The physical OFF Castle die on red felt

Encrypted messaging · zero-knowledge

The treasure isn't in the castle.

It's in the roll of a die, in your hand. We don't have the keys, no server has them — they're born from a physical act and live only in your mind and on your device.

Download APP
The manifesto

Every security system you know makes the same promise: "your secret is safe in here." A taller castle. Thicker walls. More loyal guards. For years, the game has been this: who builds the better defense.

We played that game too. Post-quantum, hybrid keys, verified protocols — our castle holds as well as, or better than, anyone else's.

But there's a question almost no one asks, because it sounds absurd:

We asked ourselves how to make the castle impregnable. And we asked ourselves why the treasure had to be inside it at all.

A secret that exists somewhere — on a server, in a key, in a database — will eventually be found. By a warrant, an attack, a human error, given enough time. Not because the defense is weak. Because the treasure is there.

So we took the treasure out of the castle.

We don't have your keys. No server has them. They're born from a roll of the die, in your hand, and live only in your mind and on your device — never anywhere else, never in transit, never somewhere anyone else could open.

We don't ask you to trust us. We show you that you don't need to.

It's not safer because no one has ever broken in. It's safe because there's nothing inside to take.

This is OFF Castle.

Positioning

Not for everyone. On purpose.

OFF Castle isn't competing to be the messaging app for a billion people. It exists for a smaller, more demanding audience: lawyers, journalists, financial advisors, entrepreneurs, politicians, and anyone handling communications whose interception carries a real, not abstract, cost — to themselves or to the people who trust them.

We're not trying to be more secure than Signal. We're solving a problem that Signal, by design, doesn't solve. Signal is, rightly, the benchmark anyone talking about private messaging measures against: mature, verified, free end-to-end encryption used by hundreds of millions of people. We're not trying to beat it on its own turf.

Three levels of reading

What it is, in short

OFF Castle is encrypted messaging where we don't have the keys, and no server does, because they're born from a roll of the die, in your hand. We're not asking you to trust that we don't read your messages: it's technically impossible for us to, even if someone ordered us to.

In short, technically

Every conversation has keys generated locally from physical entropy — the roll of a five-sided die — combined with post-quantum cryptography. The server only routes encrypted data: it never has access to the keys, so it can't read messages, nor be forced to.

Who it's for

Built for people who need security to be an architectural fact, not a company policy that can change.

Law firms and lawyers

Attorney-client communications where confidentiality is a legal obligation, not an option.

Journalists and newsrooms

Source protection in scenarios where a breach has direct consequences for real people.

Entrepreneurs and politicians

Communications that, if intercepted, have immediate market value to whoever intercepts them.

How it works

Born from a physical roll of the die — twenty-one rolls, to be precise

Combined with the same cryptographic standards used to protect government and financial communications, including a component resistant to future quantum computers, not just today's. This isn't a contractual promise, it's a consequence of how the system is built — and we won't use the language of "absolute mathematical unbreakability" here: it's a claim that doesn't survive a serious cryptographic review.

Key agreement
X25519 + ML-KEM-768 — hybrid classical / post-quantum
Entropy
physical, non-reproducible — 21 rolls of the five-sided die
Server
zero-knowledge by construction, not designed to trust itself

The die isn't a one-size-fits-all accessory.

It comes in a collection of materials — resin, different types of wood, metal — and different sizes, each with its own craftsmanship and physical balance. Every material has a genuinely different character: the way it falls isn't identical from one piece to the next. It's not a flaw to fix — it's part of the object you choose, a small personal ritual before it's ever a cryptographic key.

Frequently asked questions
What is OFF Castle?

OFF Castle is an encrypted messaging app built for people who need above-average privacy: lawyers, journalists, anyone handling sensitive information. The difference from other apps isn't just technical — it's architectural: our server never holds the keys that protect your messages. That's not a promise, it's a verifiable fact: even if someone accessed our systems, they'd find nothing readable. The treasure isn't in the castle.

What's the die, and do I need a physical one?

The five-sided die is the physical entropy source of your identity: you roll it 21 times during registration, and that sequence contributes to generating your cryptographic identity. It's a purely mechanical object — no chip, no serial number — and the 3D printing file is public, so anyone can make an equivalent one.

