What exists today
VENTEX Connect runs as a controlled production release. Core communication, device management, client-side content protection and the hybrid PQXDH path with X25519 and ML-KEM-1024 for capable device pairs are implemented.
Security architecture, public claims, operational evidence and deliberate boundaries—in one canonical, versioned and directly linkable place.
VENTEX Connect runs as a controlled production release. Core communication, device management, client-side content protection and the hybrid PQXDH path with X25519 and ML-KEM-1024 for capable device pairs are implemented.
Independent cryptographic and implementation review, tenancy, SSO/SCIM, formal service levels and broader operational acceptance are not complete.
No certification, Signal compatibility or equivalence, General Availability, government approval, metadata-free processing, hardware-backed key custody or universal PQ/Ratchet coverage. Customer and partner relationships are named only with verifiable evidence.
General questions reach contact@ventex-connect.com. Security findings belong in the responsible-disclosure channel. Detailed protocol material is shared only within an expressly agreed confidential review or audit scope; restricted access is not itself security evidence.
Every domain states its current status, technical basis and the boundary of the claim.
Protection layers, cryptographic paths and the boundaries of the current VENTEX Connect product state.
Passwords, passkeys, devices, sessions, invitations and administrative access controls.
Which data Connect needs, which content is protected and where metadata is deliberately reduced.
Release controls, health checks, status measurement and the limits of the current single-host operation.
How VENTEX distinguishes implemented, internally evidenced, limited and planned capabilities.
Report security issues safely, understand scope and enable coordinated handling.
Selected product claims link directly to their full record in the public Evidence Center.
Double Ratchet is the default send path without a conversation allowlist; device envelopes, epochs and a downgrade guard support rotation and multi-device operation.
Direct identifiers have been removed from several stored communication paths or replaced by opaque conversation-scoped references.
Refresh tokens rotate and reuse revokes the affected token family.
Releases can be gated by types, tests, build, migration, smoke checks and signed release evidence.
Present in the delivered system and traceable in source.
Supported by automated tests or operational evidence.
Usable, but only within an explicitly stated boundary.
Audit, penetration test and deployment acceptance remain independent.