Skip to content

Latest commit

Β 

History

730 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Guardyn Logo

Guardyn

Private messaging that just works πŸ”

Open source β€’ End-to-end encrypted β€’ Self-hostable

πŸ“± Download β€’ πŸ’» Self-Host β€’ Why Guardyn? β€’ Contribute

Version E2EE PQ-Ready License


What is Guardyn?

Guardyn is a private messaging app with military-grade encryption. Unlike other messengers:

  • βœ… Open source β€” you can verify everything we claim
  • βœ… Self-hostable β€” run your own server if you want complete control
  • πŸ” End-to-end encrypted β€” encryption happens on your device, not on the server. Making it impossible to disable is tracked work, not yet done.
  • 🚧 Post-quantum β€” hybrid X25519 + ML-KEM-768 is implemented in crates/crypto, but is not yet enabled end-to-end. Do not rely on it against a harvest-now-decrypt-later adversary until it is.

Guardyn Apps


πŸ“± Quick Start (Users)

Download the App

Platform Status Download
πŸ“± Android βœ… Ready Coming to Play Store Q1 2026
πŸ“± iOS βœ… Ready Coming to App Store Q1 2026
πŸ–₯️ Windows βœ… Ready GitHub Releases
πŸ–₯️ macOS βœ… Ready GitHub Releases
πŸ–₯️ Linux βœ… Ready GitHub Releases

Early Access: We're in beta! Download from GitHub Releases and join the privacy rebellion.

Connect to a Server

Option 1: Use our hosted server (coming Q2 2026)

  • Just download the app and sign up β€” we handle everything

Option 2: Self-host your own server


πŸ’» Quick Start (Developers)

Want to run your own Guardyn server? It's easy!

Prerequisites

Start in 30 Seconds

# Clone the repository
git clone https://github.com/guardyn/guardyn.git
cd guardyn

# Start all services
docker compose -f docker-compose.dev.yml up -d

# Check status
docker compose -f docker-compose.dev.yml ps

That's it! πŸŽ‰ Your server is running at localhost:8080.

Using Justfile (Even Easier)

We provide a Justfile with all common commands:

# Install Just: cargo install just (or brew install just)

just dc-up      # Start all services
just dc-down    # Stop all services  
just dc-logs    # View logs
just dc-ps      # Check status
just dc-reset   # Reset all data

Next Steps

Guide Description
Contributing Full development setup
Deployment Docker Compose details
Deployment Kubernetes for production
Contributing How to contribute

πŸ”’ Why Guardyn?

The Problem

App E2EE Always? Open Source? Self-Host? Problem
Telegram ❌ ❌ ❌ Chats readable by servers
WhatsApp βœ… ❌ ❌ Metadata goes to Meta
Slack/Teams ❌ ❌ ❌ No E2EE, enterprise only
Signal βœ… βœ…* ❌ Can't self-host
Guardyn βœ… βœ… βœ… β€”

*Signal's server is mostly open source but not designed for self-hosting.

Our Solution

For Everyone:

  • πŸ” Messages encrypted before they leave your device
  • πŸ‘οΈ Zero-knowledge: we can't read your messages
  • πŸ“± Native apps for all platforms

For Organizations:

  • 🏒 Self-host for complete data sovereignty
  • πŸ”‘ LDAP/SAML integration (coming v1.2)
  • πŸ“Š Compliance-ready (GDPR, HIPAA)

For Developers:

  • πŸ› οΈ 100% open source (Apache-2.0)
  • ⚑ 30-second local setup
  • πŸ“š Comprehensive documentation

πŸ›‘οΈ Security

What We Use

Layer Technology Why
1-on-1 Chat Signal Protocol (Double Ratchet) Battle-tested, billions of users
Group Chat OpenMLS (IETF RFC 9420) Modern standard, scalable
Key Exchange PQXDH (X3DH + ML-KEM) Post-quantum resistant
Voice/Video WebRTC + SFrame E2EE media streaming
Metadata Sealed Sender Hides who sent the message

What We Promise

  • βœ… End-to-end encryption β€” Always on, can't be disabled
  • βœ… Perfect Forward Secrecy β€” Past messages safe if keys compromised
  • βœ… Post-Quantum Ready β€” Protected against quantum computers
  • βœ… Metadata Protection β€” Sealed Sender hides sender identity
  • βœ… Hardware Keys β€” iOS Secure Enclave, Android KeyStore

