Council Knowledge Base
Back to Council

How Your Messages Stay Private

When you send a message in a Council network, it's encrypted the moment you hit send. This document explains the journey your message takes: it is encrypted on your device, and the server, including Council itself, relays ciphertext it cannot decrypt.

The Encryption Journey

Step 1: Your Passphrase Creates Your Keys

When you join a network with a passphrase, your device uses that passphrase to mathematically generate a set of encryption keys. This process is deterministic—the same passphrase always produces the same keys—which is how all network members can decrypt each other's messages without ever sharing keys directly.

The passphrase itself never leaves your device. Only the encrypted messages do.

Step 2: Your Device Adds Its Own Layer

Your device has a unique secret that was created when you first set up Council. This secret combines with the passphrase-derived keys to create a final encryption key. This means someone would need both your passphrase AND access to your specific device to decrypt messages.

Step 3: Time Synchronization

D4TE uses the current time as part of its encryption. Messages are tied to specific time intervals, which prevents certain types of replay attacks and adds another dimension to the key derivation.

Step 4: Each Message Gets Unique Keys

Every message you send is encrypted with its own message key. As messages are sent, the keys "ratchet" forward and old values are destroyed. This provides forward secrecy at the cycle boundary: when a network rotates to a new cycle, the prior cycle's keys are destroyed, and keys captured later cannot decrypt those older messages.

What Council Servers See

When your encrypted message passes through Council's servers, here's what they see:

What Council Sees What Council Cannot See
Message size Message content
When it was sent What it says
Which network it belongs to The passphrase
Who sent it (user ID) The encryption keys

Council's servers are designed to route encrypted messages, not read them. They lack the mathematical ability to decrypt your messages because they never possess the passphrase or your device secrets.

Why This Matters

Traditional messaging services typically hold encryption keys or can reset your password to access your account. With Council:

No Password Reset

If you forget your passphrase, there's no way to recover it—because Council never had it.

No Backdoor Access

There are no "master keys" that could decrypt all messages.

No Compliance Risk

Even if compelled by law enforcement, Council cannot provide message content because they don't have it.

Key Takeaways

  • Messages are encrypted on your device before transmission
  • Your passphrase and device secrets combine to create encryption keys
  • Each message uses its own key, and rotating a cycle destroys the prior cycle's keys (cycle-boundary forward secrecy)
  • Council servers hold no key that can decrypt your messages