Quantum Message

Secure messaging, peer-to-peer

Post-quantum end-to-end encryption, direct device-to-device communication, full control over your data. Available as app, web app, and white-label or SDK solution.

End-to-End Encrypted Post-Quantum Ready P2P Communication Quantum-Safe File Sharing Cross-platform 🇮🇹 100% Italian technology
Alice
online
Hi! How's it going?
All good! Project is moving forward 🔒
Great, is the data safe?
ecdh+kyber encryption active ✓
📷 project_photo.jpg 🔒 encrypted

Why Post-Quantum cryptography matters today

The quantum threat is not a future problem: it's a concrete risk for the data you protect right now.

Harvest Now, Decrypt Later

Governments and malicious actors intercept and store encrypted communications today, waiting for a quantum computer capable of decrypting them. Your sensitive data of today will be readable tomorrow if protected only by classical cryptography.

💻

Quantum computing is advancing

IBM, Google, Microsoft, and governments are investing billions in quantum computer development. Shor's algorithm can break RSA, ECDH, and the elliptic curves that underpin today's cryptography. It's not a matter of "if", but "when".

📜

Regulations and standards

NIST has already published post-quantum standards (FIPS 203, 204, 205) in August 2024. The NSA requires migration to PQC by 2035. The European ENISA recommends immediate adoption of hybrid solutions. Those who don't comply remain exposed.

🏥

Long-lived sensitive data

Medical records, trade secrets, legal communications, financial data: information that must remain confidential for decades. If encrypted only with RSA or ECDH, it will be vulnerable within a few years.

🛡️

Qessage's answer

Qessage implements ML-KEM-768 (Kyber), the NIST FIPS 203 standard, in hybrid mode: classical + post-quantum cryptography together. Even if one of the two layers is compromised, your data stays protected.

NIST FIPS 203 ML-KEM-768 Classical + PQ hybrid
📅

Act now, not tomorrow

Migrating to post-quantum cryptography takes time. Adopting a PQ-ready solution like Qessage today means protecting data before the threat materializes, not after. Proactive security is the only real security.

Everything you need for secure communication

Qessage combines the simplicity of a modern messenger with enterprise-grade security.

🔐

E2E Encryption

Configurable hybrid encryption modes: ML-KEM-768 (Kyber) + ECDH P-521/RSA-2048. Messages are readable only by sender and recipient.

🛡️

Post-Quantum Ready

Hybrid modes combine classical and post-quantum cryptography (NIST FIPS 203). Even a future quantum computer won't be able to decrypt your messages.

P2P Communication

Messages travel directly between devices via WebRTC, without passing through the server. The server is only used as a delivery fallback.

📎

Pre-upload encrypted files

Every file is encrypted locally before sending. The server only receives opaque data with .enc extension. The AES key is wrapped for both sender and recipient: both can reopen their files.

📱

Cross-platform

Available for Android, iOS, Desktop and Web. A single codebase for all platforms, with a native user experience on each one.

🧬

Biometric login

After registration, protect access with fingerprint or Face ID. Fast and secure recognition at every app launch.

🗑️

Ephemeral messages

With deleteReadMessage enabled, messages are deleted from the server after delivery. No trace left on our systems.

🛡️

RASP protection

Root/jailbreak detection, hooking (Frida), debugger, emulator, and tampering detection via freeRASP. The app protects itself at runtime.

📊

Management console

Web dashboard for administrators: user, message, and group monitoring, real-time analytics, and remote system configuration.

Uncompromising security

Designed to withstand today's and tomorrow's threats.

Message AES-256 Encrypted
AES Key ECDH + Kyber Wrapped

Dual hybrid protection

Every message is encrypted with AES-256. The key is protected by combining two independent secrets (classical + post-quantum). Both private keys are needed to decrypt: breaking only RSA/ECDH or only Kyber is not enough.

