Freehold · Peer-to-peer · Post-quantum · MIT licensed

Secure comms you hold outright

Freehold is peer-to-peer encrypted chat, calls and file transfer for small teams that handle sensitive work. No server, no accounts, no per-seat rent, no third party holding your metadata — and it keeps working where the internet does not reach. Built for the defense industrial base: the five-person machine shop on three primes programs, with CUI obligations and an assessment coming.

Proof, not promises

Every claim on this page is enforced by the protocol and proven by an automated end-to-end gate — 21 suites that spawn real nodes over the real network and try to break the claim. A carrier that alters a relayed message is refused. A tampered evidence bundle fails verification. A 1 GB transfer killed at 30% resumes byte-identical. Two machines with no internet find each other in under a minute. The verifiers run on plain Node.js on a machine that has never seen Freehold — so the capture and the verdict can come from different people.

  • $0
    MIT licensed — no tiers, no seats
  • ML-KEM-768
    Post-quantum on every link, today
  • 21
    End-to-end suites on real nodes
  • 5 min
    Deploy, with no IT department

01 — See it work

A session, as it actually behaves

freehold · session open · 4 peers · Noise X25519 + ML-KEM-768
$ /roster import fireteam.roster
signed by D. Whitlock — 6 members onboarded, 0 pasted keys
policy: mandatory vault · 30d retention · CUI banner enforced
$ /fuse 5s "grid ref for tomorrow — do not forward"
grid ref for tomorrow — do not forward (burns in 5 seconds)
burned on every device · no copy anywhere · entry written to audit chain
$ /peers
dana — direct — ML-KEM-768 — verified
jonah — LAN — no internet — ML-KEM-768 — verified
rivera — relayed — ML-KEM-768 — verified
$ /evidence export --since 30d
bundle written · 412 events · hash chain intact
mapped to NIST SP 800-171 · verify offline: node verify-evidence.mjs
$ /burn --identity
vault, history and identity destroyed. clean exit.

/fuse — ephemerality with a receipt

The message is destroyed on every recipient device when the fuse runs out, and the deletion itself is written to the tamper-evident chain. You get the operational benefit of a message that does not linger, without losing the ability to show an assessor that the policy was applied.

…and where it is refused

In a records channel, roster policy makes the channel append-only — and a fuse is refused on every member machine, not merely discouraged by a console. That is the federal-records tension resolved rather than dodged: ephemeral where you want it, provably permanent where the rules require it.

02 — Sovereign by architecture

The dependency is the vulnerability

01

Your identity is your key

A Freehold UID is an Ed25519 public key generated on your machine. No account, no registration, nobody to register with — and no server exists to breach, subpoena, take offline, or bill you. Peers connect directly, NAT holepunching included.

02

Post-quantum today, not on a roadmap

Every link runs Noise (X25519) plus an independent hybrid ML-KEM-768 (FIPS 203) layer — a fresh key per message, periodic re-keying, downgrade refusal. Traffic recorded today stays unreadable to tomorrow computers, ahead of CNSA 2.0 timelines.

03

Policy enforced, not suggested

A team lead signs the member list and security policy with the same key that authenticates them. Retention, expiry caps, banners and mandatory vault are enforced by every member machine. Follow several rosters at once — strictest policy wins.

04

Provenance, not trust

Every channel message carries its author own signature, bound to the channel. A tampered message is refused and logged at the receiving end. That is what makes store-and-forward safe: relayed does not mean trusted, it means verified.

03 — Capability

Slack-grade workspace, zero servers

A real daily driver

  • Channels, threads, reactions, editing, unread badges and @mentions
  • Desktop notifications, search and image previews
  • Voice and video calls, plus screen sharing, in the browser
  • A full terminal client for people who live there
  • Multi-device — one identity across up to eight machines
  • A stolen laptop is revoked account-wide and stops receiving ciphertext

Built for where clouds cannot go

  • Air-gapped LAN: two laptops find each other in under a minute, zero config
  • Private bootstrap node never announced on any public network
  • Store-and-forward relay through teammates you never overlap with
  • Mission-size files — 2 GB chunked transfers that survive a dropped link
  • Transfers resume where they stopped and are hash-verified on both ends
  • DDIL is the design point, not the failure mode

