Trust & encryption.
Trust starts with cryptography you can name and limits we refuse to hide. Here is how Blink seals messages, where keys live, what servers store, and what is still on the roadmap.
Trust model
Four pillars of how we earn trust
Encrypted on your device
Authenticated encryption seals messages and media on your device before they're sent. Keys are agreed and derived on the device — and on phones, the keys that sign you in and seal your account key live in your phone's secure hardware (Secure Enclave / Android Keystore) where available.
Forward secrecy by epoch
Direct and group chats rotate to a fresh key epoch every seven days, so a compromised key does not reopen an unbounded past.
Ciphertext-only servers
Our database stores only scrambled ciphertext. Media is encrypted on your device before it reaches storage. Our infrastructure never holds keys that can read your content.
Honest limits
We publish what is live and what is next. Trust is built by refusing to overclaim calls, residency, or features that are still shipping.
Cryptography
The stack at a glance
Exact building blocks security teams ask for in a briefing.
- Message & media seal
- Authenticated encryption on device
- Key agreement
- Agreed between your devices — never sent
- Key derivation
- Derived on device
- Hardware-backed keys
- Secure Enclave / Android Keystore on phones, where available
- Forward secrecy
- Seven-day key epochs
- Server storage
- Ciphertext only; encrypted media objects
- Call posture today
- Secure media-server mediated (full E2EE calls on roadmap)
- Regions today
- United States and India (more regions planned)
Practices
How trust shows up day to day
No readable content on our side
If a server cannot decrypt, it cannot casually leak plaintext. That is the baseline for every trust conversation with security and legal teams.
Device-held keys
Your devices hold derived keys and an encrypted vault. Cloud convenience does not require giving Blink a master key.
Published status and change log
Incidents, component health, and versioned engineering notes stay visible so trust is continuous — not a one-time marketing claim.
Verify it with your team
Bring security and legal to a live walkthrough — or follow the public status page and change log for continuous signal.