Continuity without contact data
A person should be able to return, receive questions, and answer without first surrendering a conventional identifier.
Open-source application infrastructure Experimental · Themis casework is planned, not live
Build confidential, resilient applications over infrastructure that must not be trusted with plaintext.
For human-rights and civil-society teams, journalists, safeguarding organizations, trusted intermediaries, and the developers who support them.
01 / Boundary Delivery systems move encrypted state. They are not entrusted with application plaintext.
02 / Continuity Sensitive work extends beyond one message: state, evidence, roles, recovery, and follow-up matter.
03 / Evidence Every security and maturity claim is bounded by what the repository can demonstrate today.
Confidentiality is a boundary.
Trust is a system.
Styx is a platform-neutral secure application substrate. It is being designed to combine self-custodied identity, end-to-end-encrypted collaboration, verifiable state transitions, offline operation, and redundant delivery.
Reporting, safeguarding, source protection, and protected coordination need clarification, assignment, receipts, evidence history, retention, recovery, and asynchronous replies. Conventional systems often bind that continuity to identifiers or a central plaintext authority.
Styx separates product policy from application state, secure sessions, and runtime custody. It is infrastructure for applications, not a general-purpose messenger.
Read the public project briefEnd-to-end encryption protects content within a defined threat model. It does not automatically solve identity exposure, durable state, delivery truth, endpoint compromise, metadata, or organizational procedure.
A person should be able to return, receive questions, and answer without first surrendering a conventional identifier.
Cases need verifiable transitions, roles, receipts, deadlines, retention, and recovery—not an ambiguous stream of messages.
Relays can carry encrypted material while still observing metadata. Browsers, endpoints, recipients, and operators remain in the threat model.
No current implementation is intended to be the normative protocol. The language-neutral application protocol and conformance corpus are planned as the authority.
Planned first vertical
Workflow, roles, policy, safety language, and accessible reporter and operator interfaces.
Protocol work planned
Versioned objects, state transitions, causality, evidence, retention, pruning, and conformance.
Foundations exist
Membership, epochs, continuous group key agreement, convergence, and confidential delivery. Marmot is a preferred compatibility target, not a current claim.
Browser foundation exists
Key custody, encrypted storage, workers, notifications, distribution, and platform integration. A future signed native profile could offer stronger origin assurance.
Planned · not yet available
Confidential case intake with a path back to conversation.
A reporter would create a fresh case context and high-entropy return capability locally, submit an encrypted case object, and use that capability later to receive questions and send answers—without an ordinary account.
Organizations would need role-based intake, assignment, rotation, revocation, retention, controlled export, continuity, and minimized administrative audit. Safe deployment also depends on trained handlers, independent escalation routes, legal and privacy review, incident procedures, and tested backups.
Themis targets anonymity or pseudonymity only against declared observers under tested conditions. Network, device, timing, content, and human factors may still identify a reporter.
Explore the anonymous-dialogue use caseImplemented evidence is deliberately separated from Draft and planned work.
Reference evidence
A tested Dart reference ledger covers signed event chains, causal clocks, deterministic merge, offline outbox, retention and recovery. It is not normative or interoperable with the browser stack.
Inspect the reference evidenceBrowser foundation
The JavaScript stack contains a 1:1 MLS reference chat, authenticated QR pairing, Nostr validation, encrypted local custody, and pinned WASM boundaries. Current envelopes still expose metadata.
Review the capability assessmentBounded result
Phase A found that the pinned OpenMLS revision can support a gated Marmot compatibility proof. The current wrapper and wire behavior are not compatible.
Read the Phase A reportThese are proposed engineering outputs, not delivery promises. Each security-sensitive change remains subject to a bounded contract, independent review, exact tests, and human approval.
Define language-neutral objects, transitions, adversarial scenarios, and reusable vectors.
Complete staged-commit safety, hostile tests, and a real independent round trip—or document a NO-GO.
Separate application semantics from chat and make offline, retry, acknowledgement, and recovery states truthful.
Build text-first accountless case intake, return dialogue, operator roles, revocation, retention, and safety UX.
Strengthen browser release controls and decide a future signed native profile with reproducible operations.
Commission independent review, remediate findings, test procedures, and pilot only within an approved scope.
No absolute claims.
The browser profile is weaker against an adversary controlling the web origin. Reproducible WASM does not authenticate every script delivered to a user.
Current delivery exposes routing, timing, size, and relationship information. Additional relays can improve availability while increasing the observer set.
End-to-end encryption does not protect a compromised device, keylogger, screen capture, or content copied by an authorized recipient.
IP addresses, browser fingerprints, writing style, attachments, monitored networks, and colluding infrastructure may identify a person.
Pruning cannot guarantee physical erasure from flash storage, backups, screenshots, or third-party replicas.
Styx has not completed an independent complete-product audit. Upstream review does not transfer to Styx integrations or operations.
Original Styx software and documentation are licensed under AGPL-3.0-or-later. Six exactly enumerated interoperability vector files use Apache-2.0 so independent implementations can reuse that evidence. Third-party components retain their upstream terms.
External code contributions are temporarily paused while contributor terms are defined. Issues, reproducible feedback, and private vulnerability reports remain welcome. Project names and official visual identity are governed separately from source-code permissions.
Evidence before promises
Inspect the architecture, challenge the threat model, reproduce the evidence, or bring a bounded use case. Never include sensitive information in a public Issue.