Arc / SECURITY

สถาปัตยกรรม E2EE หลายชั้น

ผลิตภัณฑ์ความปลอดภัยเชิงพาณิชย์ที่เผยแพร่ทิศทางวิศวกรรม

ILLUSTRATED 1:1 FLOW · 10-SECOND PREVIEW

Encrypted here.Opened there.

A message between people. Private keys stay on the devices; servers carry ciphertext and delivery data.

  1. 01
    Encrypt on device

    The message is encrypted before it leaves.

  2. 02
    Transport ciphertext

    Firestore carries ciphertext and delivery data.

  3. 03
    Open on device

    The recipient’s device decrypts the message.

FunctionsExpiry & notifications
FCMPush notification

Concept animation of one delivery path, not a recording of the app. Other paths, server-visible metadata and exceptions are documented below.

ARCHITECTURE

Arc system architecture

Explore the system diagram

Private keys are stored in the device Keychain / Keystore and never sent to servers. Messages to other people are encrypted on the device before they are sent. Phoenix hands out public PreKeys, Firestore carries ciphertext, receipts and delivery data, and Cloud Functions handle expiry deletion and notifications. Mesh bypasses servers.

One role at a time.

Open full-size diagram

Devices (iOS / Android / macOS)

Arc Protocol

1:1 · libsignal v0.96.2 · Rust FFI

  • PQXDH
  • Kyber-1024
  • Double Ratchet
Private keys
Keychain / Keystore
Decrypted text
SQLite / Hive

Message text and private keys never go to servers (except AI chats, link previews)

Explore the message flows

The dots move in the numbered order. On each of these paths, message text is encrypted on the device before it is sent.

Follow one path at a time.

Open full-size diagram
1:1 message. Post-quantum. First time: fetch B's keys. Encrypt on the device. Send ciphertext only. Notify (no content). Decrypt on B's device. Read / decrypt receipts. Only A's and B's devices can read the text

Post-quantum

1:1 message

  1. First time: fetch B's keys
  2. Encrypt on the device
  3. Send ciphertext only
  4. Notify (no content)
  5. Decrypt on B's device
  6. Read / decrypt receipts

Only A's and B's devices can read the text

On smaller screens, scroll within the diagram. Open the original using the link above.

1:1 is post-quantum (PQXDH). Group messages are not (shared key + X25519 ECIES). On Mesh, nearby Arc phones may forward the ciphertext without being able to read it. Routed relay is in development.

Arc Protocol — 1:1 encryption pipeline

Phase 1

PQXDH

Key agreement with X25519 + Kyber-1024 (post-quantum)

Phase 2

Double Ratchet

A new key for every message

Phase 3

AES-256-GCM

Encrypts message bodies and media

Technology stack

Flutter 3.44
Dart
Riverpod 2.6
Rust
Arc Protocol

App

Flutter 3.44 / Riverpod 2.6 / Rust FFI (libsignal v0.96.2)

Elixir
Phoenix
Cloud Run

Key distribution API

Elixir / Phoenix on Google Cloud Run (europe-west1)

Authentication
Firestore
Storage
Functions
Messaging
App Check
Crashlytics

Delivery and auth

Firebase (Auth / Firestore / Storage / Functions / FCM / App Check / Crashlytics)

Android
Kotlin
Swift

Mesh

BLE implementation (Dart + Android Kotlin + iOS Swift, in-house, beta)

Technical specifications

The four encryption layers

Arc core specification

Arc's core specification is ML-KEM-1024/PQXDH, E2EE for 1:1 and group chats, IGF, and offline Mesh. This Security page documents the scope and technical details.

01

PQXDH Key Exchange

ผลิตภัณฑ์ความปลอดภัยเชิงพาณิชย์ที่เผยแพร่ทิศทางวิศวกรรม

02

Double Ratchet

ผลิตภัณฑ์ความปลอดภัยเชิงพาณิชย์ที่เผยแพร่ทิศทางวิศวกรรม

03

AES-256-GCM Encryption

ผลิตภัณฑ์ความปลอดภัยเชิงพาณิชย์ที่เผยแพร่ทิศทางวิศวกรรม

04

ลายเซ็น XEdDSA (libsignal)

ผลิตภัณฑ์ความปลอดภัยเชิงพาณิชย์ที่เผยแพร่ทิศทางวิศวกรรม

พารามิเตอร์ ML-KEM-1024

POST-QUANTUM

กลไกการห่อหุ้มคีย์โพสต์ควอนตัมที่ได้มาตรฐาน NIST FIPS 203

อัลกอริทึมML-KEM-1024 (via libsignal-client)
ระดับความปลอดภัย NISTSecurity category 5
ความปลอดภัยแบบคลาสสิก2^128 bit (X25519)
ความปลอดภัยควอนตัมNIST security category 5
พื้นฐานModule Lattice (FIPS 203)
ขนาดคีย์สาธารณะ1,568 bytes
ขนาดคีย์ลับ3,168 bytes
ขนาดข้อความเข้ารหัส1,568 bytes

การปฏิบัติตามกฎระเบียบ & มาตรฐาน

NIST CSF 2.0

กรอบงาน NIST 6 ฟังก์ชันจัดการความเสี่ยงทางไซเบอร์อย่างเป็นระบบ

NIST SP 800-53

การควบคุมความปลอดภัยระดับสหพันธ์ พื้นฐาน FedRAMP

FIPS 140-3

ผลิตภัณฑ์ความปลอดภัยเชิงพาณิชย์ที่เผยแพร่ทิศทางวิศวกรรม

NIST SP 800-175B

คู่มือการเลือกอัลกอริทึมการเข้ารหัส อ้างอิง FIPS 203

ISO/IEC 27001

การรับรอง ISMS ระดับสากล พื้นฐานความไว้วางใจ B2B/B2G

GDPR

กฎระเบียบคุ้มครองข้อมูลทั่วไปของ EU มาตรฐานการคุ้มครองสูงสุดของโลก

UK Cyber Essentials+

การรับรองความปลอดภัยทางไซเบอร์ที่ได้รับอนุมัติจากรัฐบาลอังกฤษ

NCSC Cloud Security

14 หลักการ NCSC อังกฤษ มาตรฐานประเมินความปลอดภัยบนคลาวด์

ออกแบบโดยอ้างอิงแนวทางที่เผยแพร่โดย NIST สหรัฐฯ, GDPR สหภาพยุโรป, NCSC สหราชอาณาจักร และ ISO ข้อความนี้ไม่ใช่การรับรองหรือการตรวจสอบโดยบุคคลที่สาม