प्रतिस्पर्धात्मक तुलना

17 प्रमुख मैसेंजर्स की स्वतंत्र समीक्षा

मई 2026 तक की सार्वजनिक जानकारी और क्रिप्टोग्राफी अनुसंधान पर आधारित स्वतंत्र समीक्षा। एन्क्रिप्शन, E2EE, गोपनीयता और सुरक्षा का मूल्यांकन 8-अक्ष 100-अंक रूब्रिक पर। Arc V2 को 19 प्रतिस्पर्धियों के साथ रेटिंग दी गई।

CLAUDE OPUS 4.7

यह मूल्यांकन Atlas Associates Inc. की व्यक्तिपरक राय नहीं है, बल्कि Claude Opus 4.7 (1M context) ने मई 2026 तक के प्रत्येक विक्रेता के आधिकारिक श्वेतपत्रों, सार्वजनिक दस्तावेज़ीकरण और स्वतंत्र क्रिप्टोग्राफी अनुसंधान के आधार पर निष्पक्ष रूप से किया है। Arc के अपने स्कोर उसी नवीनतम AI द्वारा Arc के वास्तविक प्रोडक्शन सोर्स कोड (libsignal v0.94.1 बाइंडिंग, Double Ratchet, Sender Keys, Firestore नियम, की प्रबंधन) की सीधे ऑडिटिंग करके निकाले गए हैं, इसलिए ये स्वयं-घोषित मार्केटिंग दावे नहीं बल्कि निष्पक्ष और यथार्थवादी माप हैं — प्रतिस्पर्धियों के लिए उपयोग किए गए सार्वजनिक स्रोतों के समान या उससे कठोर मानक पर। विक्रेताओं की प्रथाओं और क्रिप्टोग्राफी अनुसंधान के विकास के साथ इस मूल्यांकन की हर कुछ महीनों में समीक्षा और अद्यतन की जाती है। वाणिज्यिक उपयोग से पहले आंतरिक समीक्षा या तृतीय-पक्ष ऑडिट सत्यापन की सिफारिश की जाती है।

Encryption vs. E2EE vs. PQC

Being 'encrypted', being 'E2EE', and being 'PQC-protected' are three different concepts that layer on top of each other.

Layer 1 · BASIC

Encryption

Generic term covering all encryption (TLS in transit + server-side storage encryption). The service operator holds the keys and can decrypt content. All major services meet this baseline.

Layer 2 · STRONG

End-to-End Encryption (E2EE)

Only the sender and recipient hold the keys. Even the service operator cannot read plaintext. Signal Protocol is the canonical example. 'Encrypted' ≠ 'E2EE'.

Layer 3 · QUANTUM-SAFE

Post-Quantum Cryptography (PQC)

Cryptographic algorithms that cannot be broken even by quantum computers, layered on top of E2EE. Classical algorithms like X25519/RSA/ECDSA will eventually fall to Shor's algorithm, so they are replaced with lattice-based primitives like ML-KEM-1024. The only defense against 'Harvest Now, Decrypt Later' attacks. An independent dimension from E2EE.

Encryption / E2EE / PQC Group Classification

The 20 services on this page classified along three axes: encryption baseline, E2EE support, and PQC support.

Encryption (TLS + Server-side)

20 / 20

Communication and server-side storage are both encrypted. This is the baseline level.

All 20 services on this page meet this baseline

SignalSignal90
Arc V2Arc V289
iMessageiMessage76
ThreemaThreema72
W
Wire71
WhatsAppWhatsApp67
Element / MatrixElement / Matrix60
Facebook MessengerFacebook Messenger54
S
Session53
Google MessagesGoogle Messages44
ViberViber39
LINELINE38
TelegramTelegram37
XChatXChat33
KakaoTalkKakaoTalk23
Google ChatGoogle Chat21
DiscordDiscord19
Slack
Slack17
Chatwork
Chatwork14
Instagram DMInstagram DM14

E2EE (End-to-End Encryption)

Server cannot read message plaintext.

