Cryptographic Architecture & Security Standards

Privacy & Security

Miracal is designed with privacy and security as core principles. Our messaging architecture uses end-to-end encryption and cryptographic device authentication to help protect private communication between users.

ECDH Key ExchangeQR Device LinkingDouble Ratchet Session Security
1

End-to-End Encryption

Miracal uses end-to-end encryption to protect the content of private conversations.

Messages are encrypted before they leave the sender's device and can only be decrypted by an authorized recipient device.

The encryption process is designed so that intermediary systems cannot access the plaintext content of an encrypted message while it is being transmitted.

Protected Content

End-to-end encryption may protect supported communication such as:

Text messages
Images
Videos
Documents
Voice messages
Audio calls
Video calls
Other supported chat content

The exact encryption behavior may vary depending on the communication feature and device.

2

Cryptographic Key Architecture

Miracal uses public-key cryptography to establish secure communication between authorized devices. Each participating device has cryptographic identity material used during the secure communication process.

Public Key

Used as part of the device authentication and key-establishment process with other verified devices.

Private Key

Kept confidential exclusively by the hardware device and never intended to be shared publicly or transmitted.

Session Key Material

Ephemeral symmetric keys derived dynamically to establish protected communication between authorized endpoints.

Private cryptographic material must remain confidential. It should never be manually copied, transmitted or shared with another person.

3

ECDH Key Exchange

Miracal uses Elliptic Curve Diffie-Hellman (ECDH) as part of its secure key-establishment process. ECDH allows two authorized devices to establish shared cryptographic key material without directly transmitting the resulting secret over the network.

High-Level Process:

1. A device generates its cryptographic key pair.
2. The public key can be shared as part of the device-linking process.
3. The corresponding private key remains protected on the originating device.
4. Authorized devices exchange the required public cryptographic information.
5. Both devices independently derive shared key material.
6. The resulting cryptographic material is used to establish protected communication.

The private component of the key pair is never intended to be exposed to another user.

4

QR-Based Device Linking

Miracal supports QR-based authentication for linking a web or additional device to an existing account. The QR code acts as a secure mechanism for initiating the device-linking process.

Linking Flow:

  1. 1. The new device generates the information required for the linking request.
  2. 2. A QR code representing the linking request is displayed.
  3. 3. The user scans the QR code using an already authenticated device.
  4. 4. The existing device verifies the linking request.
  5. 5. Required public cryptographic information is exchanged.
  6. 6. A secure key-establishment process is performed.
  7. 7. The new device becomes an authorized linked device.
  8. 8. Encrypted communication can then be established according to the application's security protocol.

Scanning a QR code alone should not be considered equivalent to exposing a private encryption key.

5

Linked Devices

Linked Devices allows users to access their account from supported additional devices. Every linked device should be treated as a separate trusted endpoint.

Users should regularly review their linked devices and remove devices that they no longer recognize or use.

Device Verification

When linking a device, the application performs authentication and cryptographic verification before establishing the trusted relationship. Only successfully authorized devices should be allowed to participate in protected account communication.

6

Private Key Protection

Private cryptographic keys are security-sensitive credentials. Miracal's security model is designed around keeping private key material under the control of the authorized device.

Users should never:

  • Share a private key with anyone
  • Send a private key through chat messages
  • Upload a private key to an unknown service
  • Paste private key material into support conversations
  • Manually transfer private key material to another person

If private cryptographic material is exposed, the security of the associated device identity may be compromised.

7

Message Encryption

Before a protected message is transmitted, the message content is processed through the application's encryption mechanism.

Conceptual Flow
Plaintext MessageEncryptionEncrypted MessageTransmissionDecryptionPlaintext Message

The encrypted representation is designed to prevent unauthorized parties from directly reading the original message content. The recipient device performs the corresponding decryption operation after the message has been received and successfully authenticated.

8

Message Authentication

Encryption protects confidentiality, while authentication helps protect message integrity and origin.

Miracal can use cryptographic authentication mechanisms to help ensure that encrypted communication has not been modified unexpectedly during transmission.

A message that fails the required cryptographic verification should not be treated as trusted communication.

9

Secure Device Authentication

Device authentication helps establish whether a device is authorized to participate in an account's protected communication.

Authentication may involve:

Account credentials
Verification codes
QR-based device linking
Device identity information
Public cryptographic keys
Cryptographic verification

The exact authentication mechanism depends on the account and device flow being used.

10

Session Security

Secure communication may use session-specific cryptographic material to reduce the exposure associated with long-term keys.

Session keys are intended to protect communication during an established secure session and should not be treated as permanent account credentials.

The application is responsible for managing the lifecycle of session cryptographic material.

11

Chat Privacy

Users can take additional steps to protect conversations on their devices.

Locking sensitive conversations with Chat Lock
Protecting the device with a PIN, passcode, or pattern
Using biometric authentication (Face ID / Fingerprint) where available
Keeping the application updated to the latest release
Reviewing linked devices regularly in Settings
Avoiding accessing chats from untrusted or shared devices

Encryption protects communication, while device security protects the information displayed on the device itself.

12

Disappearing Messages

Disappearing Messages allows supported messages to be automatically removed after a configured period. This feature provides additional control over message retention.

However, disappearing messages should not be considered a guarantee that information can never be retained. A recipient may still be able to capture or reproduce content before it disappears.

13

View Once Media

View Once allows supported media to be shared with limited viewing availability.

Once the supported media has been viewed, it is removed from the normal conversation experience according to the application's implementation.

Users should still avoid sharing highly sensitive information with recipients they do not trust.

14

Block and Report

Users can block unwanted contacts and report suspicious or abusive behavior.

Blocking helps prevent unwanted communication from a selected account.

Reporting provides a mechanism for users to notify the platform about activity that may violate applicable rules or security policies.

15

Account Security

Users are responsible for protecting their account and authentication information.

For better account security:

1. Never share verification codes.
2. Use a strong device password or PIN.
3. Keep the application updated.
4. Review linked devices regularly.
5. Remove devices that are no longer trusted.
6. Do not share private cryptographic keys.
7. Avoid logging into your account on untrusted devices.
16

Security Limitations

End-to-end encryption protects communication content during secure communication, but it does not protect a device that has already been compromised.

For example, if an unauthorized person has access to an unlocked device, they may be able to access information that is already available on that device.

Users should therefore consider both communication security and device security when protecting their account.

17

Privacy by Design

Miracal's security architecture is designed around limiting unnecessary access to private communication. Security measures may include:

End-to-end encryption
Public-key cryptography
ECDH key establishment
Device authentication
Secure device linking
Cryptographic verification
Account security controls
Privacy settings

Security mechanisms are continuously reviewed and improved as the platform evolves.

18

Frequently Asked Questions

Shared Responsibility

Security is a Shared Responsibility

Miracal provides security technologies designed to protect private communication, but users also play an important role in maintaining account security.

Keep your devices secure, protect your authentication information, review linked devices regularly, and never share private cryptographic keys.

© 2026 Miracal. All Rights Reserved.

Powered by Hindustaan Innovations Private Limited.

Raipur, Chhattisgarh - 492001, India