Security and trust
Clear security boundaries
Zaloba describes only protections and capabilities that are currently supported. Planned capabilities are labelled as such.
Current principles
Encrypted transport
Public production endpoints are prepared for HTTPS and secure WebSocket transport. Zaloba does not promise a specific negotiated TLS version on every client.
Fail-closed access
The browser application remains gated while its approved linked-device authentication flow is incomplete. It does not fabricate a successful session.
Honest capability claims
Zaloba does not claim Signal Protocol, end-to-end encryption, passkeys, per-device cryptographic identity, or deployed calling infrastructure on this site.
Current operational boundaries
- Browser QR linking, linked-device sessions, and remote revocation remain gated until the approved authentication flow is available.
- Calling, conference rooms, media relays, and screen-sharing capacity are not represented as active production capabilities here.
- The 48-hour Status lifetime describes the active product lifecycle; it is not a promise that every expired object disappears immediately from every backup or storage layer.
- This public site does not load advertising or social-network tracking code.
Responsible disclosure
If you identify a security issue in Zaloba or Lienskill Limited infrastructure, contact the security team with enough detail to investigate safely.
security@lienskill.com