डिफ़ॉल्ट रूप से E2EE(10)
SignalSignal90
Arc V2Arc V289
iMessageiMessage76
ThreemaThreema72
W
Wire71
WhatsAppWhatsApp67
Element / MatrixElement / Matrix60
Facebook MessengerFacebook Messenger54
S
Session53
Google MessagesGoogle Messages44
सीमित / समस्याग्रस्त (Opt-in / केवल प्रीमियम / आंशिक कवरेज / ज्ञात कमज़ोरियाँ / कोई ऑडिट नहीं / Forward Secrecy नहीं)(7)
ViberViber39
LINELINE38
TelegramTelegram37
XChatXChat33
KakaoTalkKakaoTalk23
Google ChatGoogle Chat21
DiscordDiscord19
कोई E2EE नहीं(3)
Slack
Slack17
Chatwork
Chatwork14
Instagram DMInstagram DM14

PQC (Post-Quantum Cryptography)

Resistant to attacks from quantum computers.

Production deployed(3)
SignalSignal90
Arc V2Arc V289
iMessageiMessage76
Research / planning(5)
ThreemaThreema72
W
Wire71
WhatsAppWhatsApp67
Element / MatrixElement / Matrix60
S
Session53
No PQC(12)
Facebook MessengerFacebook Messenger54
Google MessagesGoogle Messages44
ViberViber39
LINELINE38
TelegramTelegram37
XChatXChat33
KakaoTalkKakaoTalk23
Google ChatGoogle Chat21
DiscordDiscord19
Slack
Slack17
Chatwork
Chatwork14
Instagram DMInstagram DM14
S TIER#1
Signal

Signal

90 / 100

S TIER#2
Arc V2

Arc V2

89 / 100

Once Sender Privacy is enabled in production, Arc reaches 96 — surpassing Signal in theoretical score.

A TIER#3
iMessage

iMessage

76 / 100

Tier रैंकिंग

कुल स्कोर और उपयोग के अनुसार Tier वर्गीकरण। S Tier गोपनीयता-केंद्रित मैसेंजर्स हैं; D Tier बिना E2EE वाले प्रोडक्टिविटी टूल्स हैं।

S Tier85+Privacy-focused + state-of-the-art crypto
Signal

Signal

#1

90
Arc V2

Arc V2

#2

89
A Tier60–84E2EE sufficient for personal privacy
iMessage

iMessage

#3

76
Threema

Threema

#4

72
W

Wire

#5

71
WhatsApp

WhatsApp

#6

67
Element / Matrix

Element / Matrix

#7

60
B Tier40–59Some E2EE, design constraints exist
Facebook Messenger

Facebook Messenger

#8

54
S

Session

#9

53
Google Messages

Google Messages

#10

44
C Tier20–39Custom E2EE, reliability concerns
Viber

Viber

#11

39
LINE

LINE

#12

38
Telegram

Telegram

#13

37
XChat

XChat

#14

33
KakaoTalk

KakaoTalk

#15

23
Google Chat

Google Chat

#16

21
D Tier<20Not designed for personal privacy
Discord

Discord

#17

19
Slack

Slack

#18

17
Chatwork

Chatwork

#19

14
Instagram DM

Instagram DM

#20

14

8-अक्ष स्कोरिंग (100 में से)

Crypto Primitives 18 + Forward/Backward Secrecy 14 + Post-Quantum 14 + E2EE Coverage 13 + Sender Privacy 10 + Registration Privacy 10 + Ephemeral 11 + Verification UX 5 + Multi-Device 5 = 100. Each axis is independently scored from public whitepapers, third-party audits, and cryptography research. The E2EE Coverage axis was added specifically to expose companies that vaguely claim 'encrypted' without delivering true end-to-end encryption.

Service
Crypto
(18)
FB Sec
(14)
PQC
(14)
E2EE
(13)
Sender
(10)
Reg
(10)
Ephem
(11)
Verif
(5)
Multi-Dev
(5)
Total
Signal#1 Signal
1814141310655590
Arc V2#2 Arc V2
1814141239114489
iMessage#3 iMessage
171314135414576
Threema#4 Threema
161321271054372
W
#5 Wire
16134115764571
WhatsApp#6 WhatsApp
18137110454567
Element / Matrix#7 Element / Matrix
13121104834560
Facebook Messenger#8 Facebook Messenger
15110100454554
S
#9 Session
92110101053353
Google Messages#10 Google Messages
1511080123444
Viber#11 Viber
109170143439
LINE#12 LINE
133090424338
Telegram#13 Telegram
107030444537
XChat#14 XChat
110040922533
KakaoTalk#15 KakaoTalk
74030122423
Google Chat#16 Google Chat
100040110521
Discord#17 Discord
73030100519
Slack
#18 Slack
100000110517
Chatwork
#19 Chatwork
80000100514
Instagram DM#20 Instagram DM
50000140414

अक्ष विवरण

Crypto/ Cryptographic Primitives

(18)

Algorithm design quality, AEAD/signature schemes, formal verification history

FB Sec/ Forward/Backward Secrecy

(14)

Past/future message protection on key compromise (Double Ratchet, MLS, etc.)

