SECURITY FOUNDATION
ML-KEM-1024 + Signal Protocol
PQXDH, Double Ratchet, Sender Keys, and explicit downgrade prevention.
COMPLETED Arc PRODUCT SPECIFICATION
These eleven capabilities form one completed product specification and are evaluated together as Arc.
Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.
The short answer
These eleven capabilities form one completed product specification and are evaluated together as Arc.
ML-KEM-1024 + Signal Protocol
PQXDH, Double Ratchet, Sender Keys, and explicit downgrade prevention.
IGF + Mutual Burn
Timer, read, and tap events converge on durable device/server retirement.
Ogg Opus voice at 16 kbps + Mesh
COMPLETED Arc PRODUCT SPECIFICATION
These eleven capabilities form one completed product specification and are evaluated together as Arc.
Product focus is also a security decision. Arc removes or rejects behavior that weakens message integrity, user control, or operational clarity.
Being encrypted, being end-to-end encrypted, and using post-quantum protection are distinct concepts that can be layered.
A broad term covering transport encryption such as TLS and server-side storage encryption. The operator may hold keys and be able to access plaintext.
Only conversation endpoints hold the content keys, so the service operator should not be able to read message plaintext. Encrypted does not automatically mean E2EE.
Hybrid post-quantum session establishment with classical key agreement and no silent downgrade to a legacy path.
The 19 market products are grouped by the encryption baseline, documented E2EE availability, and documented post-quantum status.
Transport and server-side storage protection form the baseline category.
Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.
Whether public documentation says the service operator cannot read message plaintext.
Publicly documented status of protection designed for quantum-era attacks.
Tier classification by total score and use case. S Tier emphasizes privacy and modern cryptography; D Tier covers productivity tools without E2EE.
Signal
#1
Arc
#2
iMessage
#3
Threema
#4
Wire
#5
#6
Element / Matrix
#7
Facebook Messenger
#8
Session
#9
Google Messages
#10
Viber
#11
LINE
#12
Telegram
#13
XChat
#14
KakaoTalk
#15
Google Chat
#16
Discord
#17
Slack
#18
Chatwork
#19
Instagram DM
#20
Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.
| Service | Crypto (18) | FB Sec (14) | PQC (14) | E2EE (13) | Sender (10) | Reg (10) | Ephem (11) | Verify (5) | Multi-Dev (5) | Total |
|---|---|---|---|---|---|---|---|---|---|---|
#1 Signal | 18 | 14 | 14 | 13 | 10 | 6 | 5 | 5 | 5 | 90 |
#2 Arc | 18 | 14 | 14 | 12 | 3 | 9 | 11 | 4 | 4 | 89 |
#3 iMessage | 17 | 13 | 14 | 13 | 5 | 4 | 1 | 4 | 5 | 76 |
#4 Threema | 16 | 13 | 2 | 12 | 7 | 10 | 5 | 4 | 3 | 72 |
#5 Wire | 16 | 13 | 4 | 11 | 5 | 7 | 6 | 4 | 5 | 71 |
#6 WhatsApp | 18 | 13 | 7 | 11 | 0 | 4 | 5 | 4 | 5 | 67 |
#7 Element / Matrix | 13 | 12 | 1 | 10 | 4 | 8 | 3 | 4 | 5 | 60 |
#8 Facebook Messenger | 15 | 11 | 0 | 10 | 0 | 4 | 5 | 4 | 5 | 54 |
#9 Session | 9 | 2 | 1 | 10 | 10 | 10 | 5 | 3 | 3 | 53 |
#10 Google Messages | 15 | 11 | 0 | 8 | 0 | 1 | 2 | 3 | 4 | 44 |
#11 Viber | 10 | 9 | 1 | 7 | 0 | 1 | 4 | 3 | 4 | 39 |
#12 LINE | 13 | 3 | 0 | 9 | 0 | 4 | 2 | 4 | 3 | 38 |
#13 Telegram | 10 | 7 | 0 | 3 | 0 | 4 | 4 | 4 | 5 | 37 |
#14 XChat | 11 | 0 | 0 | 4 | 0 | 9 | 2 | 2 | 5 | 33 |
#15 KakaoTalk | 7 | 4 | 0 | 3 | 0 | 1 | 2 | 2 | 4 | 23 |
#16 Google Chat | 10 | 0 | 0 | 4 | 0 | 1 | 1 | 0 | 5 | 21 |
#17 Discord | 7 | 3 | 0 | 3 | 0 | 1 | 0 | 0 | 5 | 19 |
#18 Slack | 10 | 0 | 0 | 0 | 0 | 1 | 1 | 0 | 5 | 17 |
#19 Chatwork | 8 | 0 | 0 | 0 | 0 | 1 | 0 | 0 | 5 | 14 |
#20 Instagram DM | 5 | 0 | 0 | 0 | 0 | 1 | 4 | 0 | 4 | 14 |
Crypto/ Cryptographic Primitives
(18)Algorithm design quality, AEAD and signature schemes, and formal-verification history
FB Sec/ Forward/Backward Secrecy
(14)Protection of past and future messages after key compromise, such as Double Ratchet or MLS
PQC/ Post-Quantum
