Home About
System Architecture

Zero-Knowledge Ephemeral Chat

SecureChat is a real-time communication platform engineered for operational security. No persistence, no accounts, no trace. When the room dies, everything dies with it.

What makes it different

๐Ÿ’พ
Volatile Memory Only
No database. No file writes. All state is held in thread-safe Python dicts โ€” gone on restart.
โšก
WebSocket-Native
Socket.IO with gevent workers. Every message travels over persistent connections.
๐Ÿ”ฅ
Auto-Purge Lifecycle
Rooms self-destruct after 60 minutes. Empty rooms are garbage-collected immediately.
๐Ÿ”’
Zero Logs
No logs. No trace. No user tracking. All session tokens are generated per-visit.
๐Ÿ–ผ๏ธ
EXIF Scrubbing
Images re-encoded through canvas, stripping GPS and device metadata.
โš–๏ธ
Host Authority
Room creators hold full moderation power with auto host-promotion on disconnect.

What we protect against

  • Server-side message interception โ€” messages never written to persistent storage
  • Identity tracking โ€” no accounts, no cookies tied to identity
  • Image metadata leakage โ€” EXIF data stripped from all uploads
  • Zombie rooms โ€” hard 60-minute TTL on all rooms
  • Reverse proxy timeouts โ€” Socket.IO tuned for cloud deployment
  • Server fingerprinting โ€” werkzeug header masked to prevent version disclosure
  • Flood attacks โ€” per-IP rate limiting with in-memory storage

Operational boundaries

Max simultaneous rooms20
Max peers per room100
Room lifetime60 minutes
Message buffer per room2,000 messages
Max message length4,000 characters
Max file attachment100 MB
Rate limit (per IP)2,000/day ยท 400/hr
Host recovery window20 seconds

Built with

Flask 3.0 Flask-SocketIO 5.4 gevent 24 gevent-websocket gunicorn 22 Flask-Talisman Flask-Limiter Socket.IO 4.7 Playfair Display DM Sans / DM Mono CSS Grid + Flexbox Canvas API
โ† Back to Home