COMPLETED Arc PRODUCT SPECIFICATION

COMPLETED Arc PRODUCT SPECIFICATION

These eleven capabilities form one completed product specification and are evaluated together as Arc.

COMPLETED Arc PRODUCT SPECIFICATIONPUBLICLY DOCUMENTED MARKET SNAPSHOT · 2026-07-31Arc · 2026-08-26

Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.

The short answer

COMPLETED Arc PRODUCT SPECIFICATION

These eleven capabilities form one completed product specification and are evaluated together as Arc.

SECURITY FOUNDATION

ML-KEM-1024 + Signal Protocol

PQXDH, Double Ratchet, Sender Keys, and explicit downgrade prevention.

DATA CONTROL

IGF + Mutual Burn

Timer, read, and tap events converge on durable device/server retirement.

RESILIENCE

Ogg Opus voice at 16 kbps + Mesh

COMPLETED Arc PRODUCT SPECIFICATION

Arc

COMPLETED Arc PRODUCT SPECIFICATION

These eleven capabilities form one completed product specification and are evaluated together as Arc.

COMPLETED Arc PRODUCT SPECIFICATION

Standardized ML-KEM-1024 + PQXDH

COMPLETED Arc PRODUCT SPECIFICATION

Double Ratchet DM

COMPLETED Arc PRODUCT SPECIFICATION

Sender Keys Groups

COMPLETED Arc PRODUCT SPECIFICATION

Sealed Sender + anonymous delivery

COMPLETED Arc PRODUCT SPECIFICATION

IGF

COMPLETED Arc PRODUCT SPECIFICATION

Mutual Burn

COMPLETED Arc PRODUCT SPECIFICATION

Key Sync + multi-device

COMPLETED Arc PRODUCT SPECIFICATION

Ogg Opus voice at 16 kbps

COMPLETED Arc PRODUCT SPECIFICATION

Signed direct Mesh DM and Group

COMPLETED Arc PRODUCT SPECIFICATION

Direct Mesh E2EE DM

COMPLETED Arc PRODUCT SPECIFICATION

Bounded multi-hop and store-and-forward

What Arc deliberately leaves out

Product focus is also a security decision. Arc removes or rejects behavior that weakens message integrity, user control, or operational clarity.

  • No Group Mutual Burn: Mutual Burn remains a one-to-one agreement.
  • Read-or-Lose is retired: important unread messages are not destroyed merely because time passed.
  • No silent downgrade from PQXDH, Sealed Sender, or Mesh E2EE to a weaker mode.
  • No embedded AI personalities, translation models, pet assistants, or summary models inside Arc's messaging core.
  • Mesh E2EE Group is outside the core product promise; signed non-E2EE Group and E2EE DM remain separate modes.

Encryption vs. E2EE vs. PQC

Being encrypted, being end-to-end encrypted, and using post-quantum protection are distinct concepts that can be layered.

Layer 1 · BASIC

Encryption

A broad term covering transport encryption such as TLS and server-side storage encryption. The operator may hold keys and be able to access plaintext.

Layer 2 · STRONG

End-to-End Encryption (E2EE)

Only conversation endpoints hold the content keys, so the service operator should not be able to read message plaintext. Encrypted does not automatically mean E2EE.

Layer 3 · QUANTUM-SAFE

Post-Quantum Cryptography (PQC)

Hybrid post-quantum session establishment with classical key agreement and no silent downgrade to a legacy path.

Encryption / E2EE / PQC Classification

The 19 market products are grouped by the encryption baseline, documented E2EE availability, and documented post-quantum status.

Encryption (TLS + server-side)

20 / 20

Transport and server-side storage protection form the baseline category.

Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.

Signal90
Arc89
iMessage76
Threema72
Wire71
WhatsApp67
Element / Matrix60
Facebook Messenger54
Session53
Google Messages44
Viber39
LINE38
Telegram37
XChat33
KakaoTalk23
Google Chat21
Discord19
Slack17
Chatwork14
Instagram DM14

E2EE (End-to-End Encryption)

Whether public documentation says the service operator cannot read message plaintext.

