Security
Security and responsible disclosure
Last updated: 9 October 2026
How Nodz protects you
- End-to-end encryption with MLS. Conversations use the Messaging Layer Security protocol (RFC 9420) through the open-source OpenMLS library, compiled into the app. Encryption keys are created on your device and never leave it in readable form.
- No phone number, no email. There is little to leak in the first place.
- Recovery without a back door. Your recovery code never reaches our servers. Only you can decrypt your key backup.
- Hardened servers. Passwords are hashed with Argon2id, all traffic uses TLS, databases are not reachable from the internet, services run with least privilege, and we keep no access logs.
- No third-party code on our pages. No analytics, advertising or external scripts, enforced by a strict Content Security Policy.
- Verifiable builds. The encryption module is built reproducibly, and its SHA-256 checksums are published with every release.
What encryption cannot do
- It cannot hide all metadata: the server still sees when devices connect and how large encrypted messages are.
- It cannot protect a device that is infected with malware or used by someone else while unlocked.
- In the web app, the code that handles your keys is delivered by our server each time. A compromised server could deliver malicious code. Desktop and mobile apps will reduce this risk.
Compare safety numbers with your contacts in person or over another channel to make sure nobody is in the middle. Nodz warns you when a contact's key changes.
Reporting a vulnerability
Please report security problems to security@nodz.im. Include a description, the steps to reproduce it, and the impact you expect. Our security.txt lists the same contact.
We commit to:
- confirm receipt within 5 working days and keep you informed about progress;
- not take legal action against research done in good faith under this policy;
- credit you publicly if you wish, once the issue is fixed.
We ask you to:
- only test with accounts you own, and never access, change or delete other people's data;
- not perform denial-of-service attacks, spam, social engineering or physical attacks;
- give us reasonable time (normally 90 days) to fix the problem before disclosing it.