Security and responsible disclosure

Last revised 8 September 2026. No independent audit has been carried out.

No independent security audit of Yapmesh has been carried out yet. The protocol is written down and the core library is public so that one can happen. Until then, treat Yapmesh as promising, not proven.

What Yapmesh protects

  • Content of direct messages, voice notes, private files and calls. Sealed to the recipient's key. After the first reply, a Signal-style Double Ratchet gives forward secrecy and recovery from a compromised session key. Sender authenticity is the frame signature.
  • Content of private and fenced groups. Encrypted with the group's current epoch key; each sender has its own key chain per epoch, so one message key never unlocks the ones before it. Files are encrypted before they are cut into chunks. A member who leaves, is removed, or walks out of a fence never gets the next key.
  • Who is in a group. Membership is a signed roster; a join to a private group needs a proof from the invite secret; an admin's removal is a signed ban.
  • Integrity of everything. Every frame is signed; a forged or altered frame is dropped before it is looked at. Every file chunk is verified against the file's Merkle root before it is stored.
  • The installer. A build received over the mesh is installed only if its signing key matches the running app's.

What Yapmesh does not protect

  • Metadata to a radio neighbour. Any phone in range sees your hello beacon: a display name (empty while you hide), which rungs are up, the app version, the battery level, the names of your direct neighbours, and the highest presence tier you answer at. It sees that frames of a certain size move between certain keys at certain times. Hiding removes your name from the air, not your presence.
  • Traffic analysis. A relay sees sender key, recipient key, hop count and size for every direct frame it carries. Over time, who talks to whom is visible to anyone who stays in range or collects many phones' logs. Yapmesh does not pad, delay or mix traffic.
  • A compromised phone. Malware, a malicious keyboard, or a person holding your unlocked phone sees what you see. The app lock is a door on the phone, not encryption; messages keep arriving and being relayed while it is locked.
  • The Nearby room, the drop zone, SOS and open groups. These are signed and readable by everyone in range, by design. An open group's key is public.
  • The first message to a new contact has forward secrecy only after that contact's first reply.
  • Presence proofs and geo fences. GPS can be spoofed; Yapmesh treats a mock location as outside but cannot detect every spoof. The anchor fence (a radio link to a designated phone, plus a tap or a sound for a room or a table) is the kind to trust in a hospital or an office.
  • Hand-carried rungs. A message sent by SMS is sealed, but your carrier records that you texted that number and when. A message shared through another app is sealed, but that app sees you shared a piece of text.
  • Denial of service. A phone can flood the air with valid-looking frames; quotas and the seen-cache limit the damage but do not remove it. Radio jamming stops everything.
  • Screenshots and copies. Retention and fences remove data from phones that obey the protocol; they cannot stop a member from photographing a screen or a phone tampered with before it left.
  • Loss of the phone. Your key lives only on the phone. There is no recovery; contacts must verify your new key in person.

Cryptography used

Ed25519 signatures; X25519 key agreement with a sealed-box construction; HKDF-SHA256 and HMAC-SHA256 in the Double Ratchet; ChaCha20-Poly1305 for ratchet messages; XChaCha20-Poly1305 with a random 24-byte nonce for group boxes; SHA-256 Merkle trees over 16 KiB chunks; HMAC-SHA256 presence tokens per 15-minute epoch. All from an audited-primitives library; Yapmesh invents no primitives. Details are in the specification, sections 4a, 7, 8, 8a, 8b and 9.

Current build caveats

  • Builds on the developer's desk are signed with a development key. No release-signed build has been published yet; the fingerprint that will be published here must match the app's About screen.
  • Everything marked "built, not yet field-tested" on the home page has passed unit tests and compiled into the app but has not run on real phones.

Reporting a vulnerability

Email hello@yapmesh.com with "Security:" at the start of the subject. Say what you found, how to reproduce it, and which build. You will get a reply within seven days and a fix or a public note within ninety; you are free to publish after ninety days, or earlier once a fix ships, with credit if you want it. Testing against your own phones is welcome; please do not test against other people's phones or run denial-of-service attacks on a live mesh. There is no bug bounty; there is no company, only a public thank-you in the changelog. A PGP key for encrypted reports has not been published yet.

In scope: the protocol specification, the core library, the Android app, the browser client, this website. Out of scope: the Android OS, Google Play Services' Nearby Connections, Bluetooth stacks, and social engineering of people.