Open-source application infrastructure Experimental · Themis casework is planned, not live

Secure infrastructure
for sensitive work.

Build confidential, resilient applications over infrastructure that must not be trusted with plaintext.

For human-rights and civil-society teams, journalists, safeguarding organizations, trusted intermediaries, and the developers who support them.

01 / Boundary Delivery systems move encrypted state. They are not entrusted with application plaintext.

02 / Continuity Sensitive work extends beyond one message: state, evidence, roles, recovery, and follow-up matter.

03 / Evidence Every security and maturity claim is bounded by what the repository can demonstrate today.

Confidentiality is a boundary.
Trust is a system.

Sensitive relationships need more than an encrypted message.

Styx is a platform-neutral secure application substrate. It is being designed to combine self-custodied identity, end-to-end-encrypted collaboration, verifiable state transitions, offline operation, and redundant delivery.

Reporting, safeguarding, source protection, and protected coordination need clarification, assignment, receipts, evidence history, retention, recovery, and asynchronous replies. Conventional systems often bind that continuity to identifiers or a central plaintext authority.

Styx separates product policy from application state, secure sessions, and runtime custody. It is infrastructure for applications, not a general-purpose messenger.

Read the public project brief

A secure channel is not yet a safe workflow.

End-to-end encryption protects content within a defined threat model. It does not automatically solve identity exposure, durable state, delivery truth, endpoint compromise, metadata, or organizational procedure.

01

Continuity without contact data

A person should be able to return, receive questions, and answer without first surrendering a conventional identifier.

02

State beyond chat

Cases need verifiable transitions, roles, receipts, deadlines, retention, and recovery—not an ambiguous stream of messages.

03

Infrastructure with limits

Relays can carry encrypted material while still observing metadata. Browsers, endpoints, recipients, and operators remain in the threat model.

Built around the people who carry sensitive responsibility.

  • 01People reporting abuse, harassment, discrimination, wrongdoing, or safeguarding concerns
  • 02Human-rights defenders, journalists, civil-society teams, and trusted intermediaries
  • 03Organizations managing confidential cases with least-privilege roles and continuity
  • 04Developers building casework, evidence, coordination, or other sensitive applications

Product meaning stays separate from cryptographic transport.

No current implementation is intended to be the normative protocol. The language-neutral application protocol and conformance corpus are planned as the authority.

  1. 04

    Planned first vertical

    Themis product experience

    Workflow, roles, policy, safety language, and accessible reporter and operator interfaces.

    Human purpose
  2. 03

    Protocol work planned

    Styx application protocol

    Versioned objects, state transitions, causality, evidence, retention, pruning, and conformance.

    Durable meaning
  3. 02

    Foundations exist

    Secure-session profiles

    Membership, epochs, continuous group key agreement, convergence, and confidential delivery. Marmot is a preferred compatibility target, not a current claim.

    Protected exchange
  4. 01

    Browser foundation exists

    Runtime profiles

    Key custody, encrypted storage, workers, notifications, distribution, and platform integration. A future signed native profile could offer stronger origin assurance.

    Local custody
Read the approved product vision

Planned · not yet available

Themis by Styx

Confidential case intake with a path back to conversation.

A reporter would create a fresh case context and high-entropy return capability locally, submit an encrypted case object, and use that capability later to receive questions and send answers—without an ordinary account.

Organizations would need role-based intake, assignment, rotation, revocation, retention, controlled export, continuity, and minimized administrative audit. Safe deployment also depends on trained handlers, independent escalation routes, legal and privacy review, incident procedures, and tested backups.

Themis targets anonymity or pseudonymity only against declared observers under tested conditions. Network, device, timing, content, and human factors may still identify a reporter.

Explore the anonymous-dialogue use case

Foundations to build on.
Not a finished product.

Implemented evidence is deliberately separated from Draft and planned work.

Reference evidence

Application-state experience

A tested Dart reference ledger covers signed event chains, causal clocks, deterministic merge, offline outbox, retention and recovery. It is not normative or interoperable with the browser stack.

Inspect the reference evidence

Browser foundation

Encrypted session path

The JavaScript stack contains a 1:1 MLS reference chat, authenticated QR pairing, Nostr validation, encrypted local custody, and pinned WASM boundaries. Current envelopes still expose metadata.

Review the capability assessment

Bounded result

Compatibility capability probe

Phase A found that the pinned OpenMLS revision can support a gated Marmot compatibility proof. The current wrapper and wire behavior are not compatible.

Read the Phase A report

From tested foundations to a controlled pilot.

These are proposed engineering outputs, not delivery promises. Each security-sensitive change remains subject to a bounded contract, independent review, exact tests, and human approval.

  1. 01

    Protocol and conformance

    Define language-neutral objects, transitions, adversarial scenarios, and reusable vectors.

  2. 02

    Secure-session decision

    Complete staged-commit safety, hostile tests, and a real independent round trip—or document a NO-GO.

  3. 03

    SDK and reliable delivery

    Separate application semantics from chat and make offline, retry, acknowledgement, and recovery states truthful.

  4. 04

    Themis alpha

    Build text-first accountless case intake, return dialogue, operator roles, revocation, retention, and safety UX.

  5. 05

    Distribution assurance

    Strengthen browser release controls and decide a future signed native profile with reproducible operations.

  6. 06

    Audit and controlled pilot

    Commission independent review, remediate findings, test procedures, and pilot only within an approved scope.

Review milestones and measures

No absolute claims.

Security is a set of declared conditions, not a badge.

Origin

The browser profile is weaker against an adversary controlling the web origin. Reproducible WASM does not authenticate every script delivered to a user.

Metadata

Current delivery exposes routing, timing, size, and relationship information. Additional relays can improve availability while increasing the observer set.

Endpoints

End-to-end encryption does not protect a compromised device, keylogger, screen capture, or content copied by an authorized recipient.

Anonymity

IP addresses, browser fingerprints, writing style, attachments, monitored networks, and colluding infrastructure may identify a person.

Deletion

Pruning cannot guarantee physical erasure from flash storage, backups, screenshots, or third-party replicas.

Assurance

Styx has not completed an independent complete-product audit. Upstream review does not transfer to Styx integrations or operations.

Read all explicit non-claims

Inspectable by design.
Specific about the terms.

Original Styx software and documentation are licensed under AGPL-3.0-or-later. Six exactly enumerated interoperability vector files use Apache-2.0 so independent implementations can reuse that evidence. Third-party components retain their upstream terms.

External code contributions are temporarily paused while contributor terms are defined. Issues, reproducible feedback, and private vulnerability reports remain welcome. Project names and official visual identity are governed separately from source-code permissions.

Evidence before promises

Help make sensitive software worthy of trust.

Inspect the architecture, challenge the threat model, reproduce the evidence, or bring a bounded use case. Never include sensitive information in a public Issue.