You don't need to own a physical one: a virtual die is also available directly in the app, for anyone who wants to start right away without waiting for or printing the object. The physical die remains an option for anyone who wants that extra root of trust — an object no software can remotely replicate or simulate, physically verifiable by you.

What is my "Identity" on OFF Castle? Why isn't it like an account tied to a phone number?

This is probably the single most important thing to understand before you start.

The apps you normally use (WhatsApp, Telegram, etc.) tie your account to a phone number or email address, held on a server. Switch devices, and the server "recognizes" you and restores everything.

OFF Castle works differently: your Identity is created and lives on your device, not on our servers. There's no database where "your account" sits waiting for you to come back — by design, we couldn't hand it back to you even if we wanted to, because we never had it.

That's the price of zero-knowledge security: if you lose your device, or uninstall the app without having linked another device, that Identity — and its conversations — cannot be recovered.

This isn't a bug. It's the same architectural choice that makes the system resistant to seizure or a legal request for access.

Two safety nets you can set up:

  • Link a second device to the same Identity: if one device is lost, the other already has everything — conversations included.
  • A recovery email: if you get locked out of the app on the same device (e.g. an expired session), it brings you back with everything intact — your data never actually left. But if the device itself is lost, the email only restores your username: your existing conversations stay tied to the lost device and need to be re-established one by one through a manual "recharge." The recovery email itself, if you set one, is stored in plain text on our servers, linked to your account — use it only to regain access: it isn't part of the encrypted content and has no effect on your messages' security.

Note: if you recover your username on a new device, the people you talk to are not automatically notified that you've lost access to your old channels — you'll need to tell them yourself, until you complete the recharge.

Are my messages really safe? Who can read them?

Messages are end-to-end encrypted: only you and whoever's in the conversation can read them. Our server only sees encrypted data, never the plaintext content. We use standard, publicly validated cryptographic primitives (we don't invent proprietary algorithms) — the system's security is verifiable, not based on trusting our word.

It's just as important to be clear about what OFF Castle doesn't protect against: a device already compromised by malware, or real-time coercion during use, are outside the scope of any messaging app, not just ours.

Are you resistant to future quantum computers?

Yes, for the key exchange part. OFF Castle uses a hybrid scheme combining classical cryptography (X25519) with post-quantum cryptography (ML-KEM-768, NIST standard FIPS 203). In practice: even if a large-scale quantum computer becomes a real threat in the future, keys exchanged today stay protected.

Is OFF Castle open source?

It's source-available: the code is publicly viewable and verifiable by anyone, including independent security reviewers — but under a license that limits some direct commercial use of the code by third parties. We don't use the term "open source" in its strict (OSI) sense, because technically it isn't, and we'd rather be precise than generous with labels.

Does it work on iPhone?

Yes. OFF Castle is a PWA (Progressive Web App): it installs directly from the browser, with no app store in between — among other things, this lets us offer features like emergency data wipe without being subject to a third-party store's review timelines. On iPhone, installation happens through Safari (Share → Add to Home Screen); you'll find step-by-step instructions on the install page.

How much does it cost?
Plan Price Duo Team Attachments
Basic Free 1 0 up to 5 MB
Essential €4.90/user/month 5 3 up to 8 MB
Professional
Most popular
€8.90/user/month 55 5 up to 21 MB
Studio €25/user/month 233 34 up to 55 MB

Basic isn't a plan you choose: it's the automatic status for anyone invited by someone else, with one free one-time Duo channel. Essential is the first paid plan, for individual or basic professional use. Professional is the plan for anyone working with clients every day. Studio is built for firms and organizations running multiple parallel teams.

It's worth explaining why you pay, not just how much: the cost isn't there to "monetize" your data — we couldn't, we don't have it — but to keep the project sound and independent. A security service funded by ads or data sales would have a structural incentive in conflict with your privacy. One funded by the people who use it doesn't: you pay for the security itself, not to fund a business model that depends on watching what you do.

What happens if OFF Castle receives a legal request for access to my data?

For the content of your messages: nothing useful can be demanded from us, because we don't have it — it's encrypted with keys we've never held. That's the difference between "we promise not to look" and "we can't look even if someone ordered us to."