Cryptographic Architecture & Endpoint Standards

Security Overview

Miracal provides an institutional-grade, zero-knowledge communication network engineered from the ground up to protect your privacy through state-of-the-art cryptography.

Signal Protocol E2EEECDH Curve25519 KeysZero-Knowledge Architecture

Default E2EE

Every message, voice note, photo, and call is end-to-end encrypted by default. No opt-in or secret chat mode required.

Zero-Knowledge Cloud

Our servers only route blind ciphertext envelopes. We cannot read plaintext conversations, contact metadata, or media.

Forward Secrecy

Continuous cryptographic ratcheting ensures that a compromised session key never compromises past or future communication.

1

Cryptographic Protocol & Architecture

Miracal implements a modern end-to-end encryption protocol combining Curve25519, AES-256-GCM, and HMAC-SHA256. These battle-tested primitives ensure state-of-the-art confidentiality, authenticity, and message integrity.

Message Lifecycle Flow
Sender PlaintextLocal Ratchet EncryptionBlind TLS TransitRecipient DecryptionVerified Display
2

Public-Key Cryptography & ECDH Exchange

Each device creates asymmetric cryptographic key pairs within the operating system's Secure Enclave or Android Keystore:

Identity Key

Long-term curve key uniquely identifying the physical installation.

Signed Prekey

Medium-term key rotated periodically to establish immediate sessions.

One-Time Prekeys

Pool of single-use keys consumed upon initiating first-time sessions.

3

Secure QR-Based Device Linking

When linking desktop apps or web browsers, Miracal uses ephemeral QR code authentication. The QR code contains an ephemeral public key and verification nonce:

  1. The secondary device generates a temporary ephemeral Curve25519 key pair and displays a cryptographic QR challenge.
  2. The primary mobile device scans the QR code using its authenticated camera hardware.
  3. Biometric authentication (Touch ID, Face ID, or PIN) is required on the phone to approve the link request.
  4. The primary device encrypts a device-identity payload specifically for the secondary device's public key.
  5. The secondary device derives an independent session identity without ever gaining access to the primary device's master private key.
4

Device-Level Safeguards & Chat Lock

Network encryption protects messages in transit, while on-device defenses protect conversations if someone accesses your unlocked phone:

Biometric Chat Lock

Lock individual threads behind Fingerprint / Face ID authentication.

Disappearing Messages

Automatic local and remote message deletion after 24 hours, 7 days, or 90 days.

View Once Media

Ephemeral media deleted immediately upon inspection with screenshot detection alerts.

Encrypted Local Database

SQLCipher database encryption with hardware-backed master salt.

5

Vulnerability Disclosure & Contact

If you discover a potential vulnerability or security flaw, we appreciate your responsible disclosure. Please do not report security issues via public channels:

Security Operations

security@hindustaan.in

Urgent Helpline

0771-299-4005

Security Engineering Lab

Raipur, Chhattisgarh - 492001, India

6

Frequently Asked Questions

Cryptographic Verifiability

Privacy Guaranteed by Mathematics, Not Promises

We believe private communication is a fundamental human right. Our architecture guarantees that neither our engineers nor third parties can ever access your conversations.

© 2026 Miracal. All Rights Reserved.

Powered by Hindustaan Innovations Private Limited.

Raipur, Chhattisgarh - 492001, India