Standard chat vs Secure Link
Standard chats are not end-to-end encrypted. They rely on encrypted network transport and Supabase access controls, but the service can process server-readable message and attachment content. This distinction is important.
Secure Link is an optional manually shared-key mode for selected conversations where the feature is enabled for your account. It derives encryption keys on participant devices from a manually exchanged channel key and secret.
Using Secure Link
- Open the intended conversation.
- Run
/secure on. - Agree on the channel key and secret out of band with your intended recipient; do not share the secret in the same chat.
- Compare the displayed fingerprint using another trusted method before trusting the channel.
- Use
/secure rotateif a secret may be compromised./forgetkeyremoves a locally remembered key.
/secure on
/secure rotate
/forgetkey
What Secure Link does and doesn't do
| Protected | Not protected / limited |
|---|---|
| Message content encrypted locally before it is stored/sent | Conversation participants, timestamps, sizes and some delivery/typing metadata are still visible to infrastructure |
| Secure Link file content encrypted before upload | The server and platforms can observe network/account activity |
| Manually derived, versioned shared-secret encryption | Not Signal Protocol: no automatic Double Ratchet forward secrecy or post-compromise security |
| Generic push body for encrypted packets | Live Morse timing is not covered by Secure Link content E2EE |
COM1's implementation notes identify Argon2id, XChaCha20-Poly1305 and HKDF subkeys. Those details are implementation descriptions, not an independent security certification.
AI, bots and external network requests
Sending text or explicitly tagged media to an AI provider shares that selected content with a third party. Ordinary outgoing HTTP requests contact the destination API. Bot destinations and SSH servers likewise have separate trust boundaries. Secure Link encryption of the chat packet does not mean outside services cannot see content deliberately sent to them.
Losing the secret
If nobody retains the correct shared secret, old Secure Link content may be impossible to decrypt. Keep a secure backup of secrets you need. Also read the full security notes.