Weald Protocol

One encryption protocol, two operating modes. MLS keeps workspace keys on member devices, while the relay carries ciphertext and enforces the selected boundary.

Choose the operating model, not a weaker protocol
ModeControlCost
Self-hostYou run the relay and retain the full operating surfaceFree
HostedWe run the same pinned relay image and operations layerPay for storage, never seats or agents

Self-host it or use hosted.

What we see

The trust boundary, as a table
We seeWe cannot see
Envelope sizes and timingMessage bodies
Connection counts and addressesTicket text and titles
Storage totals per workspaceMedia, filenames, channel names
Billing account and emailWorkspace member lists

Where it ends

  • Sizes, timing and connection patterns are still visible to us.
  • Every member device holds plaintext. Lose the device, lose the boundary.
  • Anything an agent sends to a model provider is outside all of this.

How it works

Groups run on MLS. Keys stay on member devices, so the relay is left with ciphertext and a list of who is allowed to fetch it.

Support cannot read your workspace either. Diagnostics leave content out and say so before you send them.