EmitDreamBlog
← All postsSecuritySeptember 27, 2026 · 5 min read

Sealed for decades: our post-quantum encryption

ML-KEM-1024, ML-DSA-87 and AES-256-GCM, what they protect, what the server can still see, and where the switch-on stands.

A memory written today may be opened in fifty years. Data copied today could be decrypted by future quantum computers if it were protected only by today's classical algorithms. So EmitDream's end-to-end encryption is post-quantum from the start.

What seals a memory

  • Key exchange: ML-KEM-1024, the strongest level of the post-quantum standard NIST approved in 2024 (FIPS 203), combined with classic P-384 elliptic-curve keys.
  • Signatures: ML-DSA-87 (FIPS 204) combined with ECDSA P-384, so the person receiving an emission knows it truly came from you.
  • Content: AES-256-GCM, which a quantum computer does not meaningfully weaken.

Hybrid means an attacker must break both the post-quantum algorithm and the classic one. A flaw found in either alone exposes nothing.

Sealed on your device, before it leaves

Words, photos, videos and voice memos are encrypted on the sender's device before they are uploaded. Each emission is sealed separately to each chosen recipient's key and signed by the sender. Nobody else holds a key that opens it, including EmitDream.

Your passphrase and recovery code

Setting up takes about a minute: choose a passphrase, write down a 26-character recovery code, and type it back to confirm. In the installed app your device can remember the vault, so the app opens already unlocked. If you ever lose both the passphrase and the recovery code, you can start a fresh, empty vault by email link. What was sealed before stays sealed.

What the server can still see

We will not pretend here either. Like every encrypted messenger, the server can still see who shares with whom and when, the names and sizes of files, and, on your own entries, the date and small settings such as the chosen effect. The words and the media themselves are unreadable to it.

If you send something to a person who has not set up keys yet, it is clearly labelled "Not end-to-end encrypted", so nobody is misled about what protects it.

Where it stands today

Built and tested. It is switching on in stages: chat first, then emissions, then your own stream.

Encryption is free, for everyone, always. Nobody should have to pay for their secrets to stay theirs.