How Trident Secure
Protects You

Every layer of Trident Secure — from the network to the application — is hardened by design. Here's what's actually in place today, explained plainly.

End-to-End Encryption by Default

Every conversation is encrypted before it ever leaves your device, and can only be read by the people inside that conversation — not the server that relays it in between.

Two-Layer Key Exchange

One system privately negotiates encryption keys the moment a conversation starts; a second efficiently encrypts ongoing group conversations. Different tools for different jobs — both equally strong.

Forward Secrecy Through Key Rotation

Encryption keys change on a regular basis, so exposure of any single key doesn't unlock past messages or anything outside that narrow window.

Device Verification

You can confirm that a device claiming to belong to a contact really does, using a short visual comparison between your device and theirs — a simple check that guards against impersonation.

Cross-Signing

Verify one of a contact's devices, and that trust extends automatically to their other verified devices — no need to repeat the check for every device someone owns.

Encrypted Key Backup

Message history can be recovered on a new device without your keys ever being exposed to the server in a readable form — the backup itself stays encrypted end-to-end.

Sovereign, Self-Hosted Infrastructure

Trident Secure runs entirely on infrastructure the organisation controls. Federation with the wider Matrix network is disabled, so messages never leave the organisation's own server.

Encrypted in Transit, Too

On top of the end-to-end encryption already in place, all traffic to the server travels over TLS — a second, independent layer of protection for data on the move.

Controlled Membership

Registration is invite-only. No unknown party can simply sign up — every new account is deliberately admitted.

A Separate Vault for Files

Files and documents live in their own protected space, separate from messaging, with its own access lock.

E2EE
Every conversation encrypted by default
0
External federation — completely isolated
Self-
Hosted
100% organisation-controlled infrastructure

What's Coming Next

Security at Trident Secure isn't finished — it's maintained. Here's what's actively planned to build on the foundation above.

Not yet available. The items below are planned enhancements, not current functionality — they build on the protections already described above.

01 Planned

Verified-Devices-Only Messaging

A stricter mode where only verified devices are able to send or receive encrypted messages at all.

02 Planned

Visual Security Settings

An in-app screen showing your trusted devices, session keys, and cross-signing status at a glance.

03 Planned

Guided Key Backup & Recovery

A clear, guided setup and recovery flow for key backup, so nobody is left guessing what to do.

04 Planned

Vault Encryption Upgrade

Moving Secure Vault toward client-side encryption, unlockable only with a password or recovery key.

05 Planned

Per-Message Encryption Indicators

A visible marker on each message confirming it was sent and received under encryption.

06 Planned

Administrative Controls

Organisation-level tools for managing user and device access, as part of the upcoming Admin Portal.

Admin Portal (Coming soon)
Trident Secure logo
Trident Assist
Online
AI

Ask Trident Assist

Tap a question or type your own