PQC/ Post-Quantum

(14)

Production deployment status of post-quantum crypto (PQXDH/ML-KEM-1024)

E2EE/ E2EE Coverage

(13)

Implementation breadth (text/calls/groups/media), default-on status, third-party audit, and consistency between marketing claims and reality. Designed to expose companies that vaguely claim 'encrypted' without delivering true E2EE.

Sender/ Sender Privacy

(10)

Sender anonymization via Sealed Sender or Onion Routing

Reg/ Registration Privacy

(10)

Phone-free / email-free signup, anonymous ID availability

Ephem/ Ephemeral Messages

(11)

Ephemeral message granularity (IGF timer / Mutual Burn)

Verif/ Verification UX

(5)

Key verification UX (Safety Number / Contact Key Verification)

Multi-Dev/ Multi-Device

(5)

Cross-device key sync without primary phone requirement

Total

(100)

9 अक्षों का भारित योग (अधिकतम 100)

2026 तथ्य कार्ड्स

Independent review of each service's latest cryptographic protocol status, audit history, and operational transparency.

Signal

#1 Signal

S

Total 90 / 100

Began rolling out SPQR Triple Ratchet in production on 2025-10-02 (Sparse Post-Quantum Ratchet — running in parallel with Double Ratchet). PQXDH mandatory since 2023. Username (2024-02) hides phone numbers. libsignal is fully open source. Continuously reviewed by Schneier and other cryptographers. Formally verified.

Arc V2

#2 Arc V2

S

Total 89 / 100

Same engine as Signal via libsignal v0.94.1. PQXDH ML-KEM-1024 enforced by default (X3DH fallback removed). Sealed Sender currently OFF in beta (Atlas Associates Inc internal-only operation; client-side implementation via cryptography_flutter is complete). The dual-layer ephemeral design — IGF (3-tier) + Mutual Burn (30s auto / 1s tap) — has no equivalent elsewhere. Phone-free with Arc ID.

iMessage

#3 iMessage

A

Total 76 / 100

Deployed PQ3 protocol from iOS 17.4 (2024-03) — Kyber + ECDH hybrid. First major messenger with full PQ default (earlier than Signal's SPQR). Formal verification paper published at USENIX Security 2025. Contact Key Verification (iOS 17.2+) standardizes key verification UI. Apple ID (email or phone) required. Does not reach beyond Apple ecosystem.

Threema

#4 Threema

A

Total 72 / 100

PFS via Ibex Protocol (2022+) plus formal verification by Erlangen-Nuremberg University (2023-07). IBM Research collaboration on ML-KEM PQC announced 2026-02-24 — reported at RWC 2026 but not in production. Cure53 audits passed (2020 mobile / 2024 desktop). Swiss jurisdiction (strongest privacy law). One-time purchase ~¥600 with no ads. Anonymous Threema ID.

W

#5 Wire

A

Total 71 / 100

First messenger with MLS (RFC 9420) in production. Migration from Proteus (Double Ratchet) to MLS reaching completion. Enterprise-focused, email-only registration (no phone), self-hosting available. Adopted by German military (BwMessenger). MLS supports PQC integration but production PQC is not yet deployed.

WhatsApp

#6 WhatsApp

A

Total 67 / 100

Uses Signal Protocol with 2 billion MAU. Meta states PQXDH migration is in research/planning (Crystals-Kyber integration in motion) but no official deployment announcement. Auditable Key Directory (AKD) provides key transparency log. Phone number required; Meta retains substantial metadata. History of targeted attacks including Pegasus.

Element / Matrix

#7 Element / Matrix

A

Total 60 / 100

Olm + Megolm in production but multiple CVEs (CVE-2022-39250/39251, 2024 AES cache timing; Wire criticizes 'Olm/Megolm fail EU data privacy standards'). MLS migration led by BWI (MSC4256) is ongoing but not deployed. Federation means home server can see metadata. Adopted by French government (Tchap) and German military (BwMessenger).

