Open source β’ End-to-end encrypted β’ Self-hostable
π± Download β’ π» Self-Host β’ Why Guardyn? β’ Contribute
Guardyn is a private messaging app with military-grade encryption. Unlike other messengers:
- β Open source β you can verify everything we claim
- β Self-hostable β run your own server if you want complete control
- π End-to-end encrypted β encryption happens on your device, not on the server. Making it impossible to disable is tracked work, not yet done.
- π§ Post-quantum β hybrid X25519 + ML-KEM-768 is implemented in
crates/crypto, but is not yet enabled end-to-end. Do not rely on it against a harvest-now-decrypt-later adversary until it is.
| Platform | Status | Download |
|---|---|---|
| π± Android | β Ready | Coming to Play Store Q1 2026 |
| π± iOS | β Ready | Coming to App Store Q1 2026 |
| π₯οΈ Windows | β Ready | GitHub Releases |
| π₯οΈ macOS | β Ready | GitHub Releases |
| π₯οΈ Linux | β Ready | GitHub Releases |
Early Access: We're in beta! Download from GitHub Releases and join the privacy rebellion.
Option 1: Use our hosted server (coming Q2 2026)
- Just download the app and sign up β we handle everything
Option 2: Self-host your own server
- Complete control over your data
- See Self-Host Guide below
Want to run your own Guardyn server? It's easy!
- Docker β Install Docker
- 8GB RAM minimum
# Clone the repository
git clone https://github.com/guardyn/guardyn.git
cd guardyn
# Start all services
docker compose -f docker-compose.dev.yml up -d
# Check status
docker compose -f docker-compose.dev.yml psThat's it! π Your server is running at localhost:8080.
We provide a Justfile with all common commands:
# Install Just: cargo install just (or brew install just)
just dc-up # Start all services
just dc-down # Stop all services
just dc-logs # View logs
just dc-ps # Check status
just dc-reset # Reset all data| Guide | Description |
|---|---|
| Contributing | Full development setup |
| Deployment | Docker Compose details |
| Deployment | Kubernetes for production |
| Contributing | How to contribute |
| App | E2EE Always? | Open Source? | Self-Host? | Problem |
|---|---|---|---|---|
| Telegram | β | β | β | Chats readable by servers |
| β | β | β | Metadata goes to Meta | |
| Slack/Teams | β | β | β | No E2EE, enterprise only |
| Signal | β | β * | β | Can't self-host |
| Guardyn | β | β | β | β |
*Signal's server is mostly open source but not designed for self-hosting.
For Everyone:
- π Messages encrypted before they leave your device
- ποΈ Zero-knowledge: we can't read your messages
- π± Native apps for all platforms
For Organizations:
- π’ Self-host for complete data sovereignty
- π LDAP/SAML integration (coming v1.2)
- π Compliance-ready (GDPR, HIPAA)
For Developers:
- π οΈ 100% open source (Apache-2.0)
- β‘ 30-second local setup
- π Comprehensive documentation
| Layer | Technology | Why |
|---|---|---|
| 1-on-1 Chat | Signal Protocol (Double Ratchet) | Battle-tested, billions of users |
| Group Chat | OpenMLS (IETF RFC 9420) | Modern standard, scalable |
| Key Exchange | PQXDH (X3DH + ML-KEM) | Post-quantum resistant |
| Voice/Video | WebRTC + SFrame | E2EE media streaming |
| Metadata | Sealed Sender | Hides who sent the message |
- β End-to-end encryption β Always on, can't be disabled
- β Perfect Forward Secrecy β Past messages safe if keys compromised
- β Post-Quantum Ready β Protected against quantum computers
- β Metadata Protection β Sealed Sender hides sender identity
- β Hardware Keys β iOS Secure Enclave, Android KeyStore
β οΈ If your device is compromised, encryption can't helpβ οΈ Recipients can take screenshotsβ οΈ ISPs see IP addresses (use Tor/VPN for anonymity)
- β Internal security review completed
- β Penetration testing infrastructure deployed
- π External audit (Cure53) scheduled Q2 2026
- β 1-on-1 and group chat (E2EE)
- β Voice messages
- β Message reactions, replies, edit, delete
- β Disappearing messages
- β Read receipts and typing indicators
- β Voice and video calls (1-on-1, E2EE)
- β Screen sharing (desktop)
- π Group calls (coming v1.1)
- β Photos, videos, files (encrypted)
- β Media gallery
- β iOS, Android (Flutter)
- β Windows, macOS, Linux (Tauri)
- β Push notifications (FCM, APNs)
- β Offline support
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β YOUR DEVICES β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β π± Mobile (Flutter) π₯οΈ Desktop (Tauri) β
β iOS β’ Android Windows β’ macOS β’ Linux β
ββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
π guardyn-crypto (Rust)
All encryption happens HERE
on YOUR device
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β GUARDYN SERVER β
β (Can self-host or use our cloud) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β π Auth π¬ Messaging π₯ Presence β
β π Media π Calls π Notifications β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β TiKV β’ ScyllaDB β’ Redpanda (Data Layer) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
Server CANNOT read
your messages! π
Key Point: All encryption/decryption happens on YOUR device. The server only sees encrypted blobs.
The roadmap lives in docs/roadmap/ROADMAP.md, generated from
docs/roadmap/roadmap.yaml β the machine source of truth that also drives the issue
tracker. It is kept there rather than here so it cannot drift from the board.
We respect Signal β they pioneered secure messaging. Here's how we differ:
| Feature | Signal | Guardyn |
|---|---|---|
| 1-on-1 E2EE | β Double Ratchet | β Double Ratchet (same) |
| Group E2EE | β Sender Keys | β OpenMLS (newer standard) |
| Post-Quantum | β PQXDH shipped | π§ PQXDH implemented, not yet enabled |
| Self-Hosting | β | β Full support |
| 100% Open Source | β Everything | |
| Track Record | β 10+ years | |
| Audit Status | β Multiple audits | π Planned Q2 2026 |
Bottom Line:
- Use Signal if you want maximum proven trust
- Use Guardyn if you need self-hosting or want 100% open source
100% Apache-2.0. No dual licensing, no "Enterprise Edition" tricks.
Self-host anywhere. Modify freely. Contribute back if you want.
See CONTRIBUTING.md for setup and the pull-request contract, and AGENTS.md for the rules every change follows β invariants, git workflow, logging law and code standards.
Guardyn is developed agent-first, so the contract is written to be machine-checkable:
.claude/rules/ turns each rule into a predicate you can run against
your own branch before a reviewer sees it.
- Website: guardyn.co
- GitHub: github.com/guardyn/guardyn
- Security: security@guardyn.co (vulnerabilities only)
- General: hello@guardyn.co
The Privacy Rebellion Starts Now π‘οΈ
Built with β€οΈ by privacy advocates
Apache-2.0 β’ Copyright Β© 2025-2026 Guardyn Team
