Security overview and threat model
How Nampa protects your voice notes, and an honest account of what it can't protect against.
Voice notes are encrypted on the sender's device. Nampa stores encrypted audio and is designed so our systems cannot play your private notes. This isn't end to end encryption in the strict sense, and we won't call it that. While a note is alive, its key is held by a separate Nampa service so the recipient can open it. This page explains how that's protected, and where the limits are.
How a note travels
- You record on your phone, and the audio is encoded as Opus.
- Your phone makes a fresh 256 bit key for that one note and encrypts the audio with AES-256-GCM.
- The encrypted audio goes to our storage. The key goes to a separate key service over its own encrypted connection.
- The recipient's app fetches both, decrypts the note in memory and plays it. Nothing is written to their phone.
- After the replay, or 24 hours if it isn't played, the key service deletes the key and storage deletes the audio.
Keeping keys and audio apart
- The key service and audio storage run separately, with different credentials. Neither can reach the other's data.
- No member of staff has standing access to both. Any access to production systems needs a second person to approve it, and every access is logged.
- All connections use TLS 1.3, and the app only trusts our own certificates.
On your phone
- Playback screens are protected from screenshots and screen recording using the system protections iOS and Android provide.
- If screen recording starts, playback stops and the sender is told.
- Your voice key, if you set one up, never leaves your phone's secure enclave.
Threat model
What Nampa is designed to protect against, and what it isn't.
| Threat | Protected? |
|---|---|
| Someone breaks into our audio storage | Yes. They'd find only encrypted audio. The keys live in a separate service. |
| Someone watches the network | Yes. Notes are encrypted before they leave your phone, and every connection uses TLS. |
| A note after it has ended | Yes. The key and audio are deleted, so copies in backups can't be played. |
| Screenshots and screen recording | Mostly. Blocked on standard phones. A phone that has been rooted or jailbroken may get around it. |
| Someone with access to both the key service and audio storage while a note is alive | Partly. Separation, two person approval and logging make this hard. It's the main reason we don't call Nampa end to end encrypted. |
| A legal demand while a note is alive | Partly. Notes end within 24 hours at most, and we won't build tools to decrypt them. See our law enforcement policy. |
| Someone takes over your phone number | Partly. Signing in on a new phone alerts your old one, and notes sent before the takeover have usually already ended. |
| Malware on your phone or the recipient's | No. A compromised phone can hear notes as they play. |
| A second phone recording the speaker | No. No app can stop this. We'd rather say so than pretend. |
| Someone you trust repeating what you said | No. That's about trust between people, not technology. |
What we will never build
- A back door or master key.
- Any way to transcribe, analyse or quietly keep your notes.
- A way to turn off deletion for one person without telling them.
Independent review
Before public launch we'll have an independent firm review Nampa's security, and we'll publish a summary of what they found and what we fixed.
Reporting a security problem
If you find a weakness, write to hello@nampa.app. We'll reply within 3 working days and keep you updated until it's fixed. If you act in good faith, don't access other people's data and give us reasonable time to fix the problem, we won't take legal action against you. Our security.txt has the details in a standard format.
Questions
Write to hello@nampa.app. A person reads every message.