Freehold · Peer-to-peer · Post-quantum · MIT licensed
Secure comms you hold outright
Freehold is peer-to-peer encrypted chat, calls and file transfer for small teams that handle sensitive work. No server, no accounts, no per-seat rent, no third party holding your metadata — and it keeps working where the internet does not reach. Built for the defense industrial base: the five-person machine shop on three primes programs, with CUI obligations and an assessment coming.
Proof, not promises
Every claim on this page is enforced by the protocol and proven by an automated end-to-end gate — 21 suites that spawn real nodes over the real network and try to break the claim. A carrier that alters a relayed message is refused. A tampered evidence bundle fails verification. A 1 GB transfer killed at 30% resumes byte-identical. Two machines with no internet find each other in under a minute. The verifiers run on plain Node.js on a machine that has never seen Freehold — so the capture and the verdict can come from different people.
- $0MIT licensed — no tiers, no seats
- ML-KEM-768Post-quantum on every link, today
- 21End-to-end suites on real nodes
- 5 minDeploy, with no IT department
01 — See it work
A session, as it actually behaves
freehold · session open · 4 peers · Noise X25519 + ML-KEM-768 $ /roster import fireteam.roster signed by D. Whitlock — 6 members onboarded, 0 pasted keys policy: mandatory vault · 30d retention · CUI banner enforced $ /fuse 5s "grid ref for tomorrow — do not forward" grid ref for tomorrow — do not forward (burns in 5 seconds) burned on every device · no copy anywhere · entry written to audit chain $ /peers dana — direct — ML-KEM-768 — verified jonah — LAN — no internet — ML-KEM-768 — verified rivera — relayed — ML-KEM-768 — verified $ /evidence export --since 30d bundle written · 412 events · hash chain intact mapped to NIST SP 800-171 · verify offline: node verify-evidence.mjs $ /burn --identity vault, history and identity destroyed. clean exit.
/fuse — ephemerality with a receipt
The message is destroyed on every recipient device when the fuse runs out, and the deletion itself is written to the tamper-evident chain. You get the operational benefit of a message that does not linger, without losing the ability to show an assessor that the policy was applied.
…and where it is refused
In a records channel, roster policy makes the channel append-only — and a fuse is refused on every member machine, not merely discouraged by a console. That is the federal-records tension resolved rather than dodged: ephemeral where you want it, provably permanent where the rules require it.
02 — Sovereign by architecture
The dependency is the vulnerability
Your identity is your key
A Freehold UID is an Ed25519 public key generated on your machine. No account, no registration, nobody to register with — and no server exists to breach, subpoena, take offline, or bill you. Peers connect directly, NAT holepunching included.
Post-quantum today, not on a roadmap
Every link runs Noise (X25519) plus an independent hybrid ML-KEM-768 (FIPS 203) layer — a fresh key per message, periodic re-keying, downgrade refusal. Traffic recorded today stays unreadable to tomorrow computers, ahead of CNSA 2.0 timelines.
Policy enforced, not suggested
A team lead signs the member list and security policy with the same key that authenticates them. Retention, expiry caps, banners and mandatory vault are enforced by every member machine. Follow several rosters at once — strictest policy wins.
Provenance, not trust
Every channel message carries its author own signature, bound to the channel. A tampered message is refused and logged at the receiving end. That is what makes store-and-forward safe: relayed does not mean trusted, it means verified.