(14)Publicly documented production status of post-quantum cryptography such as PQXDH or ML-KEM
E2EE/ E2EE Coverage
(13)Default status and coverage across text, calls, groups, and media, including public audit evidence
Sender/ Sender Privacy
(10)Sender and relationship-metadata minimization, including Sealed Sender or onion routing
Reg/ Registration Privacy
(10)Availability of signup without a phone number or email and of an anonymous identifier
Ephem/ Ephemeral Messages
(11)Granularity and lifecycle of disappearing-message controls
Verify/ Verification UX
(5)Usability of key verification, such as Safety Numbers or contact-key verification
Multi-Dev/ Multi-Device
(5)Cross-device key handling without an always-online primary phone
Total
(100)Weighted sum across 9 axes (maximum 100)
Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.
Primary-source evidence checked 2026-08-26
Each primary source supports only the category where it is cited; it does not substantiate every claim or score and does not imply vendor endorsement.
Total 90 / 100
Documented status
Primary sources
Total 89 / 100
Standardized ML-KEM-1024 + PQXDH · Double Ratchet DM · Sender Keys Groups · Sealed Sender + anonymous delivery · IGF · Mutual Burn · Key Sync + multi-device · Ogg Opus voice at 16 kbps · Signed direct Mesh DM and Group · Direct Mesh E2EE DM · Bounded multi-hop and store-and-forward
Total 76 / 100
Documented status
Primary sources
Total 72 / 100
Documented status
Primary sources
Total 71 / 100
Documented status
Primary sources
Total 67 / 100
Documented status
Primary sources
Total 60 / 100
Documented status
Primary sources
Total 54 / 100
Documented status
Primary sources
Total 53 / 100
Documented status
Primary sources
Total 44 / 100
Documented status
Primary sources
Total 39 / 100
Documented status
Primary sources
Total 38 / 100
Documented status
Primary sources
Total 37 / 100
Documented status
Primary sources
Total 33 / 100
Documented status
Primary sources
Total 23 / 100
Documented status
Primary sources
Total 21 / 100
Documented status
Primary sources
Total 19 / 100
Documented status
Primary sources
Total 17 / 100
Documented status
Primary sources
Total 14 / 100
Documented status
Primary sources
Total 14 / 100
Documented status
Primary sources
These eleven capabilities form one completed product specification and are evaluated together as Arc.
Strong content encryption does not hide sender relationships by itself. Sealed Sender and anonymous delivery are treated as independent product work.
Arc separates signed non-E2EE disaster communication from E2EE Mesh DM and labels the active mode instead of blurring the distinction.
IGF and Mutual Burn are designed around durable device/server retirement, retry, and recovery—not only disappearing UI.
Concise answers to the questions readers and answer engines ask most often about Arc's security and disaster communication design.
Hybrid post-quantum session establishment with classical key agreement and no silent downgrade to a legacy path.
Atomic ratchet advancement, exact-ciphertext retry, bounded skipped keys, and crash-safe recovery for normal one-to-one chat.
Per-sender, per-device group epochs with membership fencing and SKDM delivery over authenticated one-to-one sessions.
Purpose-separated sender certificates, opaque recipient inboxes, generic push, and a no-plaintext-fallback rule.
Direct disaster messaging with authenticated origin and integrity, explicitly labeled non-E2EE because relays or nearby observers may see content.
A separate direct-message mode with end-to-end encrypted content, explicit trust state, and no silent fallback to signed non-E2EE delivery.
Resource-bounded relay, deduplication, TTL, and offline recovery without claiming a guaranteed distance, route, or delivery time.
Security
Arc Security Details
These eleven capabilities form one completed product specification and are evaluated together as Arc.
Technology
Arc Technology
These eleven capabilities form one completed product specification and are evaluated together as Arc.