RESTRICTED BETA

Hardened communication starts here

Request access to the UNDERWORLD client. No phone number or personal identifiers required. All builds are signed, verified, and routed exclusively through the Tor network and I2P.

Frequently Asked Questions.

Clinical technical answers regarding the UNDERWORLD zero-trust architecture, metadata minimization, and secure routing protocols. Review our strict defaults before requesting access.

WHAT IS UNDERWORLD?

UNDERWORLD is a restricted-security encrypted messenger designed for high-risk communication.

It combines end-to-end encrypted messaging, device-bound identity, anonymity-network routing, fail-closed delivery, metadata reduction, attachment sanitization, active attack alarms, offline encrypted capsules, Silent Witness, and Custom Verified Tunnels.

The product is not built around mass-market convenience.

It is built around exposure reduction.

WHO IS UNDERWORLD DESIGNED FOR?

UNDERWORLD is designed for people and organizations operating in environments where communication itself can create risk.

This includes journalists, freelance reporters, NGOs, human-rights operators, legal teams, diplomatic offices, investigators, security personnel, field operators, whistleblower support organizations, public-interest institutions, and private users facing surveillance, coercion, or metadata exposure.

Organizations can also use UNDERWORLD through Custom Verified Tunnels, which provide organization-specific secure intake paths inside Silent Witness.

IS UNDERWORLD JUST ANOTHER ENCRYPTED CHAT APP?

No. Encrypted chat is only one part of UNDERWORLD.

UNDERWORLD is designed as a restricted-security communication architecture. It protects not only message content, but also routing behavior, local identity, metadata exposure, attachment risk, source-side evidence handling, relay trust, fallback behavior, and emergency communication conditions.

The objective is not simply to encrypt a message.

The objective is to reduce what the communication environment can reveal.

WHAT DOES “RESTRICTED SECURITY” MEAN?

Restricted Security means UNDERWORLD does not offer a weaker convenience mode.

There is no mode built around cloud recovery, contact-list upload, plaintext relay, public social presence, notification previews, direct insecure fallback, or silent downgrade when protected routing fails.

The system is designed around one security posture:

Local encryption.
Device-bound identity.
Protected routing.
Relay distrust.
Metadata minimization.
Attachment hardening.
Fail-closed delivery.
Active warning when trust changes.

Security is not treated as a setting.

It is the architecture.

WHAT MAKES UNDERWORLD DIFFERENT FROM CONSUMER MESSAGING APPS?

Most consumer messengers optimize for convenience: cloud backups, account recovery, contact discovery, presence indicators, message previews, quick onboarding, and frictionless syncing.

Those features are useful for ordinary communication, but they can expose high-risk users.

UNDERWORLD removes or restricts those exposure points. It does not upload contacts, does not rely on cloud message recovery, does not expose typing indicators or last-seen status, does not use plaintext relay, and is designed to block unsafe fallback instead of silently downgrading.

It is built for users who need communication hardened against exposure, not optimized for convenience.

DOES UNDERWORLD USE END-TO-END ENCRYPTION?

Yes.

UNDERWORLD is designed so messages are encrypted on the sender’s device before transmission and decrypted only on the recipient’s device.

The relay is not intended to receive readable message content. It handles ciphertext.

This means the relay can support delivery without becoming trusted with plaintext conversations.

WHAT CRYPTOGRAPHIC MODEL DOES UNDERWORLD USE?

UNDERWORLD’s secure-messaging model is based on modern encrypted communication principles, including:

X3DH-style secure session establishment.
Double Ratchet-style message encryption.
Authenticated encryption.
Message-key isolation.
Forward secrecy.
Post-compromise recovery behavior.
Local identity binding.
Device-bound cryptographic identity.
Post-quantum hybrid defense direction.

The goal is to establish secure sessions, evolve keys over time, limit damage from compromise, reject tampered content, and reduce long-term interception risk.

WHAT IS X3DH-STYLE SESSION ESTABLISHMENT?

X3DH is a secure session-establishment model used in modern end-to-end encrypted messaging systems.

In UNDERWORLD, an X3DH-style model allows users to derive shared session material locally without giving the relay access to plaintext secrets.

The model can involve long-term identity keys, ephemeral key agreement, pre-key style initialization, and contact-specific cryptographic binding.

The relay may transport handshake material, but it should not learn the final session secrets.

WHAT IS DOUBLE RATCHET MESSAGING?