03 — Capability
Slack-grade workspace, zero servers
A real daily driver
- Channels, threads, reactions, editing, unread badges and @mentions
- Desktop notifications, search and image previews
- Voice and video calls, plus screen sharing, in the browser
- A full terminal client for people who live there
- Multi-device — one identity across up to eight machines
- A stolen laptop is revoked account-wide and stops receiving ciphertext
Built for where clouds cannot go
- Air-gapped LAN: two laptops find each other in under a minute, zero config
- Private bootstrap node never announced on any public network
- Store-and-forward relay through teammates you never overlap with
- Mission-size files — 2 GB chunked transfers that survive a dropped link
- Transfers resume where they stopped and are hash-verified on both ends
- DDIL is the design point, not the failure mode
Compliance without a cloud
- One-command signed evidence bundle mapped to NIST SP 800-171
- Verifiable offline by a third party with nothing but Node.js
- Records channels: append-only, deletion and self-destruct refused peer-side
- Signed, timestamped transcripts export on demand
- Tamper-evident hash-chained security event log
- CUI marking banners per conversation, enforced both ends
At rest and under duress
- AES-256-GCM at rest with a scrypt-hardened key; auto-relock on idle
- Duress passphrase that opens an innocent-looking empty account
- Dead-man switch that wipes an abandoned machine
- /burn for a clean exit
- Priority alerts everyone must acknowledge, with a live who-has-not board
- Optional traffic-shape padding; cover traffic hides idle links
04 — The comparison
Freehold versus renting a cloud messenger
| Freehold | Cloud secure messengers | |
|---|---|---|
| Cost | $0 — MIT licensed, no tiers, no seats | ~$5–15 per user / month; retention and e-discovery in the premium tier (~$1,800/yr for 10 seats) plus procurement friction |
| Infrastructure | None. Peer-to-peer — nothing to stand up, patch, or trust | Vendor cloud holds accounts, routing and metadata |
| Cross-org collaboration | Import a signed roster file per team — a sub on three primes follows three rosters at once | Admin-gated federation: security groups and network IDs exchanged between administrators per org pair |
| No internet / air-gapped | Native: zero-config LAN discovery, private bootstrap, relay through teammates | No reach to the cloud means no service |
| Quantum resistance | Hybrid ML-KEM-768 on every link, today | No public evidence the E2EE protocol itself is post-quantum |
| Retention vs ephemerality | Records channels: append-only and signed, enforced peer-side, beside fully ephemeral channels | Compliance bolt-on in the paid tier of a burn-by-default tool |
| Assessment evidence | Signed, 800-171-mapped bundle your assessor verifies offline | The vendor own accreditations keep the vendor compliant — they do little for your SSP |
| Message provenance | Per-message author signatures; tampered relays refused and audited | Server-mediated trust |
05 — Deployment
Five minutes, no IT department
Install Node.js, double-click
Node 18+ is the only prerequisite. start-ui.command on macOS or start-ui.bat on Windows installs dependencies on first run and opens the app. Terminal-only: npm start.
Swap UIDs once
Copy your UID from the sidebar, send it over any channel you already trust, and add theirs. The mutual add is the whole trust ceremony — verify with matching emoji fingerprints on a call.
Operational
Direct encrypted links come up on their own through NATs, with no port forwarding and no server. A guided first-run flow, a passphrase-vault prompt, and in-app Help cover the rest.
06 — Plain speaking
What we do not claim — read this part
Not an accredited system
No IL4/IL5, no FedRAMP. Where a contract mandates an accredited tool, Freehold is the disconnected-operations, cross-org, records-honest complement to it — not a compliance substitute. Confirm CUI usage with your FSO.
Not for thousands of seats
Built for program teams — tens of people. If you are rolling out to an enterprise directory of five thousand users, this is the wrong shape of tool and we will say so.
Not on phones yet
Desktop today: macOS, Windows and Linux, in the browser or a full terminal client. No mobile client. If you need phones now, we will tell you in the first conversation rather than the third.
Not magic
A compromised laptop beats any messenger, a peer can leak anything you send, and a forgotten vault passphrase has no recovery — that is the price of nobody else holding your keys. Every feature states its limits at the moment of use. That discipline is the product.
07 — Specification
The summary for whoever will actually evaluate it
| Identity | Ed25519 keypair generated on your machine — no account, no registration |
|---|---|
| Transport | Peer-to-peer with NAT holepunching; no server in the data path |
| Transport encryption | Noise protocol over X25519, peer identity pinned |
| Post-quantum layer | Independent hybrid ML-KEM-768 (NIST FIPS 203), downgrade refusal |
| Message keys | Fresh key per message, periodic re-keying |
| At rest | AES-256-GCM with a scrypt-hardened key; idle auto-relock |
| Rosters and policy | Ed25519-signed; enforced on every member machine, strictest wins |
| Message provenance | Per-message author signature bound to the channel |
| Audit | Hash-chained security event log; silent tampering breaks the chain visibly |
| Evidence | Signed bundle mapped to NIST SP 800-171, verifiable offline with Node.js |
| File transfer | 2 GB chunked, resumable, hash-verified both ends |
| Platforms | macOS, Windows, Linux — browser or terminal; up to 8 devices per identity |
| Licence | MIT, open source — built on the chat-tunnel protocol |
| Assurance | 21 automated suites driving real nodes over the real network |
Source, protocol and verifiers: github.com/WELCOMETOTHETRIBE/chat-tunnel.