TLS 1.2+ (transport)
DTLS/SRTP (WebRTC P2P)
E2E AES-256 (content)
AES-256 (media files)

Four layers of encryption

Transport is protected by TLS. P2P connection uses DTLS. Message content is end-to-end encrypted. Media files have their own independent AES-256 encryption. The server never sees cleartext data.

none
rsa
ecdh
kyber
rsa+kyber
ecdh+kyber

6 configurable modes

From "no encryption" for internal environments to "ecdh+kyber" for maximum security with forward secrecy and post-quantum protection. Mode can be changed remotely without updating the app.

Architecture built for resilience

Hybrid P2P/server system for maximum reliability and minimum latency.

Flutter App
Android iOS Web
Direct P2P
(WebRTC)
Server fallback
(Parse + LiveQuery)
Backend
Parse Server (Back4App) Cloud Functions LiveQuery (WebSocket)
Infrastructure
STUN/TURN (coturn) Firebase FCM SMS / Email / Entra ID

Your messaging app, your brand

Qessage is available as a fully customizable white-label solution.

🎨

Custom branding

Logo, colors, app name, and icons fully customizable. Your users will only see your brand.

🏢

Dedicated backend

Dedicated or on-premise Parse Server instance. Data stays in your systems, under your control.

🔧

Tailored configuration

Choose the authentication mode (phone, email, Entra ID), encryption level, and active features.

🏥

Vertical sectors

Healthcare, finance, public administration, defense, legal: each sector has specific requirements. Qessage adapts to your compliance needs.

📱

Autonomous publishing

Builds for Google Play, App Store, and web. Publish with your own developer account, no dependency on us.

🤝

Support and training

Assistance with customization, deployment, and team training. Ongoing technical support.

Ideal for

Organizations with sensitive data Public Administration Healthcare and telemedicine Law firms Financial institutions GDPR-compliant organizations Defense and security Confidential internal communications

Why Qessage

Comparison with the most popular alternatives.

Qessage WhatsApp Telegram Signal
Default E2E encryption Configurable ✓ Yes Secret chats only Yes
Post-quantum cryptography ML-KEM-768 ✓ No No PQXDH (partial)
Hybrid modes (classical + PQ) rsa+kyber, ecdh+kyber ✓ No No Yes (X25519+Kyber)
Direct P2P communication WebRTC ✓ No No No
On-premise backend Yes ✓ No No Yes (self-hosted)
White-label / customization Full ✓ No No Limited
Server-side ephemeral messages Yes ✓ Disappearing only Timer Timer
Media file encryption AES-256 pre-upload ✓ Yes Secret chats only Yes
Quantum-safe file sharing Hybrid ML-KEM-768 ✓ No No No
QKD integration (PQC + QKD) Yes ✓ No No No
Admin console Yes ✓ Business API No No
Runtime protection (RASP) freeRASP ✓ Proprietary No No
European digital sovereignty Italy / EU ✓ USA (Meta) UAE / Dubai USA
🇮🇹 🇪🇺

100% Italian technology, European sovereignty

Qessage is designed, developed, and maintained entirely in Italy by Quantum2Pi. No dependency on non-European big tech for code, cryptography, or infrastructure.

🏛️
GDPR and EU regulation compliant Data processed in compliance with the European Data Protection Regulation. Backend deployable on European infrastructure or on-premise.
🔐
Cryptography without backdoors Code developed in Italy, NIST/ISO standard algorithms. No non-EU government backdoor obligations (CLOUD Act, FISA).
🇪🇺
European digital sovereignty A concrete alternative to US and Asian messengers. Your data stays under European jurisdiction, without non-EU transfers.
🤝
Direct support Development and support team in Italy. No intermediaries, no time zones to manage. Direct point of contact for every need.

Get started today

Contact us for a demo, a proof-of-concept, or to discuss your custom white-label solution.

📧

Email

info@quantum2pi.com
🌐

Website

www.quantum2pi.com
💬

Live demo

Request access to the demo to try Qessage in action