UNDERWORLD RESTRICTED SECURITY MESSENGER
Zero-trust architecture. Hardened by default.
UNDERWORLD is an encrypted messenger built for high-risk communication for the people who cannot afford exposure. Where a message can reveal too much, an identity can become a target and ordinary privacy is already too late.
A survival-grade messenger built to become the world’s most secure line of communication.




RELEASE CANDIDATE 26 JULY 2026

When Privacy Is Already Too Late.
There are places where a single message can cost a life, freedom, or everything behind it.
Where a contact becomes a target. Where a location becomes evidence. Where a notification, a file, a name, or a network trace can expose the person behind the screen.
UNDERWORLD was built for that moment.
Not for casual privacy.
Not for convenience.
Not for ordinary communication.
Dangerous evidence. Human sources. Sensitive identities. Built for NGOs, journalists, security operators, and high-risk users, UNDERWORLD protects the conversations that cannot afford exposure.
Some messages do not need more features. They need protection.
Engineered without compromise.
We eliminated standard convenience features to close the critical attack vectors that consumer messaging apps routinely leave exposed to network surveillance.
Post-Quantum Defense Aligned With CNSA 2.0
DARKNET Only Fail-Closed
Zero Cloud Trust
Nothing stored above you.
UNDERWORLD combines classical encryption with quantum-resistant protection, following the direction of CNSA 2.0 — the cryptographic suite published by the U.S. National Security Agency for future National Security Systems.
Underworld routes communication through hardened anonymity networks such as Tor and I2P, with no direct path, no plaintext relay, and no insecure fallback when the network becomes hostile.
No remote message storage. No cloud backups. No contact upload. No recovery backdoor. No hidden server-side copy waiting to be restored, seized, or exposed. If you lose your device, your cryptographic identity is gone with it.




Let them watch dust.
UNDERWORLD routes encrypted relay traffic through privacy networks like Tor and I2P.
Every hop knows only where the signal came from and where it goes next — never the full route, never the complete path, never the conversation itself.
Encrypted routing obscures the journey while reducing network traceability across the chain.
By the time anyone tries to follow the signal, all that remains is motion, noise, and fragments.
Encryption Model
End-to-End Encryption
Triple Ratchet Messaging
Conversation keys evolve over time as messages are exchanged, reducing the impact of future key compromise.
Messages use isolated key material so one compromised message does not unnecessarily expose the rest of the conversation.
Cryptographic identity material is generated and stored locally. UNDERWORLD does not use cloud identity recovery as a trust dependency.
Message-Key Isolation
Local Identity Storage
Blackout Mode
When the internet is gone, blocked, or unsafe, UNDERWORLD does not stop.
Blackout Mode is a manual emergency workspace for preparing encrypted offline message capsules when secure routing cannot be trusted. Capsules can later be moved through local carriers such as QR, file transfer, Wi-Fi, or Bluetooth — without exposing the content to the carrier.
No automatic activation. No blind fallback. No plaintext handoff.
You enter manually. You stay in control.


When the network dies, the message survives.
When an Underworld-compatible channel is active, transmission is routed through the Tor network and designed to avoid direct network exposure. No ordinary browser trail. No direct relay fallback. No plaintext route. The source is shielded at the network layer before the message ever reaches its destination.
It is built for people carrying information that cannot be handled like an ordinary message: human-rights abuse, corruption, institutional violence, war-crime documentation, and public-interest evidence.
Silent Witness can guide users toward trusted reporting destinations such as OCCRP, ProPublica, Whistleblower Aid, Human Rights Watch, and the ICC Office of the Prosecutor. Channels remain locked until verification requirements are met. Endpoint and fingerprint checks help reduce the risk of fake destinations, phishing, wrong addresses, and unsafe handling.
No casual sharing. No public posting. No social feed. No leak marketplace.
Only a protected bridge between people carrying critical information and organizations built to receive it.
Underworld does not decide what truth is. It does not publish, investigate, edit, or interfere. It protects the source-side process: preparation, local encryption, evidence control, destination verification, Tor-routed transmission, and hostile-environment security around the user.
Silent Witness — for the moment when the message matters more than the messenger.
Organization names and logos are shown for identification of public reporting destinations only. No affiliation or endorsement is implied unless explicitly stated.


