Shadewire · network

One backbone,
end to end.

Everything on this page describes systems we actually run. Where something is a limitation rather than a feature, it says so.

Two paths

A message and a device travel differently.

A message

Client

web · desktop · android

Shadewire ingress

tls termination

Application services

api · events · files · media proxy

Private datastore

database · object storage

A device

Your device

enrolled by the operator

Encrypted link

wireguard tunnel

Shadewire Mesh

self-hosted control plane

Private services

not published to the internet

Honest limits

What self-hosting does and doesn't buy you.

The operator can see server-side data

Messages are stored on our database so they can be delivered and searched. That means an administrator with access to the host can read them. This is true of every platform of this kind; the difference is who the administrator is, not that one doesn't exist. Shadewire does not offer end-to-end encrypted messaging today.

Transport is encrypted, storage is not magic

Traffic to every public hostname is TLS, and Mesh links are WireGuard. Data at rest sits on our disks under our physical control — which is a meaningful improvement over a third party holding it, and is not the same claim as zero-knowledge storage.

One operator is a single point of failure

There is no on-call rotation. Outages last as long as it takes one person to notice and fix them, and maintenance happens when there's time. Independence has a cost and this is most of it.

No advertising, no analytics, no resale

Nothing here is funded by attention. There is no advertising system to feed, no analytics vendor in the page, and no commercial reason for the data to go anywhere.

Running on the wire

Current state.

Read from the estate's own status feed. Stale or unreachable data is reported as such rather than shown as live.

ChatUnavailable
MeshUnavailable
InfrastructureUnavailable
Last reading—