Security & Privacy

Encrypted transport. AI on your terms.

Every message and call is end-to-end encrypted. AI is on from the start and always in your hands β€” when it's on, your content is processed under a strict no-training guarantee: the AI that handles it is contractually barred from training on your prompts or responses. Turn it off per conversation or entirely, anytime.

πŸ”’

End-to-end by default

Messages use Envelope v1 (X25519 + AES-256-GCM + Ed25519). Calls add a forward-secret key exchange with per-frame authenticated encryption. In transit, the server holds only ciphertext.

🧠

No-training AI

When you use AI, your content is processed under contractual no-training terms β€” it is never used to train a model. The same no-training pipeline on every tier. Turn AI off and nothing leaves the encrypted envelope.

πŸŽ›οΈ

One clear switch

AI off = pure end-to-end. AI on = no-train understanding. You decide per conversation and per group β€” and you can change your mind any time.

The model

One architecture, two honest modes

Transport is always end-to-end encrypted. The only choice is whether AI processes your content β€” and that choice is yours, made explicit.

πŸ”‡ AI off β€” pure E2E

Your messages and calls are end-to-end encrypted and nothing is processed. Fast, focused, and the server holds only ciphertext.

✨ AI on β€” no-train

To summarize a note or answer a question, the worker decrypts inside an isolated process and handles your content under a strict no-training guarantee β€” never used to train a model, on any tier.

Built for the quantum era

Hybrid post-quantum encryption β€” rolling out

We've built hybrid post-quantum encryption into Telbox's core. As your devices update to support it, conversations upgrade to post-quantum automatically β€” no setting to flip.

πŸ”— Hybrid, not either-or

Each sealed message combines classic X25519 with ML-KEM-768, the NIST post-quantum standard (FIPS 203). An attacker has to break both β€” today's elliptic-curve math and the lattice cryptography a quantum computer would target.

πŸ—„οΈ Beats "harvest now, decrypt later"

Adversaries record encrypted traffic today, betting they'll crack it once quantum hardware arrives. Hybrid post-quantum is rolling out so a message captured now stays sealed against that future machine.

♾️ Upgrades itself

The upgrade is capability-negotiated: a conversation moves to post-quantum once both devices support it, automatically. Devices not yet updated keep the still-strong classical encryption until they are.

🏷️ Post-quantum signatures

Verified-institution signatures are rolling out ML-DSA-44 (FIPS 204) alongside Ed25519, to stay resistant to tomorrow's quantum hardware.

Verified participants

You can prove who's an agent

In the agents preview, each agent gets its own Ed25519 identity. Its messages are signed and verified on your device, so a "from Agent X" badge is a cryptographic proof β€” not a label. Revoke an agent and every message it ever sent loses its badge, retroactively.

  • Per-agent signing keys, KMS-wrapped, never plaintext
  • On-device verification with a tap-to-verify badge
  • Retroactive revocation distinguishes compromise from rotation
Verified Β· Nudge Bot

Tapping the badge re-checks the signature against the agent's published identity key, right on your phone. No server in the trust path.

Defense in depth

Engineered to be boring under attack

🌐

SSRF-guarded egress

Every outbound fetch (webhooks, link previews, MCP) is DNS-pinned and blocks metadata, RFC1918, and loopback ranges.

πŸ”

Scoped API keys

Partner keys carry an explicit scope set. Deny-by-default: every authenticated route is consciously classified, so nothing leaks by omission.

🧾

Signed provenance

Institutional messages use canonical CBOR + Ed25519 with multi-witness audit anchoring. Tamper-evident by construction.

πŸ›‘οΈ

Prompt-injection fences

Content an agent reads is marked untrusted; external and irreversible actions never auto-fire from freshly-read content.

πŸ”

No-train, end to end

The no-train guarantee is the default routing for every user, not a paid upgrade. The tier gates cost, not privacy.

πŸ›οΈ

Sovereign option

Regulated institutions self-host a cell where data never leaves their cloud and keys live in their KMS. Details β†’

Want the mechanics, not the marketing? How Telbox handles your data walks through the encryption, the server-side AI decryption, and the no-training guarantee in engineering detail β€” the inspectable companion to our Privacy Policy.

Read the legal source of truth: