDeviceRelayInfrastructure

Server role

The server enables encrypted delivery, call signaling, and fallback route coordination. It does not replace on-device E2EE.

Metadata

SKYTAL minimizes the role of server infrastructure and the volume of technical data required to operate the service. Infrastructure may process metadata needed for routing and delivery.

What happens to data

A brief overview of what the server sees and what stays on your device — based on current implementation.

  • Messages: no persistent server chat history; a temporary encrypted delivery queue is used.
  • Files: encrypted media layer with limited server-side retention.
  • Keys: private keys on the device; only public Signal crypto material on the server.
  • Metadata: technical data for routing and service operation; SKYTAL does not claim the absence of metadata.

What we do not claim

  • SKYTAL is not a fully decentralized messenger
  • Infrastructure may process metadata required for routing
  • Messages and files are not delivered directly P2P between devices today

Security contact

Security questions and vulnerability reports: info@skytal.ru (subject: Security).

info@skytal.ru