Encrypted messaging · zero-knowledge
It's in the roll of a die, in your hand. We don't have the keys, no server has them — they're born from a physical act and live only in your mind and on your device.
Download APP
The manifesto
Every security system you know makes the same promise: "your secret is safe in here." A taller castle. Thicker walls. More loyal guards. For years, the game has been this: who builds the better defense.
We played that game too. Post-quantum, hybrid keys, verified protocols — our castle holds as well as, or better than, anyone else's.
But there's a question almost no one asks, because it sounds absurd:
We asked ourselves how to make the castle impregnable. And we asked ourselves why the treasure had to be inside it at all.
A secret that exists somewhere — on a server, in a key, in a database — will eventually be found. By a warrant, an attack, a human error, given enough time. Not because the defense is weak. Because the treasure is there.
So we took the treasure out of the castle.
We don't have your keys. No server has them. They're born from a roll of the die, in your hand, and live only in your mind and on your device — never anywhere else, never in transit, never somewhere anyone else could open.
We don't ask you to trust us. We show you that you don't need to.
It's not safer because no one has ever broken in. It's safe because there's nothing inside to take.
This is OFF Castle.
Positioning
OFF Castle isn't competing to be the messaging app for a billion people. It exists for a smaller, more demanding audience: lawyers, journalists, financial advisors, entrepreneurs, politicians, and anyone handling communications whose interception carries a real, not abstract, cost — to themselves or to the people who trust them.
We're not trying to be more secure than Signal. We're solving a problem that Signal, by design, doesn't solve. Signal is, rightly, the benchmark anyone talking about private messaging measures against: mature, verified, free end-to-end encryption used by hundreds of millions of people. We're not trying to beat it on its own turf.
Three levels of reading
What it is, in short
OFF Castle is encrypted messaging where we don't have the keys, and no server does, because they're born from a roll of the die, in your hand. We're not asking you to trust that we don't read your messages: it's technically impossible for us to, even if someone ordered us to.
In short, technically
Every conversation has keys generated locally from physical entropy — the roll of a five-sided die — combined with post-quantum cryptography. The server only routes encrypted data: it never has access to the keys, so it can't read messages, nor be forced to.
Who it's for
Built for people who need security to be an architectural fact, not a company policy that can change.
Law firms and lawyers
Attorney-client communications where confidentiality is a legal obligation, not an option.
Journalists and newsrooms
Source protection in scenarios where a breach has direct consequences for real people.
Entrepreneurs and politicians
Communications that, if intercepted, have immediate market value to whoever intercepts them.
How it works
Combined with the same cryptographic standards used to protect government and financial communications, including a component resistant to future quantum computers, not just today's. This isn't a contractual promise, it's a consequence of how the system is built — and we won't use the language of "absolute mathematical unbreakability" here: it's a claim that doesn't survive a serious cryptographic review.
It comes in a collection of materials — resin, different types of wood, metal — and different sizes, each with its own craftsmanship and physical balance. Every material has a genuinely different character: the way it falls isn't identical from one piece to the next. It's not a flaw to fix — it's part of the object you choose, a small personal ritual before it's ever a cryptographic key.
Frequently asked questions
OFF Castle is an encrypted messaging app built for people who need above-average privacy: lawyers, journalists, anyone handling sensitive information. The difference from other apps isn't just technical — it's architectural: our server never holds the keys that protect your messages. That's not a promise, it's a verifiable fact: even if someone accessed our systems, they'd find nothing readable. The treasure isn't in the castle.
The five-sided die is the physical entropy source of your identity: you roll it 21 times during registration, and that sequence contributes to generating your cryptographic identity. It's a purely mechanical object — no chip, no serial number — and the 3D printing file is public, so anyone can make an equivalent one.
You don't need to own a physical one: a virtual die is also available directly in the app, for anyone who wants to start right away without waiting for or printing the object. The physical die remains an option for anyone who wants that extra root of trust — an object no software can remotely replicate or simulate, physically verifiable by you.
This is probably the single most important thing to understand before you start.
The apps you normally use (WhatsApp, Telegram, etc.) tie your account to a phone number or email address, held on a server. Switch devices, and the server "recognizes" you and restores everything.
OFF Castle works differently: your Identity is created and lives on your device, not on our servers. There's no database where "your account" sits waiting for you to come back — by design, we couldn't hand it back to you even if we wanted to, because we never had it.
That's the price of zero-knowledge security: if you lose your device, or uninstall the app without having linked another device, that Identity — and its conversations — cannot be recovered.
This isn't a bug. It's the same architectural choice that makes the system resistant to seizure or a legal request for access.
Two safety nets you can set up:
Note: if you recover your username on a new device, the people you talk to are not automatically notified that you've lost access to your old channels — you'll need to tell them yourself, until you complete the recharge.
Messages are end-to-end encrypted: only you and whoever's in the conversation can read them. Our server only sees encrypted data, never the plaintext content. We use standard, publicly validated cryptographic primitives (we don't invent proprietary algorithms) — the system's security is verifiable, not based on trusting our word.
It's just as important to be clear about what OFF Castle doesn't protect against: a device already compromised by malware, or real-time coercion during use, are outside the scope of any messaging app, not just ours.
Yes, for the key exchange part. OFF Castle uses a hybrid scheme combining classical cryptography (X25519) with post-quantum cryptography (ML-KEM-768, NIST standard FIPS 203). In practice: even if a large-scale quantum computer becomes a real threat in the future, keys exchanged today stay protected.
It's source-available: the code is publicly viewable and verifiable by anyone, including independent security reviewers — but under a license that limits some direct commercial use of the code by third parties. We don't use the term "open source" in its strict (OSI) sense, because technically it isn't, and we'd rather be precise than generous with labels.
Yes. OFF Castle is a PWA (Progressive Web App): it installs directly from the browser, with no app store in between — among other things, this lets us offer features like emergency data wipe without being subject to a third-party store's review timelines. On iPhone, installation happens through Safari (Share → Add to Home Screen); you'll find step-by-step instructions on the install page.
| Plan | Price | Duo | Team | Attachments |
|---|---|---|---|---|
| Basic | Free | 1 | 0 | up to 5 MB |
| Essential | €4.90/user/month | 5 | 3 | up to 8 MB |
| Professional Most popular |
€8.90/user/month | 55 | 5 | up to 21 MB |
| Studio | €25/user/month | 233 | 34 | up to 55 MB |
Basic isn't a plan you choose: it's the automatic status for anyone invited by someone else, with one free one-time Duo channel. Essential is the first paid plan, for individual or basic professional use. Professional is the plan for anyone working with clients every day. Studio is built for firms and organizations running multiple parallel teams.
It's worth explaining why you pay, not just how much: the cost isn't there to "monetize" your data — we couldn't, we don't have it — but to keep the project sound and independent. A security service funded by ads or data sales would have a structural incentive in conflict with your privacy. One funded by the people who use it doesn't: you pay for the security itself, not to fund a business model that depends on watching what you do.
For the content of your messages: nothing useful can be demanded from us, because we don't have it — it's encrypted with keys we've never held. That's the difference between "we promise not to look" and "we can't look even if someone ordered us to."