What We Don't Promise

  • ⚠️ If your device is compromised, encryption can't help
  • ⚠️ Recipients can take screenshots
  • ⚠️ ISPs see IP addresses (use Tor/VPN for anonymity)

Security Audit

  • βœ… Internal security review completed
  • βœ… Penetration testing infrastructure deployed
  • πŸ“‹ External audit (Cure53) scheduled Q2 2026

πŸ“± Features

Messaging

  • βœ… 1-on-1 and group chat (E2EE)
  • βœ… Voice messages
  • βœ… Message reactions, replies, edit, delete
  • βœ… Disappearing messages
  • βœ… Read receipts and typing indicators

Calls

  • βœ… Voice and video calls (1-on-1, E2EE)
  • βœ… Screen sharing (desktop)
  • πŸ“‹ Group calls (coming v1.1)

Media

  • βœ… Photos, videos, files (encrypted)
  • βœ… Media gallery

Platform

  • βœ… iOS, Android (Flutter)
  • βœ… Windows, macOS, Linux (Tauri)
  • βœ… Push notifications (FCM, APNs)
  • βœ… Offline support

πŸ—οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                         YOUR DEVICES                            β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  πŸ“± Mobile (Flutter)          πŸ–₯️ Desktop (Tauri)               β”‚
β”‚  iOS β€’ Android                Windows β€’ macOS β€’ Linux           β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                           β”‚
                    πŸ” guardyn-crypto (Rust)
                    All encryption happens HERE
                    on YOUR device
                           β”‚
                           β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                       GUARDYN SERVER                            β”‚
β”‚  (Can self-host or use our cloud)                               β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  πŸ”‘ Auth        πŸ’¬ Messaging      πŸ‘₯ Presence                   β”‚
β”‚  πŸ“ Media       πŸ“ž Calls          πŸ”” Notifications              β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  TiKV β€’ ScyllaDB β€’ Redpanda (Data Layer)                       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                           β”‚
                    Server CANNOT read
                    your messages! πŸ”’

Key Point: All encryption/decryption happens on YOUR device. The server only sees encrypted blobs.


πŸ—ΊοΈ Roadmap

The roadmap lives in docs/roadmap/ROADMAP.md, generated from docs/roadmap/roadmap.yaml β€” the machine source of truth that also drives the issue tracker. It is kept there rather than here so it cannot drift from the board.


πŸ†š Compared to Signal

We respect Signal β€” they pioneered secure messaging. Here's how we differ:

Feature Signal Guardyn
1-on-1 E2EE βœ… Double Ratchet βœ… Double Ratchet (same)
Group E2EE βœ… Sender Keys βœ… OpenMLS (newer standard)
Post-Quantum βœ… PQXDH shipped 🚧 PQXDH implemented, not yet enabled
Self-Hosting ❌ βœ… Full support
100% Open Source ⚠️ Most parts βœ… Everything
Track Record βœ… 10+ years ⚠️ New (2026)
Audit Status βœ… Multiple audits πŸ“‹ Planned Q2 2026

Bottom Line:

  • Use Signal if you want maximum proven trust
  • Use Guardyn if you need self-hosting or want 100% open source

πŸ“– License

100% Apache-2.0. No dual licensing, no "Enterprise Edition" tricks.

Self-host anywhere. Modify freely. Contribute back if you want.


🀝 Contributing

See CONTRIBUTING.md for setup and the pull-request contract, and AGENTS.md for the rules every change follows β€” invariants, git workflow, logging law and code standards.

Guardyn is developed agent-first, so the contract is written to be machine-checkable: .claude/rules/ turns each rule into a predicate you can run against your own branch before a reviewer sees it.


πŸ’¬ Contact


The Privacy Rebellion Starts Now πŸ›‘οΈ

Built with ❀️ by privacy advocates
Apache-2.0 β€’ Copyright Β© 2025-2026 Guardyn Team

About

Privacy-focused secure messenger with post-quantum E2EE (PQXDH/ML-KEM), OpenMLS groups, SFrame voice/video, Sealed Sender. Flutter (iOS/Android) + Tauri (Desktop). Self-hostable, Kubernetes-native, Apache-2.0.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

31 stars

Watchers

2 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages