Home About Projects NoidChat

NOIDChat

Private. Encrypted. Anonymous.
A messaging app built for people who believe privacy isn't optional. No phone number. No email. No identity required. Every message is protected by 7 layers of encryption that rotate every second.
Open Web App Download Android APK

7-Layer Roulette Encryption

Every message passes through 7 layers of encryption. The cipher combination changes every second based on your shared secret. Even if one layer is somehow broken, six more protect your data.

L1Standard Cipher LayerAES-GCM / AES-CBC / AES-CTR / ChaCha20
L2Standard Cipher LayerRotating selection
L3Standard Cipher LayerHMAC authenticated
L4Custom NOID CipherQuantumFold / NeuralCrypt
L5Custom NOID CipherHyperLattice / VortexHash
L6Custom NOID CipherPlasmaKey / DarkMatter
L7Scramble LayerByte-level permutation

Built For Privacy

No Identity Required

Sign up with just a username. No phone number. No email. No tracking. Your display name is all anyone sees.

End-to-End Encrypted

Messages are encrypted on your device before sending. The server never sees your plaintext. Only you and the recipient can read them.

Safety Numbers

Verify your contacts with 60-digit safety numbers — like Signal. Know for certain that nobody is intercepting your messages.

Encrypted Files

Photos, videos, audio, documents — all encrypted with the same 7-layer system. Real-time progress shows each layer completing.

Hyper Protect

The ultimate panic button. Set a deactivation PIN — if entered, ALL your data is permanently destroyed. Your account ceases to exist. No trace.

Rotating QR Codes

Add friends securely with QR codes that change every 60 seconds. HMAC-signed so they can't be forged or replayed.

Biometric Lock

Lock the app with fingerprint or face recognition. Real WebAuthn cryptographic verification — not just a screen overlay.

Groups & Stories

Encrypted group chats with automatic key rotation when members leave. Share stories that disappear after 24 hours.

Security Hardened

4 rounds of penetration testing by independent security agents. 55+ vulnerabilities found and fixed. Here's what's protected:

XSS Protection

All user input escaped. Nicknames sanitized. No injection possible.

SSRF Protection

Link previews blocked from internal networks. DNS rebinding mitigated.

Rate Limiting

Brute force blocked. Upload limits. Message throttling. Connection timeouts.

Auth Security

JWT with pinned algorithms. Bcrypt password hashing. Reserved username blocking.

File Security

Uploads require authentication. Random filenames. MIME validation. Size limits.

Data Isolation

Channel membership checks on every operation. No cross-channel data leaks.

Encryption at Rest

Auth database encrypted with AES-256-GCM. SSL keys restricted to owner only.

Clean Logout

All keys, caches, cookies, and service workers wiped on logout. No residual data.

Get NOIDChat

Available now on web and Android. iOS coming soon.
Open in Browser Download APK (5.7MB)