Double Ratchet is a secure messaging design where conversation keys evolve as messages are exchanged.

Instead of using one static secret for an entire conversation, the cryptographic state advances over time. This improves forward secrecy, limits the impact of key compromise, and helps the session recover security after state progression where possible.

UNDERWORLD uses this style of model to avoid long-lived static conversation secrets.

WHAT IS MESSAGE-KEY ISOLATION?

Message-key isolation means messages are protected with distinct derived key material.

If one message key were exposed, the design goal is to prevent that exposure from unnecessarily compromising unrelated messages or the entire conversation.

This reduces the blast radius of compromise and supports stronger replay resistance, duplicate-message detection, ratchet-state validation, and tamper handling.

WHAT IS POST-QUANTUM HYBRID DEFENSE?

Post-quantum hybrid defense combines classical cryptographic protection with quantum-resistant security direction.

The purpose is to reduce long-term interception risk, especially store-now-crack-later threats where encrypted traffic captured today may be attacked in the future using more advanced capabilities.

UNDERWORLD’s architecture follows a post-quantum hybrid direction aligned with NSA-published CNSA 2.0 principles for future quantum-resistant security planning.

This does not mean UNDERWORLD is NSA-approved, government-certified, or military-endorsed.

HOW DOES UNDERWORLD ROUTE TRAFFIC?

UNDERWORLD is designed to route communication through anonymity networks such as Tor and I2P where supported.

The routing layer and encryption layer are separate. Encryption protects the message content. Tor and I2P reduce direct network exposure. The relay transports ciphertext. The recipient decrypts locally.

This layered model prevents the relay or network from becoming the only security boundary.

WHAT DOES “CNSA 2.0-ALIGNED” MEAN?

CNSA 2.0 is the U.S. National Security Agency’s published direction for future quantum-resistant protection of National Security Systems.

When UNDERWORLD uses the phrase CNSA 2.0-aligned, it means the architecture follows the direction of modern high-assurance cryptographic planning, especially around post-quantum transition and long-term confidentiality.

Alignment is not certification.

UNDERWORLD does not claim NSA approval, NSA certification, military approval, or government endorsement unless explicitly stated.

DOES UNDERWORLD STORE MESSAGES IN THE CLOUD?

.

UNDERWORLD is designed without cloud message recovery.

Private conversations are not intended to be stored on UNDERWORLD servers as readable content or recoverable cloud backups.

The relay may process encrypted payloads required for delivery, but the relay is designed as ciphertext transport, not as a cloud message archive.

CAN UNDERWORLD RECOVER MY ACCOUNT IF I LOSE MY DEVICE?

UNDERWORLD uses device-bound cryptographic identity.

If the device and local identity material are lost, UNDERWORLD cannot restore the same cryptographic identity from the cloud.

This is deliberate.

A recovery system powerful enough to restore private identity can also become a breach path, coercion target, or legal seizure path.

UNDERWORLD removes that recovery dependency to reduce centralized risk.

DOES UNDERWORLD UPLOAD MY CONTACTS?

UNDERWORLD is designed not to upload the user’s contact list or address book.

Contact upload creates a relationship graph. In high-risk communication, the relationship between two people can be as sensitive as the message itself.

UNDERWORLD avoids centralized contact discovery as a privacy tradeoff.

DOES UNDERWORLD SHOW TYPING INDICATORS, ONLINE STATUS, OR LAST SEEN?

UNDERWORLD avoids social presence signals such as typing indicators, online status, and last-seen markers.

These features may seem harmless in ordinary messaging apps, but they expose behavioral metadata.

In hostile environments, knowing that someone is awake, active, typing, available, or recently online can create risk.

WHAT HAPPENS IF TOR OR I2P IS BLOCKED?

If protected routing is unavailable, UNDERWORLD is designed to fail closed instead of silently downgrading.

The message should not move through plaintext relay, direct internet delivery, or ordinary insecure transport.

For blocked or offline conditions, UNDERWORLD provides Blackout Mode, allowing users to prepare encrypted offline capsules for later controlled transfer.

WHAT IS THE RELAY, AND CAN IT READ MESSAGES?

The relay is the transport component that moves encrypted payloads.

UNDERWORLD treats the relay as untrusted. It should not receive plaintext message content, private keys, cloud backups, recoverable identities, or readable conversation history.

