OSL

What works today

OSL is in early access before its v1 launch. This page is the honest, dated record of what the shipping app actually does. Every feature page on this site links here. Matrix version 2026-07-31.

The rest of this site describes OSL v1 — the product we are building toward. This page is the exception: nothing here is forward-looking. If a capability is not listed as working below, do not rely on it, and do not buy Pro expecting it.

Local data at rest #

At-rest status: source-inspected and focused-test evidence only; no named release or existing profile was verified. The Hub identity path requires a persistent TPM or operating-system credential-store sealer; accepted message and attachment-cache values are sealed before SQLite writes; and several Hub record writers require the file-storage key. SQLite structure remains visible, while peer-map, membership, other conditional JSON, Hub configuration, renderer localStorage, provider-managed profiles, the active-slot marker, and a fixed-label startup trace can be plaintext. Opened plaintext exists in memory while displayed. Notes is implemented but not wired into the source-inspected production app; Scrub-index code is excluded from present-tense claims because its production reachability is unproved, and attachment behavior remains Planned despite source reachability.

Working today #

Proven on test builds against a real conversation. Not yet proven on a numbered release build, which is why none of these is labelled Available.

Capabilities that work in the shipping app
CapabilityStatusLast verifiedWhat that means
Per-message hybrid sealingBeta2026-07-26Working. Every direct message is sealed to the recipient keys with a fresh key of its own, combining X25519 with post-quantum ML-KEM-768. Proven on test builds against a real conversation, not yet on a numbered release build.
Protected text send and readBeta2026-07-26Working on Discord. Sending and reading protected text is proven on test builds. Discord is the only connector qualified so far.

Not in the shipping app yet #

These are part of OSL v1 and are described elsewhere on this site as the product we are building. None of them is finished today.

Capabilities still being finished before v1
CapabilityStatusLast verifiedWhere it actually stands
Cover text carrierPlanned2026-07-26Not yet. The readable text never reaches the connected service, but what the service currently receives is an obvious encrypted block rather than an innocuous-looking message. The natural-language cover mode is switched off in the current build because the post-quantum wire is too large for it.
Encrypted image sendingPlanned2026-07-26Not in the shipping app yet. The encryption for images is written and the picker accepts PNG and JPEG, but nothing in the released app drives it end to end. This is not part of what a Pro purchase gives you today.
Non-image file sendingPlanned2026-07-26Not yet. Only PNG and JPEG are offered; other file types are not supported.
Group chat and server channel protectionPlanned2026-07-26Not yet. Group and channel protection is switched off in the shipping app, and the messages it would build carry no signature identifying the sender. Treat anything you write in a group or channel as unprotected.
Old-message protectionPlanned2026-07-26Not yet. The mechanism that would keep old messages safe if a key is later stolen is written and tested but deliberately switched off pending independent review.
Attachment Privacy GuardPlanned2026-07-26Not yet. Stripping hidden details out of a file before encrypting it is written but nothing in the shipping app calls it. Assume a file you send still carries its original details.
Before-send warningPlanned2026-07-26Not yet. The detection code exists and is tested, but nothing in the shipping app calls it, so OSL does not warn you today.
Timed expiryPlanned2026-07-26Not yet. Timed deletion is not wired into the shipping app.
View oncePlanned2026-07-26Not yet. Components are built; the production wiring and the two-party consent it requires are incomplete.
BurnPlanned2026-07-26Not yet as a peer action. When it lands, burn deletes OSL local and server-side state and asks the other side to delete too. It does not destroy anyone ability to decrypt what the service already holds, and it cannot recall a screenshot.
Link protectionPlanned2026-07-26Not yet. This is a design intention with no code behind it.
Scrub discoveryPlanned2026-07-27Not yet. Current source can fall back to generic JSON when a provider parser refuses an export, so provider identity, archive inventory, media bytes and completeness are not reliably bound. Google, Discord, Meta, X and WhatsApp exports are not qualified end to end.
Guided deletion handoffPlanned2026-07-26Not yet, and further off than a dependency on discovery would suggest. The part of the app that would actually carry out a guided deletion is not connected: it holds every candidate and does not open the page, choose the delete action, confirm it, or check that it worked. When it does land, OSL will take you to the page and you confirm each removal yourself — OSL will not delete on your behalf.
AutoScrubPlanned2026-07-26Not yet. What exists is switched-off interface scaffolding, not a working engine — the app itself says it is unavailable in this build. AutoScrub is also the one optional closed-source module, it is not installed by default, and it would need your explicit consent to download.
AI-generated carrier textPlanned2026-07-26Not yet. Opt-in AI-written cover text. Cloud generation is never end-to-end private, because the service has to see the text it is working on.
Processing creditsPlanned2026-07-26Not yet, and not on sale. Credits would be bought separately and never renew.
Automatic Pro expiryPlanned2026-07-26Not yet. A purchased code currently unlocks Pro without a redemption clock, so the month does not yet start when you enter the code.

Connector support #

A logo appearing anywhere on this site never implies support. This table is the only place that says which services are supported.

Versioned connector support matrix
ConnectorProtected sendProtected receiveAttachmentsScrubLast verifiedStatusProvider policy risk
DiscordBetaBetaPlannedPlanned2026-07-31BetaDiscord forbids automating normal user accounts outside its OAuth2/bot API. OSL has no Discord approval; use may put the account at risk.
SignalPlannedPlannedPlannedNot applicable2026-07-31Coming soonNot qualified by OSL: no two-peer proof on any build. Signal Desktop's own screen-security behavior can make companion viewing unavailable.
WhatsAppPlannedPlannedPlannedNot applicable2026-07-31Coming soonNot qualified by OSL: no two-peer proof on any build. WhatsApp restricts auto-messaging, non-personal use, unofficial apps, and scraping.
TelegramExternally blockedExternally blockedExternally blockedNot applicable2026-07-31Externally blockedTelegram remains externally blocked for OSL: current provider issue records still show unreliable message and control accessibility. OSL will not fake support.
Outlook / OSL MailPlannedPlannedPlannedPlanned2026-07-31Coming soonScoped as OSL Mail, not ordinary chat support. Microsoft and Google mail terms/support are live inputs, but OSL has no mail-specific proof.

Illustrations, not measurements #

  • Country exposure comparison Illustration — A drawing, not a measurement. The homepage comparison summarises published agency and company practice. It is not a scan of your device, and this site never shows a live protection score.
  • Product animations Illustration — Drawings, not recordings. Every animated scene on this site illustrates intended behaviour rather than showing the app running.

How to read the labels #

  • Available — proven on a numbered release build. Nothing carries this label yet.
  • Beta — the code does it and it has been exercised on a test build. Expect rough edges.
  • Planned — part of v1, not finished. Some of it is written but not connected; some is design only.
  • Externally blocked — a third party does not expose what OSL would need. We will not fake support.
  • Illustration — a drawing of intended behaviour, not a recording or a measurement.

Not independently audited #

OSL uses a custom encryption construction that has not been independently audited, and no provider has tested, reviewed or approved it. If your threat model is high-stakes — legal investigation or targeted surveillance — use Signal, Briar or Cwtch instead. An internal source review is published on the audit page.

Protecting message content does not hide metadata. A connected service still sees who you talk to, when, and how often. OSL cannot change that.