COMPANY · ESTATE · ORBLINK
Messages nobody in the middle can read.
ORBLINK is the sealed-messaging system in the ORBIS.ID estate. People and organizations send each other messages that nobody between them can read — not because of a policy, but because of mathematics. This page describes what sealed messaging is, how it fits the platform, and what phase it is in today.
A message, a key, and no middle ground.
When an organization sends a message to a person, it encrypts that message with a key only the person can decrypt. The organization never learns where that key is, and the message never travels in a form the platform can read. Sealed messaging is not a feature that can be turned off. It is the shape of the thing.
Why sealed messaging matters in the estate.
Organisations use messages to send proofs, documents, and information to people. If a company holds those messages on a server and reads them to measure engagement or build profiles, the person has not really gained control — they have just switched from one kind of exposure to another. Sealed messaging means an organization can contact you without ever learning what it contacted you about.
How it connects to the wallet and the network.
A person holds a wallet full of proofs. An organization needs a way to send new proofs to that wallet — not through an app store, not through email, but through a direct sealed channel. ORBLINK is that channel. It is also the way an organization and a person can exchange documents, applications, or any message without the platform sitting in the middle reading it.
The claim, and no wider than that.
ORBLINK's own claim is narrow, on purpose: message content is encrypted end to end, and the relay that carries it stores ciphertext only. Its own thread header says the same thing plainly to the person reading it — "Only you and [name] can see this. Not even we can." Nothing about the security of the infrastructure around it is claimed beyond that one sentence.
Before you go any further.
There is no register row for sealed messaging. That is an absence, not a state, and the block below prints it as one rather than leaving the subject out.
The register holds 17 live · 2 partial · 2 planned · 5 not yet.
1 of the 1 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.
- sealed-messaging
The register route serves, but it carries no row for these yet. List what it does carry:
curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug' Straight answers.
- Is ORBLINK a chat app?
- In shape, yes — it carries messages, voice messages and calls between people who have established who each other is. What makes it a different animal is not the feature list. It is that the relay carrying all of it holds ciphertext and can read none of it, and that the key doing the talking is a key the phone's own hardware made.
- Can the platform read messages sent through ORBLINK?
- No. The encryption is built so that even ORBIS.ID cannot decrypt the messages. The platform carries them, but cannot read them.
- Who can use ORBLINK today?
- This depends on the phase of the feature. See the section above for what is built and what is coming.
One claim, made narrowly: the relay holds ciphertext and can read none of it. We are not going to decorate that with statements about the security of everything around it — naming the postures we are not claiming would leave you holding them anyway.
Do not trust us. Check us.