Trust & Safety
Understanding what Atopos protects, what it limits, and how to use it responsibly.
- Plain-English Threat Model — What we protect, what we limit, and what we cannot protect against.
- Local keys & Extra Lock — How keys work and how to manage them.
- Threat model vs marketing myths — Honest limits vs exaggerated claims.
How Atopos compares
| Atopos | Signal | Wire | ||
|---|---|---|---|---|
| End-to-end encryption | Yes | Yes | Yes | Yes |
| No phone number required | Yes | No | No | Yes (email) |
| Server-blind (server never has keys) | Verified — see the claims matrix | Claimed | Claimed | Claimed |
| Published threat model | Yes | Partial | Partial (encryption whitepaper) | Yes |
| TLA+ state-machine invariants (protocol-level: no double-spend, epoch binding, no cross-room redeem. Not a cryptographic proof of primitives.) | Yes | Protocol only | No first-party | Protocol only (MLS) |
| Verifiable security evidence | Machine-runnable | Partial (public formal models) | Partial (auditable key transparency) | Published audit reports |
| Monero payment option | Yes | No | No | No |
| Offline room creation | Yes (CLI) | No | No | No |
| Open source | Security docs + evidence public; full source mirror publication in progress | Yes (anti-spam module private) | No | Yes |
This comparison reflects our understanding as of September 2026, checked against public primary sources. We encourage you to verify each claim independently.