Product and review state
VENTEX Connect is operated as a controlled production release. The documented delivery includes a web application, installable PWA and API-first architecture.
This designation is the current public product state. Earlier maturity labels no longer describe the release available today.
This overview is a technical product description. It is neither a certification nor an external audit report and does not claim equivalence with classified communication systems.
The internal state re-run on 9 September 2026 covers 308 mapped counter-tests and 19 real-browser runs with 189 checks. A check that cannot execute is recorded as open, not passed.
- Controlled Production Release before General Availability
- Web, PWA and API-first delivery
- No external security certification
- No absolute security claim
Public security principles
Devices, sessions and revocation are visible security objects. Protected messages and attachments are processed on authorised endpoints; the service is designed not to treat content as conveniently usable plaintext.
For capable devices, a controlled hybrid PQXDH session setup combining X25519 and ML-KEM-1024 has been active since 6 September 2026. The resulting secret initialises the subsequent Double Ratchet; this is not a continuously post-quantum-secure ratchet.
If a participating device does not yet support this path, the documented versioned compatibility path applies. Once version 3 has succeeded, a device-pair downgrade guard prevents a silent return to an older version.
The architecture is informed by published Signal principles, but is independently implemented, not Signal-compatible and not equivalent to libsignal. Detailed protocol mappings, test vectors and implementation evidence are made available only within expressly agreed confidential reviews or audits.
Public claims are limited to the maturity supported by repository evidence, tests or approved runtime evidence.
- Devices as a controllable boundary
- Content protection before transport trust
- Hybrid PQXDH session setup for capable devices
- Evidence before claims
- Explicit separation of production-deployed, controlled-release and planned
Threats and boundaries
The current model considers stolen credentials, lost devices, unauthorised API calls, compromised transport and an inquisitive service operator.
A fully compromised endpoint, coerced use, hardware side channels and unknown platform flaws remain outside the claimed protection boundary.
Assurance roadmap
Automated quality gates, browser checks and release records reduce defects but do not replace independent review.
High-security, government or certification claims require a scoped architecture review, penetration test and independent cryptography audit.
