Security Overview
Miracal provides an institutional-grade, zero-knowledge communication network engineered from the ground up to protect your privacy through state-of-the-art cryptography.
Default E2EE
Every message, voice note, photo, and call is end-to-end encrypted by default. No opt-in or secret chat mode required.
Zero-Knowledge Cloud
Our servers only route blind ciphertext envelopes. We cannot read plaintext conversations, contact metadata, or media.
Forward Secrecy
Continuous cryptographic ratcheting ensures that a compromised session key never compromises past or future communication.
Cryptographic Protocol & Architecture
Miracal implements a modern end-to-end encryption protocol combining Curve25519, AES-256-GCM, and HMAC-SHA256. These battle-tested primitives ensure state-of-the-art confidentiality, authenticity, and message integrity.
Public-Key Cryptography & ECDH Exchange
Each device creates asymmetric cryptographic key pairs within the operating system's Secure Enclave or Android Keystore:
Long-term curve key uniquely identifying the physical installation.
Medium-term key rotated periodically to establish immediate sessions.
Pool of single-use keys consumed upon initiating first-time sessions.
Secure QR-Based Device Linking
When linking desktop apps or web browsers, Miracal uses ephemeral QR code authentication. The QR code contains an ephemeral public key and verification nonce:
- The secondary device generates a temporary ephemeral Curve25519 key pair and displays a cryptographic QR challenge.
- The primary mobile device scans the QR code using its authenticated camera hardware.
- Biometric authentication (Touch ID, Face ID, or PIN) is required on the phone to approve the link request.
- The primary device encrypts a device-identity payload specifically for the secondary device's public key.
- The secondary device derives an independent session identity without ever gaining access to the primary device's master private key.
Device-Level Safeguards & Chat Lock
Network encryption protects messages in transit, while on-device defenses protect conversations if someone accesses your unlocked phone:
Lock individual threads behind Fingerprint / Face ID authentication.
Automatic local and remote message deletion after 24 hours, 7 days, or 90 days.
Ephemeral media deleted immediately upon inspection with screenshot detection alerts.
SQLCipher database encryption with hardware-backed master salt.
Vulnerability Disclosure & Contact
If you discover a potential vulnerability or security flaw, we appreciate your responsible disclosure. Please do not report security issues via public channels:
security@hindustaan.in
0771-299-4005
Raipur, Chhattisgarh - 492001, India
Frequently Asked Questions
Privacy Guaranteed by Mathematics, Not Promises
We believe private communication is a fundamental human right. Our architecture guarantees that neither our engineers nor third parties can ever access your conversations.