Skip to content

End-to-end encrypted team messaging

Your conversations.Your control.

Bring your teams together in a messenger designed to be hosted on your own infrastructure. Encrypted messages and files, authorised devices under your control.

Protection built for today. Cryptography designed to anticipate tomorrow.

  • Encrypted messages and files
  • Designed for self-hosting
  • Hybrid post-quantum key establishment
For your teams

Move your projects forward. Keep a hold on your exchanges.

A conversation to decide, a group to coordinate, a file to move on: LumaChat brings the exchanges of your teams together in an encrypted space.

Day to day

The work moves along inside the conversation.

Every subject finds its place

Direct conversations, groups, threaded replies and topic Streams help you organise the exchanges of the team.

Share your files, encrypted

Files are encrypted on your device before they are sent. Their content stays encrypted in the storage of the server.

Keep a hold on your devices

Link a device with a QR code and manage the authorised ones. Revocation removes access to future exchanges.

Your infrastructure

Your messenger, on your own ground.

LumaChat is designed to be hosted on your own infrastructure. Keep a hold on your communication environment, as close as possible to the requirements of your organisation.

Discuss my project with Cercle Digital

A named counterpart

LumaChat is a Cercle Digital product. One counterpart to build your project around your uses and your requirements.

An instance you administer

Administer the accounts and the settings of your instance. Your organisation defines its own communication environment.

The protections

Confidentiality built into the product.

Preparing for the confidentiality of tomorrow

LumaChat combines classical and post-quantum cryptography for key establishment. An approach designed to anticipate the risk of exchanges being collected today and decrypted later.

Detecting suspicious identities

The application checks a log of identities and devices. Anomalies it detects, such as a substituted identity, can block sending and ask for a verification.

Knowing who takes part

Agents are named participants with explicit permissions. An authorised agent can read the exchanges of the conversations it takes part in.

Letting the protection evolve

The core provides for migration to a stronger cryptographic profile. The tests check, among other things, that a migration to a weaker profile is refused.

The role of the server

Relaying your exchanges, without reading them.

The content stays encrypted

The server keeps messages and files in encrypted form. Acceptance tests inspect the stored data looking for content and keys in the clear.

Limiting the traces that remain

A sealed sender, sizes normalised into buckets and an inventory of the metadata: concrete mechanisms to reduce what is exposed.

Encrypting the backup too

Backups are encrypted on the device before they are transferred. The protection follows your data into its backup.

Understanding the cryptographic profile
LumaChat builds on MLS for group conversations. Key establishment combines X25519 and ML-KEM-768 with X-Wing. Identity objects combine Ed25519 and ML-DSA-65 signatures. The Rust core gathers these mechanisms into one base shared by the native clients and the web.
The engineering

A Rust core. Documented mechanisms.

The same security core

The security core is written in Rust and exposed to the native clients and to the web. That shared base holds the cryptographic mechanisms and the authorisation rules in one place.

Tested security scenarios

The tests cover, among other things, encrypted storage on the server, the detection of substituted identities, and device revocation for future messages.

Access under your control

Verified identities, revocable devices and explicit permissions: the security rules travel with the exchanges of your teams.

Before you begin

How do I build my project with LumaChat?
Contact Cercle Digital to discuss your uses, your infrastructure and what your teams need.
What does hybrid post-quantum mean?
Key establishment combines classical and post-quantum cryptography. The combination aims to anticipate the risks tied to future decryption capabilities.
Where does my infrastructure fit in?
LumaChat is designed for self-hosting. Your project can therefore be built around your own environment and your operational requirements.
Who can read a conversation?
The authorised participants and their devices decrypt the exchanges they receive. An agent added to a conversation becomes a recipient as well. The relay server is not meant to reach the content in the clear.
How do I keep a hold on my devices?
Link your devices with a QR code and manage their permissions. Revocation removes access to future exchanges.
Getting started

Discover the product in three steps.

  1. Discover LumaChat from your browser.

  2. Create your identity on your device.

  3. Invite a correspondent and compare your safety code before you exchange.

The applications

Discover LumaChat on the web.

Discover the web version in your browser, or download the Android package when this instance offers one.

Web application

Opens the client in your browser. Installing it on your system is offered from inside the application, wherever your browser allows it.

Open LumaChat