Veto · Private messenger

Private messaging without a phone number

Veto is an extreme-privacy messenger: local identity, keys on the device, end-to-end encryption and relays that only see ciphertext. We built the trilingual site and the /app PWA, released as an honest public alpha.

Veto's landing message (no phone number, keys on your device) beside the app's chat interface.
Veto's landing message (no phone number, keys on your device) beside the app's chat interface.
In short

Veto is an extreme-privacy messenger: identity is local, with no phone number, and messages are end-to-end encrypted. We built its trilingual marketing site and the /app PWA, with multi-relay delivery where relays and operators only see ciphertext. It is out as a public alpha and says so on the front page: no production release before an external crypto audit.

Client
Veto · Private messenger
Sector
Privacy and messaging
Deliverables
  • Trilingual marketing site
  • PWA at /app
  • Local identity creation
  • E2E multi-relay architecture
  • Documented readiness gates
0phone numbers required
E2Erelays see ciphertext only
Alphapublic, audit before release
The context

Nobody in the middle reads the messages

The brief for Veto was strict. Scanners, relays and operators should never see plaintext, and nobody should need a phone number or an SMS to join. The security claims also had to be honest: a privacy product that overstates its protection breaks the trust it asks for. The project needed a real product and a clear statement of where it stands.

Design and build

Identity on the device, ciphertext on the relays

We built the /app PWA around one flow. A user creates an identity locally, with no phone number, and the keys stay on the device. A PIN locks the local vault. Each message is encrypted end to end before it leaves the device, then travels through several relays, which, like the operators, only handle ciphertext. The trilingual marketing site presents the product and its security model, and the readiness gates that decide when Veto can ship are documented.

  1. 01

    No phone number

    Joining Veto takes no phone number and no mandatory SMS: the identity is local and the keys live on the device.

  2. 02

    End-to-end, multi-relay

    Messages are end-to-end encrypted, then delivered through several relays. Relays and operators only ever see ciphertext, never the plaintext.

  3. 03

    PIN-protected vault

    The local vault is protected by a PIN: what Veto keeps on the device stays locked until the PIN is entered.

  4. 04

    Documented readiness gates

    Release criteria are written down. The site says it plainly: public alpha, not production-audited, no-go for release until an external crypto audit.

Outcomes

An honest alpha, ready for a crypto audit

Veto is live as a public alpha with a real interface: the marketing site in three languages and the PWA at /app. The privacy narrative is clear and the security claims are honest. The base is ready for an external crypto audit, and the site keeps release readiness at no-go until that audit has taken place.

  • Public alpha: trilingual site and a real app interface
  • Relays and operators see ciphertext only, never plaintext
  • No phone number and no mandatory SMS to join
  • Base ready for an external crypto audit
Talk to Slash

Let's put it in production

Tell us your challenge. We reply within 24 business hours with an honest first read: if we can help, we'll say how; if not, we'll say who can.

I reply personally. No endless forms, no canned replies.

Message Esteban