Every layer of Trident Secure — from the network to the application — is hardened by design. Here's what's actually in place today, explained plainly.
Every conversation is encrypted before it ever leaves your device, and can only be read by the people inside that conversation — not the server that relays it in between.
One system privately negotiates encryption keys the moment a conversation starts; a second efficiently encrypts ongoing group conversations. Different tools for different jobs — both equally strong.
Encryption keys change on a regular basis, so exposure of any single key doesn't unlock past messages or anything outside that narrow window.
You can confirm that a device claiming to belong to a contact really does, using a short visual comparison between your device and theirs — a simple check that guards against impersonation.
Verify one of a contact's devices, and that trust extends automatically to their other verified devices — no need to repeat the check for every device someone owns.
Message history can be recovered on a new device without your keys ever being exposed to the server in a readable form — the backup itself stays encrypted end-to-end.
Trident Secure runs entirely on infrastructure the organisation controls. Federation with the wider Matrix network is disabled, so messages never leave the organisation's own server.
On top of the end-to-end encryption already in place, all traffic to the server travels over TLS — a second, independent layer of protection for data on the move.
Registration is invite-only. No unknown party can simply sign up — every new account is deliberately admitted.
Files and documents live in their own protected space, separate from messaging, with its own access lock.
Security at Trident Secure isn't finished — it's maintained. Here's what's actively planned to build on the foundation above.
Not yet available. The items below are planned enhancements, not current functionality — they build on the protections already described above.
A stricter mode where only verified devices are able to send or receive encrypted messages at all.
An in-app screen showing your trusted devices, session keys, and cross-signing status at a glance.
A clear, guided setup and recovery flow for key backup, so nobody is left guessing what to do.
Moving Secure Vault toward client-side encryption, unlockable only with a password or recovery key.
A visible marker on each message confirming it was sent and received under encryption.
Organisation-level tools for managing user and device access, as part of the upcoming Admin Portal.
Admin Portal (Coming soon)