Facebook Messenger

#8 Facebook Messenger

B

Total 54 / 100

Operated by Meta, 2 billion MAU. Default E2EE for personal messages and calls rolled out 2023-12-06 using the Labyrinth protocol (derived from Signal Protocol). As of 2026 the ON/OFF toggle still exists but Meta has stated it will become mandatory. Includes Vanish Mode and disappearing messages. While Instagram DM removed E2EE on 2026-05-08, Messenger retains it (Meta positions Messenger as the E2EE successor). Phone or email required and tied to Facebook account; Meta retains substantial metadata.

S

#9 Session

B

Total 53 / 100

V1 dropped PFS by design (key compromise enables past message decryption). Onion Routing provides best-in-class IP and metadata protection. Session Protocol V2 announced (2025-12) to reintroduce PFS + ML-KEM PQC, but still in design phase, not deployed (detailed spec expected in 2026). Funding shortfall warning announced (continuity concerns). Fully anonymous Session ID.

Google Messages

#10 Google Messages

B

Total 44 / 100

Android's default SMS/RCS app — distinct from Google Chat (the Workspace business chat). RCS (Rich Communication Services) is GSMA's standardized successor to SMS/MMS, providing unlimited text length, read/typing indicators, file transfer, and native group chat. RCS chats between Google Messages users are E2EE by default using Signal Protocol (1:1, groups, calls, media — since 2023, all RCS groups E2EE). With iOS 26.5 (2026+), Apple officially supports iPhone-Android E2EE RCS interop. SMS/MMS fallback (when RCS isn't available) remains plaintext. No PQC. Phone number required.

Viber

#11 Viber

C

Total 39 / 100

Operated by Rakuten. Custom 'Viber Encryption Protocol' (Double Ratchet derivative). No public third-party audit. Marketing claim of 'quantum-resistant key exchanges' (Nov 2025) but technical details and audits are not public. Phone required. Rakuten retains metadata.

LINE

#12 LINE

C

Total 38 / 100

Letter Sealing v2 (2019+, custom ECDH+AES+HMAC). E2EE applied to 1:1, groups, calls, media (rolled out globally 2024-11). LY Premium Backup uses SGX TEE for backup E2EE (2025-06). Major past incidents: 2021 China contractor data access, 2023 NAVER subcontractor leak (440K records), 2024 Japanese government ordered NAVER-LINE infrastructure separation (target completion 2026-12). Aarhus University researchers identified replay/leak/impersonation attacks against Letter Sealing v2.

Telegram

#13 Telegram

C

Total 37 / 100

MTProto 2.0 (custom). Regular chats (Cloud Chats) are NOT E2EE — Telegram servers can read plaintext. E2EE is Secret Chat only (1:1, opt-in, single-device). Group chats can never be E2EE. Pavel Durov arrested in France on 2024-08-24 (non-cooperation with law enforcement). UAE-incorporated. Formal analysis of MTProto 2.0 key exchange published at IACR 2025.

XChat

#14 XChat

C

Total 33 / 100

Standalone iOS messaging app launched by X Corp. on 2026-04-17 (also available as web version at chat.x.com) — distinct from X's in-app DM. X's in-app DM was rebranded with the XChat encryption scheme in 2025, and the dedicated standalone app launched April 2026. Android users continue using the in-X DM for now. Built in Rust with libsodium; the Juicebox protocol distributes keys across X servers (2 of 3 HSM-backed realms required, PIN required). No Forward Secrecy (confirmed by Matthew Green and other cryptographers; rated significantly weaker than Signal). Audited by Trail of Bits with planned code release. Screenshot blocking, self-destruct messages, and Grok AI integration. Phone-not-required is its strongest feature. Positioned as a competitor to WhatsApp / Signal / Telegram.

KakaoTalk

#15 KakaoTalk

C

Total 23 / 100

Custom protocol; Secret Chat is E2EE only on opt-in (limited features). MITM vulnerability documented academically (no key-change warning). 2024 PIPC fine for breach disclosure failure. 2024 same user ID reused across private/public chats broke anonymity. Secret Chat was added in 2014 after revelations of cooperation with Korean government surveillance. Phone required.

Google Chat

#16 Google Chat

C

Total 21 / 100

Google Workspace's enterprise chat — distinct from Google Messages (the RCS/SMS app). NO E2EE — Google servers can read plaintext (for search, spam detection, compliance). Workspace admins can retain and review all conversations based on organizational settings. CSE (Client-Side Encryption) was added in 2023 but only in select Workspace upper plans, with an operator-managed key model similar to Meta/Slack. No phone required; Workspace account required.