E2EE by default(9)
Signal90
iMessage76
Threema72
Wire71
WhatsApp67
Facebook Messenger54
Session53
Viber39
Arc89
Limited / partial / opt-in(7)
Element / Matrix60
Google Messages44
LINE38
Telegram37
XChat33
KakaoTalk23
Discord19
No verified first-party evidence found(4)
Google Chat21
Slack17
Chatwork14
Instagram DM14

PQC (Post-Quantum Cryptography)

Publicly documented status of protection designed for quantum-era attacks.

Production deployed(3)
Signal90
iMessage76
Arc89
Research / planning(2)
Wire71
Session53
No verified first-party evidence found(15)
Threema72
WhatsApp67
Element / Matrix60
Facebook Messenger54
Google Messages44
Viber39
LINE38
Telegram37
XChat33
KakaoTalk23
Google Chat21
Discord19
Slack17
Chatwork14
Instagram DM14

Tier Ranking

Tier classification by total score and use case. S Tier emphasizes privacy and modern cryptography; D Tier covers productivity tools without E2EE.

S Tier85+Privacy-focused + state-of-the-art cryptography

Signal

#1

90

Arc

#2

89
A Tier60–84E2EE sufficient for personal privacy

iMessage

#3

76

Threema

#4

72

Wire

#5

71

WhatsApp

#6

67

Element / Matrix

#7

60
B Tier40–59Some E2EE, with design constraints

Facebook Messenger

#8

54

Session

#9

53

Google Messages

#10

44
C Tier20–39Custom or limited E2EE, with reliability concerns

Viber

#11

39

LINE

#12

38

Telegram

#13

37

XChat

#14

33

KakaoTalk

#15

23

Google Chat

#16

21
D Tier<20Not designed for confidential personal messaging

Discord

#17

19

Slack

#18

17

Chatwork

#19

14

Instagram DM

#20

14

9-Axis Scoring (out of 100)

Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.

Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.
Service
Crypto
(18)
FB Sec
(14)
PQC
(14)
E2EE
(13)
Sender
(10)
Reg
(10)
Ephem
(11)
Verify
(5)
Multi-Dev
(5)
Total
#1 Signal
1814141310655590
#2 Arc
1814141239114489
#3 iMessage
171314135414576
#4 Threema
161321271054372
#5 Wire
16134115764571
#6 WhatsApp
18137110454567
#7 Element / Matrix
13121104834560
#8 Facebook Messenger
15110100454554
#9 Session
92110101053353
#10 Google Messages
1511080123444
#11 Viber
109170143439
#12 LINE
133090424338
#13 Telegram
107030444537
#14 XChat
110040922533
#15 KakaoTalk
74030122423
#16 Google Chat
100040110521
#17 Discord
73030100519
#18 Slack
100000110517
#19 Chatwork
80000100514
#20 Instagram DM
50000140414

Axis Legend

Crypto/ Cryptographic Primitives

(18)

Algorithm design quality, AEAD and signature schemes, and formal-verification history

FB Sec/ Forward/Backward Secrecy

(14)

Protection of past and future messages after key compromise, such as Double Ratchet or MLS

PQC/ Post-Quantum

(14)

Publicly documented production status of post-quantum cryptography such as PQXDH or ML-KEM

E2EE/ E2EE Coverage

(13)

Default status and coverage across text, calls, groups, and media, including public audit evidence

Sender/ Sender Privacy

(10)

Sender and relationship-metadata minimization, including Sealed Sender or onion routing

Reg/ Registration Privacy

(10)

Availability of signup without a phone number or email and of an anonymous identifier

Ephem/ Ephemeral Messages

(11)

Granularity and lifecycle of disappearing-message controls

Verify/ Verification UX

(5)

Usability of key verification, such as Safety Numbers or contact-key verification

Multi-Dev/ Multi-Device

(5)

Cross-device key handling without an always-online primary phone

Total

(100)

Weighted sum across 9 axes (maximum 100)

20-product evidence and specification cards

Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.

Primary-source evidence checked 2026-08-26

Each primary source supports only the category where it is cited; it does not substantiate every claim or score and does not imply vendor endorsement.