Messages are encrypted before reaching the relay. If the encryption layer is implemented and used correctly, relay compromise should not expose message plaintext.

WHAT DOES “ZERO-KNOWLEDGE RELAY TRANSPORT” MEAN?

In UNDERWORLD, zero-knowledge relay transport means the relay is not trusted with message plaintext or private cryptographic state.

The relay should not know private keys, readable attachments, cloud recovery material, identity secrets, or conversation content.

Its role is limited to moving encrypted payloads without becoming the source of trust.

DOES UNDERWORLD PROTECT METADATA?

UNDERWORLD reduces metadata exposure, but no system can eliminate every possible signal.

The app reduces metadata through no contact upload, no online status, no last-seen markers, no typing indicators, no notification previews, anonymity-network routing, decoy relay traffic, attachment sanitization, no cloud identity recovery, and fail-closed routing.

The objective is to protect not only what is said, but also what can be inferred from the surrounding communication.

WHAT IS DECOY RELAY TRAFFIC?

Decoy relay traffic consists of encrypted payloads that resemble normal relay traffic but do not carry real conversation content.

Even when observers cannot read message content, they may study timing, volume, activity bursts, and message frequency. Decoy traffic adds background encrypted movement, making real communication harder to isolate.

Decoy traffic does not guarantee invisibility. It reduces signal quality.

HOW DOES UNDERWORLD HANDLE ATTACHMENTS?

UNDERWORLD treats attachments as security objects, not simple uploads.

Files may contain GPS coordinates, device identifiers, author fields, embedded thumbnails, file paths, editing history, application metadata, misleading extensions, or dangerous structures.

UNDERWORLD’s attachment-defense model is designed to reduce these risks through metadata sanitization and suspicious file checks, including risky MIME mismatches, oversized payload abuse, path-traversal attempts, malformed attachment packets, dangerous attachment patterns, and metadata deception.

WHAT ARE ACTIVE ATTACK ALARMS?

Active Attack Alarms are warnings generated when UNDERWORLD detects suspicious security conditions.

These may include packet injection attempts, replay behavior, authentication-tag failure, malformed encrypted packets, duplicate message abuse, relay message forgery, identity substitution, ratchet-state anomalies, dangerous attachments, routing downgrade attempts, screen overlay attacks, and obscured-touch events.

Instead of treating every failure as a generic error, UNDERWORLD can classify suspicious events as possible attack indicators.

CAN UNDERWORLD DETECT SPYWARE ON MY PHONE?

Not reliably in every case.

UNDERWORLD can detect certain app-level, protocol-level, routing-level, attachment-level, and interface-level interference conditions.

It cannot reliably detect every form of advanced spyware, hostile firmware, malicious operating-system control, compromised keyboard, external camera recording, or physical surveillance.

No messenger can fully protect a device that is already compromised at a high privilege level.

WHAT IS BLACKOUT MODE?

Blackout Mode is UNDERWORLD’s offline encrypted capsule workflow.

It is designed for conditions where the internet is unavailable, blocked, monitored, or unsafe.

A user can prepare encrypted offline capsules locally and move them later through controlled local carriers such as QR transfer, file transfer, Wi-Fi, Bluetooth, or physical handoff.

The carrier does not receive plaintext. Blackout Mode is manual by design and does not automatically downgrade to unsafe transport.

WHAT IS SILENT WITNESS?

Silent Witness is UNDERWORLD’s protected evidence and reporting layer.

It helps users prepare, sanitize, encrypt, verify, and route sensitive material toward legitimate receiving organizations or Custom Verified Tunnels.

It is designed for journalists, NGOs, legal teams, diplomatic offices, investigators, security personnel, field operators, whistleblower support organizations, and public-interest institutions.

Silent Witness is not a so

WHAT ARE CUSTOM VERIFIED TUNNELS?

Custom Verified Tunnels are organization-specific secure intake paths inside Silent Witness.

A tunnel can define the receiving endpoint, organization identity material, public-key or fingerprint verification, routing policy, evidence-handling instructions, attachment restrictions, safety warnings, channel lock conditions, and fail-closed requirements.

This allows a newsroom, NGO, legal team, embassy, security department, investigative unit, or public-interest organization to receive sensitive material through a hardened verified path instead of relying only on exposed web forms, ordinary email, public upload pages, cloud drives, or unverified contact addresses.

Organizations can request information at:

corporate@underworldmessenger.com