Compliance without a cloud

  • One-command signed evidence bundle mapped to NIST SP 800-171
  • Verifiable offline by a third party with nothing but Node.js
  • Records channels: append-only, deletion and self-destruct refused peer-side
  • Signed, timestamped transcripts export on demand
  • Tamper-evident hash-chained security event log
  • CUI marking banners per conversation, enforced both ends

At rest and under duress

  • AES-256-GCM at rest with a scrypt-hardened key; auto-relock on idle
  • Duress passphrase that opens an innocent-looking empty account
  • Dead-man switch that wipes an abandoned machine
  • /burn for a clean exit
  • Priority alerts everyone must acknowledge, with a live who-has-not board
  • Optional traffic-shape padding; cover traffic hides idle links

04 — The comparison

Freehold versus renting a cloud messenger

FreeholdCloud secure messengers
Cost$0 — MIT licensed, no tiers, no seats~$5–15 per user / month; retention and e-discovery in the premium tier (~$1,800/yr for 10 seats) plus procurement friction
InfrastructureNone. Peer-to-peer — nothing to stand up, patch, or trustVendor cloud holds accounts, routing and metadata
Cross-org collaborationImport a signed roster file per team — a sub on three primes follows three rosters at onceAdmin-gated federation: security groups and network IDs exchanged between administrators per org pair
No internet / air-gappedNative: zero-config LAN discovery, private bootstrap, relay through teammatesNo reach to the cloud means no service
Quantum resistanceHybrid ML-KEM-768 on every link, todayNo public evidence the E2EE protocol itself is post-quantum
Retention vs ephemeralityRecords channels: append-only and signed, enforced peer-side, beside fully ephemeral channelsCompliance bolt-on in the paid tier of a burn-by-default tool
Assessment evidenceSigned, 800-171-mapped bundle your assessor verifies offlineThe vendor own accreditations keep the vendor compliant — they do little for your SSP
Message provenancePer-message author signatures; tampered relays refused and auditedServer-mediated trust

05 — Deployment

Five minutes, no IT department

1

Install Node.js, double-click

Node 18+ is the only prerequisite. start-ui.command on macOS or start-ui.bat on Windows installs dependencies on first run and opens the app. Terminal-only: npm start.

2

Swap UIDs once

Copy your UID from the sidebar, send it over any channel you already trust, and add theirs. The mutual add is the whole trust ceremony — verify with matching emoji fingerprints on a call.

3

Operational

Direct encrypted links come up on their own through NATs, with no port forwarding and no server. A guided first-run flow, a passphrase-vault prompt, and in-app Help cover the rest.

06 — Plain speaking

What we do not claim — read this part

Not an accredited system

No IL4/IL5, no FedRAMP. Where a contract mandates an accredited tool, Freehold is the disconnected-operations, cross-org, records-honest complement to it — not a compliance substitute. Confirm CUI usage with your FSO.

Not for thousands of seats

Built for program teams — tens of people. If you are rolling out to an enterprise directory of five thousand users, this is the wrong shape of tool and we will say so.

Not on phones yet

Desktop today: macOS, Windows and Linux, in the browser or a full terminal client. No mobile client. If you need phones now, we will tell you in the first conversation rather than the third.

Not magic

A compromised laptop beats any messenger, a peer can leak anything you send, and a forgotten vault passphrase has no recovery — that is the price of nobody else holding your keys. Every feature states its limits at the moment of use. That discipline is the product.

07 — Specification

The summary for whoever will actually evaluate it

IdentityEd25519 keypair generated on your machine — no account, no registration
TransportPeer-to-peer with NAT holepunching; no server in the data path
Transport encryptionNoise protocol over X25519, peer identity pinned
Post-quantum layerIndependent hybrid ML-KEM-768 (NIST FIPS 203), downgrade refusal
Message keysFresh key per message, periodic re-keying
At restAES-256-GCM with a scrypt-hardened key; idle auto-relock
Rosters and policyEd25519-signed; enforced on every member machine, strictest wins
Message provenancePer-message author signature bound to the channel
AuditHash-chained security event log; silent tampering breaks the chain visibly
EvidenceSigned bundle mapped to NIST SP 800-171, verifiable offline with Node.js
File transfer2 GB chunked, resumable, hash-verified both ends
PlatformsmacOS, Windows, Linux — browser or terminal; up to 8 devices per identity
LicenceMIT, open source — built on the chat-tunnel protocol
Assurance21 automated suites driving real nodes over the real network

Source, protocol and verifiers: github.com/WELCOMETOTHETRIBE/chat-tunnel.