08 — Questions
Asked and answered
What is Freehold?
Freehold is peer-to-peer encrypted chat, calls and file transfer for small teams that handle sensitive work. There is no server, no accounts, no per-seat rent, and no third party holding your metadata. It is MIT licensed and open source, built on the chat-tunnel protocol. The name is the thesis: a freehold is property you own outright rather than rent — which is exactly the difference between this and a cloud messenger subscription.
How much does Freehold cost?
Nothing. It is MIT licensed with no tiers and no seats. The comparison that matters is against cloud secure messengers at roughly $5–15 per user per month, where retention and e-discovery typically live in a premium tier — around $1,800 a year for a ten-seat subscription, plus the procurement friction of buying it. Freehold has no per-seat cost because there is no vendor infrastructure to pay for.
How does Freehold work with no internet at all?
Two laptops on one network segment find each other in under a minute with zero configuration, using an identity-free discovery beacon. You can also run your own one-file bootstrap node that is never announced on any public network. Messages relay through teammates to people you never overlap with — carrying the original author signature, so a relayed message is still verified rather than merely trusted. Denied, disrupted, intermittent and limited connectivity is the design point, not the failure mode.
What does post-quantum actually mean here?
Every link runs Noise over X25519 plus an independent hybrid ML-KEM-768 layer — the NIST FIPS 203 standard — with a fresh key per message, periodic re-keying, and downgrade refusal. Traffic recorded today stays unreadable to tomorrow computers, which is the "harvest now, decrypt later" exposure post-quantum cryptography exists to close. This is ahead of CNSA 2.0 timelines rather than a future roadmap item.
Can Freehold produce evidence for an assessment?
One command exports a signed bundle — verified audit chain, roster policy, retention settings, crypto inventory — mapped to NIST SP 800-171 control families. A third party can verify it offline with nothing but Node.js. Drop it in an SSP or hand it to a C3PAO. Freehold also supports records channels where roster policy makes a channel append-only: deletion and self-destruct are refused on every member machine, and signed timestamped transcripts export on demand. That resolves the federal-records retention versus ephemerality tension the DoD IG has documented, instead of dodging it.
What protects a device that is lost or seized?
Identity, history and files are encrypted at rest with AES-256-GCM and a scrypt-hardened key, and the vault auto-relocks on idle — the browser is outside the trust boundary. A duress passphrase destroys everything and opens an innocent-looking empty account. A dead-man switch wipes an abandoned machine. There is a /burn command for a clean exit. The tradeoff is stated plainly: a forgotten vault passphrase has no recovery, because nobody else holds your keys.
Is Freehold accredited — can it replace an authorized system?
No, and we will not claim otherwise. There is no IL4/IL5 or FedRAMP accreditation. Where a contract mandates an accredited tool, Freehold is the disconnected-operations, cross-org, records-honest complement to it — not a compliance substitute. It is built for program teams of tens of people, not thousands of seats. Anyone handling CUI should confirm usage with their FSO.
How is a team set up without exchanging keys by hand?
A team lead signs the member list and security policy with the same key that authenticates them. Policy — retention, expiry caps, banners, mandatory vault — is enforced by every member machine rather than suggested by a console. You can follow several rosters at once and the strictest policy wins, which is how a subcontractor on three primes programs works in practice. Cross-org collaboration is importing a signed roster file per team, not an admin-gated federation negotiated between two organizations.
How long does deployment take?
About five minutes and no IT department. Install Node.js 18 or newer and double-click start-ui.command on macOS or start-ui.bat on Windows; it installs dependencies on first run and opens the app. Swap UIDs with your teammates once over any channel you already trust — the mutual add is the whole trust ceremony, and you verify with matching emoji fingerprints on a call. After that, direct encrypted links come up on their own through NATs, with no port forwarding, no firewall tickets, and no server.
What platforms does Freehold run on?
macOS, Windows and Linux, desktop today — in the browser or as a full terminal client. One identity works across up to eight machines, messages reach every device, and a stolen laptop is revoked account-wide and stops receiving ciphertext at all. There is no mobile client yet. If your use case requires phones today, we will tell you that in the first conversation rather than the third.
Bring us the network you think will break it
The demonstration is two laptops, one switch, and no uplink — or your own contested environment, if you would rather we earned it the hard way. Thirty minutes, no procurement, and you keep the evidence bundle either way.