Shadewire · network
One backbone,
end to end.
Everything on this page describes systems we actually run. Where something is a limitation rather than a feature, it says so.
Two paths
A message and a device travel differently.
A message
Client
Shadewire ingress
Application services
Private datastore
A device
Your device
Encrypted link
Shadewire Mesh
Private services
Honest limits
What self-hosting does and doesn't buy you.
The operator can see server-side data
Messages are stored on our database so they can be delivered and searched. That means an administrator with access to the host can read them. This is true of every platform of this kind; the difference is who the administrator is, not that one doesn't exist. Shadewire does not offer end-to-end encrypted messaging today.
Transport is encrypted, storage is not magic
Traffic to every public hostname is TLS, and Mesh links are WireGuard. Data at rest sits on our disks under our physical control — which is a meaningful improvement over a third party holding it, and is not the same claim as zero-knowledge storage.
One operator is a single point of failure
There is no on-call rotation. Outages last as long as it takes one person to notice and fix them, and maintenance happens when there's time. Independence has a cost and this is most of it.
No advertising, no analytics, no resale
Nothing here is funded by attention. There is no advertising system to feed, no analytics vendor in the page, and no commercial reason for the data to go anywhere.
Running on the wire
Current state.
Read from the estate's own status feed. Stale or unreachable data is reported as such rather than shown as live.