Security
How Disckreet keeps what you share private
Disckreet locks your content on your phone before it is sent, we cannot read it, and you stay in control of it after your partner has it. Here is exactly how it works, and where the limits are.
The short version
- Everything you send is encrypted on your phone before it leaves.
- We hold only scrambled data, and we do not have the keys.
- You can hide it from your partner's screen, or delete it from their phone, at any time.
- No app can stop everything, so we tell you what we cannot control.
Encrypted before it leaves your phone
Messages, photos and videos are encrypted on your device with AES-256. Your private key is created on your phone and never leaves it in a form we can read. Photos and videos use authenticated encryption (AES-256-GCM), so any tampering is detected. Our servers only ever hold the scrambled version. Photos and videos are removed from our servers once your partner has them. Anything left unopened is deleted after 30 days, and we warn the sender at 27 days.
You stay in control
Hide.
One switch turns everything you have shared into a locked tile on your partner's screen. Your partner can only open your content using key material that you control.
Delete.
Delete something you sent and it is removed from your partner's phone as well as yours.
Unlink.
End the connection and shared content is removed from both phones.
Protected on your phone
PIN and Face ID.
A six-digit PIN. After three wrong attempts the app makes you wait, and the wait grows with each further mistake. Nothing is wiped and you are never locked out for good. The app locks itself when you leave it. Face ID is optional, and it never runs until you tap to use it.
Blank screenshots.
Screenshots and screen recordings of shared content come out blank. If a capture is detected, your content is hidden on their phone and you are told.
Nothing readable left behind.
Photos and videos are stored encrypted and are only decrypted in memory while you look at them.
Check your connection
After pairing, both phones show the same five safety words. If they match, nobody has slipped into the middle of your conversation. If they do not, stop and start again.
Calls
Calls are end-to-end encrypted. They connect directly between your phones where possible. When that is not possible, the encrypted audio and video is relayed through Cloudflare, which cannot decrypt it. Disckreet does not record or store calls.
What we can and cannot see
We cannot see
- Your messages, photos and videos
- Your call audio and video
- Your private keys
We can see
- An anonymous account ID and the nickname you chose
- When a message was sent, how big it was, and which conversation it belongs to
- Your notification token and your subscription status
- Broad app usage and crash reports, with no content and no keys
The full detail is in our privacy policy.
What no app can protect you from
Someone guessing your PIN. Someone filming the screen with another device while you both use the app. A compromised Apple ID, if you back up your key with iCloud Keychain. A phone that is already compromised. Only share with someone you trust, and if you ever suspect something is wrong, hide your content and unlink straight away.
Found a security problem?
Disckreet is an end to end encrypted messaging app. We take reports about its security seriously and we would rather hear from you than read about it somewhere else.
legal@disckreet.comWe aim to acknowledge every report within 3 business days, and to give you an initial assessment within 10 business days. If you have not heard from us in that time, please resend, since it means something has gone wrong on our end.
What to include
The more of this you can give us, the faster we can act:
- What the issue is, in a sentence or two
- Steps to reproduce it, or a proof of concept
- The app version and the device and OS version you saw it on
- What an attacker could do with it
- Whether you believe it is already being exploited
What is in scope
- The Disckreet iOS app
- Our backend services and APIs
- disckreet.com
What is out of scope
- Social engineering of our team, our users, or our suppliers
- Physical attacks against offices or devices
- Denial of service, volumetric testing, or anything that degrades the service for other users
- Automated scanner output with no demonstrated impact
- Missing hardening headers or best practice settings with no demonstrated impact
- Vulnerabilities in third party services we do not control
Testing safely
Please test only against your own accounts and your own data. Do not access, modify, or retain another person's messages or media, and do not attempt to degrade the service for anyone else. If you accidentally encounter another user's data, stop, and tell us in your report.
Our commitment to you
If you report an issue in good faith, follow this policy, and give us a reasonable opportunity to fix the problem before disclosing it publicly, we will not pursue or support legal action against you for your research. We will keep you informed of progress, and we are happy to credit you when the fix ships if you would like us to.
We do not currently run a paid bug bounty.
Coordinated disclosure
We ask for 90 days from our acknowledgement before public disclosure, or until a fix has shipped, whichever comes first. If the issue is being actively exploited we will move faster, and we will tell you if that is the case.
Regulatory note
Disckreet is distributed in the European Union. Where a report concerns an actively exploited vulnerability, we have reporting obligations to EU authorities under Article 14 of the Cyber Resilience Act with a 24 hour first deadline. Prompt, detailed reports help us meet those obligations and help users faster.