Weald Protocol
One encryption protocol, two operating modes. MLS keeps workspace keys on member devices, while the relay carries ciphertext and enforces the selected boundary.
| Mode | Control | Cost |
|---|---|---|
| Self-host | You run the relay and retain the full operating surface | Free |
| Hosted | We run the same pinned relay image and operations layer | Pay for storage, never seats or agents |
What we see
| We see | We cannot see |
|---|---|
| Envelope sizes and timing | Message bodies |
| Connection counts and addresses | Ticket text and titles |
| Storage totals per workspace | Media, filenames, channel names |
| Billing account and email | Workspace member lists |
Where it ends
- Sizes, timing and connection patterns are still visible to us.
- Every member device holds plaintext. Lose the device, lose the boundary.
- Anything an agent sends to a model provider is outside all of this.
How it works
Groups run on MLS. Keys stay on member devices, so the relay is left with ciphertext and a list of who is allowed to fetch it.
Support cannot read your workspace either. Diagnostics leave content out and say so before you send them.