Forticom

The Signal protocol you already trust, on relay infrastructure you run yourself — sovereign, self-contained and auditable from bootloader to payload.


Domain

Sovereign messaging

Stage

Design-partner pilot

Started

2025

Products

Forticom relay + client


Zero metadata

Nothing logged, not even session headers

Your relays

No shared infrastructure

Boot to payload

One auditable stack

The problem

Most "secure" messaging leaks anyway.

The cryptography in modern messaging can be sound while everything around it is not. Metadata leaks, the servers sit on someone else’s cloud, and the endpoints are trusted without being controlled — all under the label of security.

For defense, diplomacy, boardrooms and journalists, the operator, the infrastructure and the metadata are the exposure. A protocol you trust is worth little if you cannot run it yourself, in a place you control, leaving nothing behind.


The approach

Trusted from the bootloader up.

01

The Signal protocol, kept

Forticom runs the same end-to-end encrypted protocol, privacy-enhanced and container-isolated — no bespoke cryptography and no reduction in the guarantee users already rely on.


02

Relays you run

Self-contained relay infrastructure deploys to your own cloud or bare metal, with no app-store or cloud-push dependency and no shared infrastructure. Private DNS and out-of-band sideband channels let it work offline, behind firewalls, or inside fully isolated enclaves.


03

A hardened root

Built on the SwiftBoot lineage: a trusted kernel, TPM-based keying and per-user hardware identity binding, with the whole stack auditable from bootloader to message payload.


04

Nothing retained

Zero metadata retention — nothing logged, not even session headers — and no third-party trackers, analytics or CDNs. Operational modes span ephemeral, stealth, persistent and broadcast, and the stack integrates with compliance and audit workflows without any third-party SaaS.


Who it is for

Where the metadata is the risk.

Defense operators in air-gapped or contested zones. Enterprise security teams keeping messaging inside a compliance boundary. Diplomatic and NGO field agents in censored regions. Executives and boards. Investigative journalists protecting sources.

Each needs the same thing: relay control, no external dependencies, and no trace left in an app store, a SIM or a cloud log.


Where it stands

A pilot under real conditions.

MilestoneStatusEvidence
Self-contained relay stackRunningDeploys to cloud or bare metal
Signal protocol, container-isolatedRunningIn pilot
SwiftBoot root + TPM keyingIn progressEndpoint hardening
Independent security reviewNext

Figures on this page are targets and internal measurements at proof-of-concept stage. We share the methodology with anyone who wants to run it.


What's next

Review, then production.

The pilot runs to an independent security review of the full stack — bootloader, relay and client — and a first sovereign deployment operated end to end by the party that depends on it.

Forticom spins out of Research ByIQ once a first sovereign deployment is in production.