LIVARA 0.9.16 / TEN QUESTIONS

Compare theanswers.

A private messenger comparison: Livara against the encrypted chat apps you already know.

Most comparison pages are a competitor grid with one column mysteriously full of ticks. This one asks ten questions and answers them for Livara — including the answers that count against us.

01 / THE GRID
Ten questions worth asking anything

Ask these of any messenger.

The right-hand column describes what dedicated private messengers typically answer, from their own published documentation. It is a summary of a category, not an accusation about a named product.

10

Some of these go against us.

Channel content is readable, LGS1 membership is server-controlled, metadata is not hidden, group calls are an Android peer mesh rather than MLS/SFrame, and there is no external audit report to point at. A comparison that hid those would not be worth the scroll.

Read the full threat model
Ten privacy questions answered for Livara Chat and for the typical private messenger
The questionLivara ChatTypical private messenger
Are one-to-one messages end-to-end encrypted?Yes — current secure chats use the hybrid-PQ LVR1 ratchet, and a send is refused rather than quietly downgradedUsually yes on dedicated messengers, usually no on social platforms
Are group messages end-to-end encrypted?Private text, media, files, captions and edit content use LGS1 sender keys. Membership state is still server-controlled, so MLS-grade malicious-server integrity remains future workVaries; coverage for text, history, media and membership changes is often not separated
Are channel messages end-to-end encrypted?No. Channel content remains server-readable and is labelled separately from encrypted group textUsually not for public or broadcast channels
Is the encryption resistant to a future quantum computer?Custom LVR1 combines ML-KEM-768 with P-256 and periodically advances a PQ epoch, but it is unaudited and not equivalent to Signal's Triple RatchetNot comparable as a category: published post-quantum deployments now differ materially by product and protocol
Does the server learn your password?No. SRP proves knowledge without the wire ever carrying the passwordCommonly a password hash is sent over TLS and verified server-side
Is who-you-talked-to hidden from the operator?No. Routing, timestamps and membership are stored so devices can syncNo, with rare exceptions that trade away instant multi-device sync
Can you verify the app you installed is the app that was published?Partly — the SHA-256 is published and the Proof Lab hashes your file offline, but independent source-to-artifact reproduction is still missingStore installs are signed, but a checksum you can check yourself is uncommon
Does a correct password alone restore your keys on a new device?No, deliberately. The encrypted key backup needs your recovery phraseOften yes, via a cloud backup — convenient, and a much larger blast radius
Is there a phone number requirement?No. An account is a username and a passwordFrequently required, which ties the account to a real-world identity
Is it free?Yes, with no advertising and no message-content processing for advertisingUsually free; the funding model is what varies
02 / HOW TO CHOOSE
Pick against your actual threat

“Most secure” is not a product.

It is a question about who you are hiding from. These three answers point at three different apps, and only one of them is this one.

01

You want your messages unreadable by the operator

Livara encrypts compatible direct and private-group text/media, but its first-contact directory and LGS1 member list are still server trust points. It is the wrong choice when you require an audited protocol or malicious-server-safe group membership today.

verdict · encrypted content, incomplete server-compromise model
02

You need the fact of the conversation hidden

Livara is the wrong tool. Routing, timestamps and membership are stored by the ordinary delivery path. Look at systems with integrated sealed sender, private group credentials and a published metadata threat model; multi-device support does not by itself make metadata resistance impossible.

verdict · not this
03

You want to verify rather than trust

The APK digest is published and the Proof Lab hashes your file locally, but that proves only equality with the published artifact. It does not prove source correspondence, protocol correctness or an independent audit. Those remain release gates.

verdict · start at the proof lab
03 / QUESTIONS
Frequently asked

The questions people actually type

What is the most secure messaging app?
There is no single answer, because 'secure' is several different questions. Livara uses custom hybrid-PQ LVR1 for direct text/media and LGS1 for compatible private-group text/media. It does not hide the social graph, authenticate first-contact keys automatically, or protect LGS1 membership from a compromised server, and it has no completed independent audit. Pick against the threat you actually have.
Does Livara Chat end-to-end encrypt group chats?
Compatible private groups use LGS1 sender-key E2EE for text, edits and messages carrying unique attachment keys, so photos, video, files and captions are encrypted before upload. The server still controls the member list and can insert an account if compromised. Channels remain server-readable.
Is Livara Chat quantum-safe?
Current direct LVR1 sessions combine P-256 with ML-KEM-768 and periodically advance a custom post-quantum root. LGS1 keys and attachment keys are distributed inside those pairwise sessions. LVR1 is unaudited and must not be equated with Signal's Triple Ratchet; WebRTC call media uses DTLS-SRTP and is not itself post-quantum.
Do I need a phone number to use Livara Chat?
No. An account is a username and a password, so the account is not tied to a real-world identity by a carrier record.
How do I check that the app I installed is the one Livara published?
Download the Android APK, then open the Proof Lab at /proof and drop the file in. Your browser hashes it locally and compares the SHA-256 with the published digest. Nothing is uploaded, and it works with your network disconnected.
Stop reading, start checking

Check the parts that are measurable.

The Proof Lab runs on your device and makes no network requests. It verifies selected artifact and primitive checks, not the whole security architecture.

Open LivaraGet the app