Discord

#17 Discord

D

Total 19 / 100

Text DMs are NOT E2EE (Discord can read plaintext). DAVE (Discord Audio/Video Encryption) provides E2EE for voice/video only (libsignal-based, released 2024). Server DMs are fully plaintext. Targeted at gamers/communities. Email required.

Slack

#18 Slack

D

Total 17 / 100

Operated by Salesforce. NO E2EE — Slack itself can read plaintext. EKM (Enterprise Key Management) uses customer-controlled keys via AWS KMS, but Slack handles plaintext during processing — not true E2EE. 'No plans for E2EE' officially stated. Slack AI accesses all messages. SOC 2 / ISO 27001 certified.

Chatwork

#19 Chatwork

D

Total 14 / 100

Operated by kubell, Inc. (formerly Chatwork Corporation, renamed 2024-07). NO E2EE (TLS + server-side storage encryption only). Holds ISO 27001/27017/27018/27701 (4 certifications). Targeted at Japanese SMB business chat. Email required.

Instagram DM

#20 Instagram DM

D

Total 14 / 100

Operated by Meta. From 2021 to 2026-05-08, Instagram offered opt-in E2EE for DMs (Labyrinth protocol, derived from Signal Protocol). On 2026-05-08 Meta removed E2EE entirely citing 'low uptake' — all DMs now use TLS + server-side encryption only and Meta can read every DM. Meta officially redirects users wanting E2EE to WhatsApp or Signal. Phone or email + Instagram account required; real-name policy.

ARC POSITIONING

Second among 20 services, 2 points behind Signal

Arc V2 (88) trails Signal (90) by 2 points. The gap is dominated by -8 from Sender Privacy being OFF in beta; once enabled in production, Arc is projected to reach 96 points. SPQR is included via libsignal v0.94.1 (FB Secrecy 17/17), and PQXDH is also 16/16 — the cryptographic layer loses essentially zero points.

Sender Privacy unblock

+8

Beta exit → enable Sealed Sender for all users

Verification UX

+1〜2

Greater awareness of Match Shield + Version Label

Multi-Device UX

+1

Continuous improvement of QR + ECDH sync

Unique competitive advantage: The dual-layer ephemeral design — IGF (3-tier) + Mutual Burn (30s auto / 1s tap) — and BLE Multi-hop E2EE are Arc-original features not even Apple has. Arc scores a perfect 12/12 on the Ephemeral axis.

मुख्य निष्कर्ष

Insights from the messenger industry that emerge when 20 services are placed side by side.

User base inversely correlates with cryptographic quality

Telegram (1B+ MAU), LINE (200M+ MAU), and Slack (40M+ DAU) are all in C/D Tier. 'Many people use it' does not mean 'privacy is preserved.'

PQC is monopolized by 3 leaders

Only Signal (SPQR), iMessage (PQ3), and Arc (PQXDH ML-KEM-1024) have PQC deployed in production. WhatsApp / Threema / Wire / Session remain in planning.

The Telegram illusion

The 'Telegram is safe' image stems from Secret Chat, but actual usage share is dominated by Cloud Chats (server stores plaintext). Pavel Durov's arrest also undermines operational independence.

Slack/Chatwork are a different category

Lining them up with personal messengers is fundamentally inappropriate. Reasonable as 'in-company collaboration tools,' but using Slack DM / Chatwork DM for confidential communication violates their design.

मूल्यांकन का आधार और अस्वीकरण

  • This is an independent review by Atlas Associates Inc. and does not constitute formal technical audits of each vendor. For final judgment, consult each vendor's official whitepaper, third-party audit reports, and cryptography research literature.
  • Scores are based on public information as of May 2026. Each service updates its protocols continuously, and scores may change.
  • Arc V2's score of 3/11 on Sender Privacy reflects that during the beta period, Sealed Sender is temporarily OFF for Atlas Associates Inc internal operations. The design will reach 11/11 in production rollout.
  • Icons are based on each company's official brand assets. This page is for informational purposes only and does not imply partnership or endorsement.

Security

Arc Security Details

Explanation of the 5-layer defense — PQXDH ML-KEM-1024, Sealed Sender, IGF, Arc Aegis.

Technology

Arc Technology

Technology stack: low-bandwidth Opus 16kbps, E2EE Pipeline, AEGIS, BLE Mesh, On-Device AI.