LIVARA 0.9.16 / THREAT MODEL

Who seeswhat.

A threat model that only lists strengths is a brochure. This one names the relevant adversaries, says exactly what each gets, and then prints the list of things Livara does not claim.

01 / THE ADVERSARIES
Six people who might want your messages

Named, and answered.

Some get more than you might hope. They are listed anyway, in the same type size as the rest.

01

A network observer on the same Wi-Fi

Sees TLS to Livara and nothing else. No message content, direct or group.

Held
02

Livara's own server or someone who takes it

Reads channel content and routing metadata. It cannot directly open compatible private text/media, but it can substitute a first-contact key or insert a private-group member until key transparency and MLS replace those trust points.

Not held
03

Someone who steals your password

Cannot restore your direct-chat keys — the encrypted backup needs the recovery phrase as well.

Held
04

Someone holding your unlocked phone

Reads everything you can read. No messenger survives this one.

Not held
05

A future quantum computer with recorded traffic

Current direct sessions use Livara's unaudited hybrid-PQ LVR1; LGS1 sender keys and attachment keys travel inside those sessions. This is not equivalent to Signal's reviewed Triple Ratchet, and DTLS-SRTP call media is not itself post-quantum.

Held
06

A tampered download served by a middlebox

Detectable before install. The SHA-256 is published and the Proof Lab hashes your file locally.

Held
02 / THE COVERAGE LINE
The same table, everywhere on this site

Private text and media are sealed.

This table is printed identically on the home page, on the security page and here, because the answer should not depend on which page you landed on.

07

Seven rows, no shading.

LVR1 closes compatible direct content before upload. LGS1 does the same for compatible private-group text and attachment-key messages; channel and metadata cells show what remains visible.

The cryptographic detail
What the Livara server can and cannot read in direct chats, compatible encrypted groups, and channels
What it isDirect 1:1GroupsChannels
Message textSealed on your deviceLGS1 sender-key sealedServer can read it
Text editsSealed on your deviceLGS1 sender-key sealedServer can read them
Photos, video, files, captionsEncrypted before uploadEncrypted before uploadServer can read them
Who you talked toServer knowsServer knowsServer knows
When you talkedServer knowsServer knowsServer knows
Your passwordNever leaves your deviceNever leaves your deviceNever leaves your device
Your private keysNever leave your deviceNever leave your deviceNever leave your device
03 / WHAT LIVARA DOES NOT CLAIM
The list nobody publishes

Limits we are not hiding

Each of these is a real limitation with a real consequence. They are here because a boundary you can only discover by being disappointed is not a boundary, it is a trap.

Not claimed

Livara does not hide metadata

Ordinary delivery stores sender, destination, group membership, timing, ciphertext size and delivery state. LSS1 code exists but is not integrated into normal sends. Multi-device sync is not a proof that this metadata must be retained in this form.

Not claimed

Livara does not authenticate group membership against a compromised server

LGS1 covers compatible private-group text and media, but it encrypts to the member list supplied by Livara. A compromised service can insert an account before redistribution. Channels remain server-readable.

Not claimed

Group calls are a peer mesh, not MLS/SFrame

Android supports 2–6-person group audio/video and screen sharing. Every peer link uses WebRTC DTLS-SRTP and pairwise-sealed signaling, but there is no MLS-bound SFrame layer, call media is not post-quantum, the server still sees participant/timing metadata, and browser clients do not join group rooms yet.

Not claimed

Livara does not solve first-contact key substitution

Clients pin a complete identity after a successful message and detect later changes. Until a witnessed key-transparency directory exists, a malicious server can substitute the first key shown to two new devices.

Not claimed

Livara cannot protect a compromised device

Keys live on the device. Malware with your unlocked device has your plaintext, and no protocol choice on our side changes that.

Not claimed

Livara cannot recover a lost recovery phrase

Lose the device and the phrase together and the old direct-chat ciphertext stays closed permanently. That is the real price of a server that cannot read your messages.

Not claimed

Livara does not claim a formal external audit

There is no third-party audit report to point at yet. Instead of implying one, the site ships the Proof Lab so the parts that are checkable can be checked by you today.

Do not take this page on faith either

The checkable half is checkable now.

Hash the APK, run the handshake, corrupt a byte and watch the authentication reject it. All of it offline, in your own browser, before you install anything.

Open LivaraGet the app