Early Access

GhostWire

Private channels your business owns — not a consumer messenger alternative.

Overview

What GhostWire is.

Most of what businesses call "secure messaging" is a consumer chat app with a padlock icon bolted on. GhostWire starts from a different brief: a communications channel your business actually owns, built for conversations where the record, the delivery guarantee and the key material all need to answer to you — not to a platform.

At its core is a zero-knowledge, store-and-forward relay. Messages move through an anonymous relay layer that cannot read what it carries, each delivery is HMAC-signed so tampering is detectable, and keys are managed on your terms rather than pooled inside someone else's identity graph. The result is a channel built for boardrooms, deal teams and incident responders, not group chats.

GhostWire is in Early Access. The relay is deployed and under active hardening, with a small set of partner organisations shaping the roadmap directly with our engineers. It is not a general-purpose replacement for your everyday team chat — it is the private line you stand up when the conversation genuinely can't sit on a consumer platform.

Capabilities

What it does.

Delivery & Relay

Store-and-forward relay

Messages traverse an anonymous relay layer designed so no single node holds the full picture of sender, recipient and content at once.

HMAC-signed delivery

Every message is signed on send and verified on receipt, so tampering or replay in transit is detectable, not assumed away.

Delivery confirmation

Senders get a verifiable record that a message reached its recipient, without the relay itself needing to read the payload.

Anonymous routing

The relay is built to minimise metadata leakage between parties, keeping who-talked-to-whom out of a central log.

Keys & Identity

Zero-knowledge architecture

Content is encrypted such that the relay operator cannot read message payloads — only the intended parties hold the keys.

Organisation-owned key management

Keys are provisioned and rotated under your organisation's control, not held in a shared vendor identity system.

Device-bound sessions

Sessions are tied to authorised devices, so a lost or compromised endpoint doesn't quietly become a standing backdoor.

Key rotation

Rotation policies are configurable per organisation, so long-lived channels don't run for years on the same key material.

Governance & Audit

Full audit trail

Delivery events are logged in a tamper-evident trail, so who sent what, when and to whom is answerable after the fact.

Retention controls

Retention windows are set by your organisation's policy, not a fixed platform default.

Access policies

Channel membership and access are governed by policies your organisation defines and can revoke instantly.

Compliance-ready export

Audit records can be exported for legal, compliance or incident-response review without depending on the relay operator.

Architecture

How it's built.

GhostWire's architecture is deliberately linear: a message enters as plaintext on a client, and every layer after that exists to reduce what any single party — including Pharoah — can see, tamper with, or lose.

Client apps encrypt on-device before anything leaves the endpoint. That encrypted envelope is what actually crosses the wire; the anonymous relay stores and forwards it without the ability to decrypt it. Delivery is HMAC-verified at the recipient end, and every step is written to an audit trail that your organisation controls.

It's a small number of layers on purpose. Fewer moving parts means fewer places for a mistake, a subpoena, or a misconfigured integration to turn a private channel into a leaky one.

Client appsMessages are composed and encryptedon-device before they ever leave …Encrypted envelopeThe encrypted payload — not plaintext — iswhat actually transits the network.Anonymous re…A relay layer stores and forwards theenvelope without the ability to read …HMAC-verified deliveryEach delivery is cryptographically signedand verified, so tampering in transit…Audit trailDelivery events are recorded in atamper-evident log your organisat…

GhostWire architecture, in order

  1. Client apps: Messages are composed and encrypted on-device before they ever leave the endpoint.
  2. Encrypted envelope: The encrypted payload — not plaintext — is what actually transits the network.
  3. Anonymous relay (store-and-forward): A relay layer stores and forwards the envelope without the ability to read its contents.
  4. HMAC-verified delivery: Each delivery is cryptographically signed and verified, so tampering in transit is detectable.
  5. Audit trail: Delivery events are recorded in a tamper-evident log your organisation controls and can export.
Use Cases

Who it's built for.

Executive and board communications

Leadership teams need a channel for sensitive strategy discussions that doesn't sit on the same platform as everyday team chatter.

Legal and compliance-sensitive correspondence

Conversations that may become discoverable or privileged need a verifiable, auditable record with organisation-controlled retention.

Cross-border deal teams

M&A and investment teams working across jurisdictions need a private channel they own outright, independent of any single counterparty's tooling.

Incident response coordination

Security and incident-response teams need a channel that stays reachable and auditable even when primary corporate systems are the ones under investigation.

FAQ

Straight answers.

Is GhostWire available today?

GhostWire is in Early Access. The relay is deployed and under active hardening, and a limited number of partner organisations are onboarding directly with our engineering team. Access is by consultation, not open sign-up.

Is GhostWire a consumer messaging app?

No. GhostWire is built for businesses that need a private channel they own — not as a like-for-like swap for a consumer chat app or your everyday team chat tool.

What does "store-and-forward relay" mean?

Messages are held briefly by an anonymous relay and forwarded to the recipient, without the relay being able to read the content it's carrying.

How are messages authenticated?

Every message is HMAC-signed on send and verified on delivery, so tampering or replay in transit is detectable rather than assumed away.

Who controls the encryption keys?

Your organisation does. Keys are provisioned, rotated and revoked under your control rather than held in a shared vendor identity system.

Can we audit who sent what, and when?

Yes. Every delivery event is written to a tamper-evident audit trail that your organisation controls and can export for legal or compliance review.

Is GhostWire zero-knowledge?

Yes. Content is encrypted so that the relay operator — including Pharoah — cannot read message payloads in transit.

What does Early Access actually involve?

A small cohort of organisations onboard directly with our engineers, with hands-on setup, direct input into the roadmap, and priority access as features harden.

How do we get access?

Book a consultation. Early Access is guided, not self-serve, so we can match onboarding to your organisation's security requirements.

What kind of organisations is GhostWire built for?

Regulated businesses, legal and deal teams, and any organisation whose most sensitive conversations shouldn't sit on a general-purpose platform.

Is there a public roadmap?

The roadmap is being shaped in the open with Early Access partners rather than published as a fixed public plan — it changes as real deployments surface real requirements.

Does GhostWire replace our existing team chat tool?

No, and it isn't meant to. GhostWire is a dedicated, owned channel for conversations too sensitive for a shared platform, sitting alongside your everyday tools rather than replacing them.

Engagement

How to work with us.

GhostWire is delivered through Early Access, not a self-serve checkout. Organisations onboard directly with our engineering team so key management, retention policy and access control are configured against your actual requirements before the first message ever moves.

Engagement is consultation-first and scoped to your organisation. There is no published self-serve price during Early Access.

Ready to talk about GhostWire?

Private channels your business owns — not a consumer messenger alternative.