08 — Questions

Asked and answered

What is Freehold?

Freehold is peer-to-peer encrypted chat, calls and file transfer for small teams that handle sensitive work. There is no server, no accounts, no per-seat rent, and no third party holding your metadata. It is MIT licensed and open source, built on the chat-tunnel protocol. The name is the thesis: a freehold is property you own outright rather than rent — which is exactly the difference between this and a cloud messenger subscription.

How much does Freehold cost?

Nothing. It is MIT licensed with no tiers and no seats. The comparison that matters is against cloud secure messengers at roughly $5–15 per user per month, where retention and e-discovery typically live in a premium tier — around $1,800 a year for a ten-seat subscription, plus the procurement friction of buying it. Freehold has no per-seat cost because there is no vendor infrastructure to pay for.

How does Freehold work with no internet at all?

Two laptops on one network segment find each other in under a minute with zero configuration, using an identity-free discovery beacon. You can also run your own one-file bootstrap node that is never announced on any public network. Messages relay through teammates to people you never overlap with — carrying the original author signature, so a relayed message is still verified rather than merely trusted. Denied, disrupted, intermittent and limited connectivity is the design point, not the failure mode.

What does post-quantum actually mean here?

Every link runs Noise over X25519 plus an independent hybrid ML-KEM-768 layer — the NIST FIPS 203 standard — with a fresh key per message, periodic re-keying, and downgrade refusal. Traffic recorded today stays unreadable to tomorrow computers, which is the "harvest now, decrypt later" exposure post-quantum cryptography exists to close. This is ahead of CNSA 2.0 timelines rather than a future roadmap item.

Can Freehold produce evidence for an assessment?

One command exports a signed bundle — verified audit chain, roster policy, retention settings, crypto inventory — mapped to NIST SP 800-171 control families. A third party can verify it offline with nothing but Node.js. Drop it in an SSP or hand it to a C3PAO. Freehold also supports records channels where roster policy makes a channel append-only: deletion and self-destruct are refused on every member machine, and signed timestamped transcripts export on demand. That resolves the federal-records retention versus ephemerality tension the DoD IG has documented, instead of dodging it.

What protects a device that is lost or seized?

Identity, history and files are encrypted at rest with AES-256-GCM and a scrypt-hardened key, and the vault auto-relocks on idle — the browser is outside the trust boundary. A duress passphrase destroys everything and opens an innocent-looking empty account. A dead-man switch wipes an abandoned machine. There is a /burn command for a clean exit. The tradeoff is stated plainly: a forgotten vault passphrase has no recovery, because nobody else holds your keys.

Is Freehold accredited — can it replace an authorized system?

No, and we will not claim otherwise. There is no IL4/IL5 or FedRAMP accreditation. Where a contract mandates an accredited tool, Freehold is the disconnected-operations, cross-org, records-honest complement to it — not a compliance substitute. It is built for program teams of tens of people, not thousands of seats. Anyone handling CUI should confirm usage with their FSO.

How is a team set up without exchanging keys by hand?

A team lead signs the member list and security policy with the same key that authenticates them. Policy — retention, expiry caps, banners, mandatory vault — is enforced by every member machine rather than suggested by a console. You can follow several rosters at once and the strictest policy wins, which is how a subcontractor on three primes programs works in practice. Cross-org collaboration is importing a signed roster file per team, not an admin-gated federation negotiated between two organizations.

How long does deployment take?

About five minutes and no IT department. Install Node.js 18 or newer and double-click start-ui.command on macOS or start-ui.bat on Windows; it installs dependencies on first run and opens the app. Swap UIDs with your teammates once over any channel you already trust — the mutual add is the whole trust ceremony, and you verify with matching emoji fingerprints on a call. After that, direct encrypted links come up on their own through NATs, with no port forwarding, no firewall tickets, and no server.

What platforms does Freehold run on?

macOS, Windows and Linux, desktop today — in the browser or as a full terminal client. One identity works across up to eight machines, messages reach every device, and a stolen laptop is revoked account-wide and stops receiving ciphertext at all. There is no mobile client yet. If your use case requires phones today, we will tell you that in the first conversation rather than the third.

Bring us the network you think will break it

The demonstration is two laptops, one switch, and no uplink — or your own contested environment, if you would rather we earned it the hard way. Thirty minutes, no procurement, and you keep the evidence bundle either way.