When silence is no longer possible, Underworld gives users a safer path to speak.
Final Pulse.
For the moment when the owner can no longer protect the device.
If UNDERWORLD detects a severe crash, violent fall, prolonged immobility, or heartbeat loss through a connected wearable, it enters emergency lockdown. A countdown begins. If the PIN is not entered before the timer expires, UNDERWORLD destroys local encryption keys and wipes protected vault data.
No single-signal panic wipe. No accidental deletion from a dropped phone. No blind reaction to a disconnected bracelet.
Impact. Silence. Heartbeat lost. Countdown. Lockdown. Key destruction.
When the owner is gone, the vault does not remain behind.


Confuse the watcher. Protect the message.
Decoy Relay Traffic
UNDERWORLD can send encrypted decoy payloads through the relay that look like normal messages but contain no real conversation content.
This makes it harder for the relay or a network observer to separate real messages from background encrypted activity.
Even if message content is unreadable, timing and traffic patterns can still reveal who is active and when communication happens.
Decoy traffic reduces that signal alongside TOR-only routing, ciphertext padding, relay purge controls, and fail-closed delivery.
No Recovery by Design
You didn’t come this far to stop


UNDERWORLD does not keep cloud backups, recovery keys, identity keys, or server-side copies of private conversations.
Your data stays protected on your device. Because UNDERWORLD has no server-side recovery path, there is no hidden access channel to restore, decrypt, or hand over your messages.
This means nobody not UNDERWORLD, not relay operators, not infrastructure providers, and not outside parties — can recover your conversations if your device or identity keys are lost.
Privacy is enforced by architecture, not by promise.
Active Incoming Attack Alarms
UNDERWORLD is built to know when the signal turns hostile.
If suspicious interference is detected, the app can warn you that an incoming attack may be in progress — that someone may be trying to intercept, impersonate, manipulate, or force their way into your communication path.
If the attack escalates and the session shows signs of possible breach, UNDERWORLD raises the warning level and tells you the communication can no longer be trusted.
It does not fail silently.
It blocks first, warns fast, and alerts you when trust is broken.
Packet Injection Attempt
Replay Attack
Message Tampering
Authentication-Tag Failure
Malformed Packet Attack
Duplicate Message-ID Attack
Duplicate Encrypted Message Attack
Sender-Binding Attack
Contact Identity Substitution Attack
Ratchet-State Attack
Skipped-Key Abuse Attack
Relay Message-Forgery Attempt
Attachment Path-Traversal Attack
Dangerous Attachment Attack
Risky MIME Mismatch Attack
Oversized Attachment Abuse
Attachment Metadata Deception
Tapjacking / Obscured-Touch Attack
Screen Overlay Attack
Insecure Routing Downgrade Attempt
Last-Resort Protection
When access is forced, privacy still has a final line.
UNDERWORLD can be configured with a secondary duress PIN for extreme pressure situations.
If someone forces you to unlock the app, entering the duress PIN triggers an irreversible security response: sensitive local data is destroyed before it can be exposed.
No warning. No recovery prompt. No cloud restore. No second chance.
The real PIN unlocks the app.
The duress PIN protects your last line of dignity.
One code opens. One code burns.


Multi-hop cryptographic transit.
Local Encryption
Tor Circuit Entry
Zero-Knowledge Relay
Fails Closed Delivery
Messages are sealed locally using X3DH and Double Ratchet protocols before any network transmission begins.
The payload enters a multi-hop Tor circuit directly from your device, masking your IP address and physical location.
The destination relay receives only encrypted ciphertext. It cannot identify the sender, recipient, or message contents.
If a secure Tor circuit cannot be established, the transmission aborts. No fallback to plaintext routing is permitted.
Metadata Defense
Not just encrypted. Sanitized
Attachment Sanitization
Files are processed through a sanitization layer designed to reduce exposed metadata before they are shared.
Notification Privacy
Alerts are kept generic by default to reduce exposed message content outside the encrypted app screen.
No Social Presence Leaks
UNDERWORLD avoids typing indicators, online status, and last-seen markers.