#2 Arc

S

Total 89 / 100

Standardized ML-KEM-1024 + PQXDH · Double Ratchet DM · Sender Keys Groups · Sealed Sender + anonymous delivery · IGF · Mutual Burn · Key Sync + multi-device · Ogg Opus voice at 16 kbps · Signed direct Mesh DM and Group · Direct Mesh E2EE DM · Bounded multi-hop and store-and-forward

#4 Threema

A

Total 72 / 100

#7 Element / Matrix

A

Total 60 / 100

Documented status

E2EE · Limited / partial / opt-inPQC · No verified first-party evidence found

Primary sources

#8 Facebook Messenger

B

Total 54 / 100

#10 Google Messages

B

Total 44 / 100

#11 Viber

C

Total 39 / 100

Documented status

E2EE · E2EE by defaultPQC · No verified first-party evidence found

Primary sources

#12 LINE

C

Total 38 / 100

Documented status

E2EE · Limited / partial / opt-inPQC · No verified first-party evidence found

Primary sources

#13 Telegram

C

Total 37 / 100

Documented status

E2EE · Limited / partial / opt-inPQC · No verified first-party evidence found

Primary sources

#14 XChat

C

Total 33 / 100

Documented status

E2EE · Limited / partial / opt-inPQC · No verified first-party evidence found

Primary sources

#15 KakaoTalk

C

Total 23 / 100

Documented status

E2EE · Limited / partial / opt-inPQC · No verified first-party evidence found

Primary sources

#17 Discord

D

Total 19 / 100

#18 Slack

D

Total 17 / 100

Documented status

E2EE · No verified first-party evidence foundPQC · No verified first-party evidence found

Primary sources

#19 Chatwork

D

Total 14 / 100

Documented status

E2EE · No verified first-party evidence foundPQC · No verified first-party evidence found

Primary sources

#20 Instagram DM

D

Total 14 / 100

Documented status

E2EE · No verified first-party evidence foundPQC · No verified first-party evidence found

Primary sources

What the comparison makes clear

These eleven capabilities form one completed product specification and are evaluated together as Arc.

Metadata privacy is a separate battlefield

Strong content encryption does not hide sender relationships by itself. Sealed Sender and anonymous delivery are treated as independent product work.

Offline does not automatically mean E2EE

Arc separates signed non-E2EE disaster communication from E2EE Mesh DM and labels the active mode instead of blurring the distinction.

Deletion is a lifecycle, not an animation

IGF and Mutual Burn are designed around durable device/server retirement, retry, and recovery—not only disappearing UI.

Arc messaging architecture: direct answers

Concise answers to the questions readers and answer engines ask most often about Arc's security and disaster communication design.

What is Standardized ML-KEM-1024 + PQXDH in Arc?

Hybrid post-quantum session establishment with classical key agreement and no silent downgrade to a legacy path.

What is Double Ratchet DM in Arc?

Atomic ratchet advancement, exact-ciphertext retry, bounded skipped keys, and crash-safe recovery for normal one-to-one chat.

What is Sender Keys Groups in Arc?

Per-sender, per-device group epochs with membership fencing and SKDM delivery over authenticated one-to-one sessions.

What is Sealed Sender + anonymous delivery in Arc?

Purpose-separated sender certificates, opaque recipient inboxes, generic push, and a no-plaintext-fallback rule.

What is Signed direct Mesh DM and Group in Arc?

Direct disaster messaging with authenticated origin and integrity, explicitly labeled non-E2EE because relays or nearby observers may see content.

What is Direct Mesh E2EE DM in Arc?

A separate direct-message mode with end-to-end encrypted content, explicit trust state, and no silent fallback to signed non-E2EE delivery.

What is Bounded multi-hop and store-and-forward in Arc?

Resource-bounded relay, deduplication, TTL, and offline recovery without claiming a guaranteed distance, route, or delivery time.

Comparison basis & disclosure

  • Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.
  • Each primary source supports only the category where it is cited; it does not substantiate every claim or score and does not imply vendor endorsement.
  • Vendor names and marks belong to their respective owners. Inclusion does not imply partnership, endorsement, or affiliation.

Security

Arc Security Details

These eleven capabilities form one completed product specification and are evaluated together as Arc.

Technology

Arc Technology

These eleven capabilities form one completed product specification and are evaluated together as Arc.