TECHNOLOGY

Technology

Defense-grade encryption meets ultra-efficient communication. Built for environments where every byte matters and every message must be protected.

01 / 06
Post-Quantum Cryptography

Post-quantum,from day one.

COMPLETED Arc PRODUCT SPECIFICATION

COMPLETED Arc PRODUCT SPECIFICATION

Key Exchange
PQXDH
Post-Quantum Extended Diffie-Hellman
Lattice KEM
ML-KEM-1024
NIST FIPS 203 Level 5

Signal Foundation audited cryptographic stack

Librarylibsignal-client (Rust FFI)
RatchetDouble Ratchet (normal DM)
SignatureXEdDSA
MetadataSealed Sender
Self-implemented CryptoForbidden
01

Ultra-Low Bandwidth Communication

COMPLETED Arc PRODUCT SPECIFICATION

Voice Message Compression

File size per minute of voice recording

AAC 128kbps
960 KB/min
AAC 64kbps
480 KB/min
Opus 16kbps
120 KB/min
Arc (Opus)
120 KB/min

8x smaller

NetworkSpeedVoice (1 min)Photo (500KB)
5G100 Mbps+<1s<1s
4G LTE10 Mbps<1s<1s
3G1 Mbps<1s~4s
2G / EDGE50 kbps~20s~80s
Satellite (LEO)25 Mbps<1s<1s
BLE Mesh1 Mbps<1s~4s
02

4-Phase E2EE Pipeline

Normal DM uses official libsignal v0.96.2 primitives with PQXDH and Double Ratchet. The common outbound journal and physical-device release gate remain incomplete; security processing is protocol-specific.

Phase 1

PQXDH

COMPLETED Arc PRODUCT SPECIFICATION

Phase 2

Double Ratchet

Forward secrecy — unique key per message, immediate deletion

Phase 3

AES-256-GCM

Authenticated encryption with 256-bit keys

Phase 4

Sealed Sender

COMPLETED Arc PRODUCT SPECIFICATION

03

Post-Quantum Cryptography

ML-KEM-1024

Security LevelNIST Level 5
Classical EquivalentAES-256
Public Key1,568 bytes
Ciphertext1,568 bytes
FoundationFIPS 203

Hybrid Design

Arc combines classical and post-quantum cryptography. Even if one algorithm is broken, the other maintains security. This dual-defense protects against both today's threats and tomorrow's quantum computers.

X25519 ECDH (classical)
+
ML-KEM-1024 (quantum-resistant)

⚠️ Protects against "Harvest Now, Decrypt Later" attacks — adversaries who record encrypted traffic today to decrypt with future quantum computers.

04

BLE Mesh Network Arc ORIGINAL

Explicit Security Modes

COMPLETED Arc PRODUCT SPECIFICATION

Ephemeral Zones

Automatically create temporary communication zones during disasters. Map evacuation points, medical stations, and resource distribution centers in real-time.

Zero-Knowledge Presence

Prove you're nearby without revealing your exact location. Privacy-preserving proximity verification for trust establishment.

REAL Arc UI · 10-SECOND PREVIEW

Reach first. Or keep it confidential.

Arc makes the security boundary visible before the first Mesh message—and keeps that mode fixed for the conversation.

E2EE OFF · signed · relay-readable
E2EE ON · confidential · fail-closed
05

IGF (Instant Gone Forever)

Messages expired by IGF disappear from devices immediately. Their encrypted server documents are permanently deleted on the schedule for each plan; until that cleanup runs, an expired encrypted document may remain on Arc's servers. Essential: default 1 day; manual dial 00:01–23:59 (hours and minutes only) Premium: default 7 days; manual dial 1 second–7 days Intelligence: default 7 days; manual dial 1 second–7 days

Essential (Free)Every 48 hours (00:00 JST)
Premium2× daily (00:00 / 12:00 JST)
IntelligenceEvent-driven at expiry + every-5-minute safety net
06

Secure Device Transfer

Authorize a one-time device transfer without copying the new device’s cryptographic identity. Every active device generates and protects its own identity and message keys.

01

One-time QR authorization

02

Target Device

01

One-time QR authorization

02

Target Device

03

Explicit history choice

One-time QR authorization

The QR code is bound to the account, source and target devices, roster revision, and expiry. It is an authorization, not an encryption key.

Independent device identity

The new device generates its own identity, prekeys, sessions, and local database key. Long-term private keys are never copied.

Explicit history choice

Before transfer, choose eligible current history or start empty. Expired IGF, burned, and deleted items are always excluded.

Essential

One active device normally. During replacement only, the old and new devices coexist until verification; the old device is then revoked.

Premium / Intelligence

Up to three independent active devices. New messages are encrypted separately for every active device; no device is the master.

Secure Device Transfer is not enabled in the current public release. Availability requires verified device-roster and physical-device release gates.

07

How Arc Compares

Competitor cards link to first-party sources. Arc's card is bound to its completed product specification and the same scoring model.

08

Use Cases

Healthcare

Future plan · Separate healthcare specification

Challenge

Patient data communication must comply with HIPAA and privacy regulations while remaining fast enough for clinical workflows.

We are seeking healthcare organizations, clinical experts, security and compliance specialists, and implementation partners to co-design, validate, and pilot this future specification.

  • COMPLETED Arc PRODUCT SPECIFICATION
  • IGF · Essential: default 1 day; manual dial 00:01–23:59 (hours and minutes only) · Premium: default 7 days; manual dial 1 second–7 days · Intelligence: default 7 days; manual dial 1 second–7 days
  • COMPLETED Arc PRODUCT SPECIFICATION
Explore the medical model

Disaster Response

Challenge

Communication infrastructure is destroyed. Rescue teams need secure coordination without cell towers or internet.

We are seeking municipalities, government agencies, and pilot partners to co-develop and validate disaster-tech deployments.

  • COMPLETED Arc PRODUCT SPECIFICATION
  • Ephemeral Zones map evacuation and medical aid points
  • 120KB/min voice — usable on survival-grade bandwidth
🌲

Field Operations

Challenge

Remote sites with no connectivity need data collection, team coordination, and secure communication with headquarters.

  • Offline-first design: record locally, auto-sync on reconnect
  • COMPLETED Arc PRODUCT SPECIFICATION
  • Environmental sensors, quality tracking, and time management
09

Standards & Compliance

🇺🇸NIST CSF 2.0

Cybersecurity framework for critical infrastructure

🇺🇸NIST SP 800-53

Security and privacy controls for federal systems

🇺🇸FIPS 140-3

Cryptographic module validation (pending)

🇺🇸FIPS 203 (ML-KEM)

ML-KEM post-quantum key encapsulation standard

🌐ISO/IEC 27001

International information security management

🇪🇺GDPR

EU data protection and privacy regulation

🇬🇧UK Cyber Essentials+

UK government-backed cyber security certification

🇺🇸HIPAA

Design-ready for healthcare data protection

Explore Arc's Security Architecture

Dive deeper into Arc's cryptographic design, threat model analysis, and compliance documentation.