Projects · Secure communications

Private conversations that leave proof, not exposure.

Two end-to-end encrypted communicators for chat, voice, video and conferences. Messages are sealed on each device with hybrid post-quantum encryption, and every message, call and policy change leaves a signed receipt on a private ledger. The content never does.

Request access Compare the two

For managed enterprise teams

X-Comm

The leadership communicator inside a Cloudflare Zero Trust perimeter. Every person signs in with a verified email, devices connect through Cloudflare WARP, and the app checks the tunnel before anyone enters the workspace.

  • Chat, voice, video and conferences, with chat during calls
  • Hybrid post-quantum E2E encryption (X25519 + ML-KEM-768)
  • Encrypted file sharing: storage only ever holds ciphertext
  • Rings and chimes when closed, with no message content in the notification
  • New people onboarded through a governed request a named approver signs off
Member sign-in ↗
For partners, clients and guests

ZERO TRUST COMM

The same encrypted core with nothing to install. Sign in with a one-time code to your email, and the built-in tunnel routes every call through encrypted relays, so participants never see each other's network address.

  • No VPN client or device enrollment
  • In-app tunnel: calls relay-only over TLS on port 443
  • Invite by QR code or link: opening it adds the guest to the allow list
  • Every person added is recorded with who invited them
  • Separate workspace: its own rooms, contacts, ledger and storage
Member sign-in ↗
Shared foundation

Built the way AXIOM builds everything: verify, then trust.

Encryption

Post-quantum by default

Each message is encrypted on the sender's device with a hybrid X25519 and ML-KEM-768 (FIPS 203) key exchange. Relays and storage carry ciphertext only. When every participant supports it, the session runs at the strongest level; otherwise it settles at the level all can meet.

Evidence

Receipts, not recordings

A hash of each ciphertext, call and governance change is chained into a ledger signed with ML-DSA-65 (FIPS 204) and anchored to Q-Chain. You can prove what happened and when, without anyone being able to read it.

Identity

No phone numbers

People are identified by their verified email through Cloudflare Access, never by a phone number or public handle. Membership is per room, and only members can invite.

Which one fits

Same protection. Different front door.

X-Comm ZERO TRUST COMM
Best forInternal leadership on managed devicesWorking with partners, clients and investors
Sign-inEmail code + WARP device clientOne-time code to email, nothing to install
Network protectionWARP Zero Trust tunnel for the whole deviceBuilt-in relay tunnel for the app's own traffic
Adding peopleGoverned request, approved by a named approverQR code or link from a member
Messages and filesHybrid post-quantum end-to-end encryption, ciphertext-only storage
ProofML-DSA-65 signed ledger anchored to Q-Chain

Voice and video use the browser's standard WebRTC encryption (DTLS-SRTP); in ZERO TRUST COMM that media also travels inside the TLS relay tunnel. Both run in any modern browser and install to the home screen.

Bring your team into the corridor.

Tell us who needs to talk and how they work today. We will set up the right communicator, invite your people, and walk you through the receipts.

Request access How AXIOM governs it
PQC

ML-KEM-768 + X25519

Ledger

ML-DSA-65 receipts

Zero Trust

Identity on every session

No numbers

Email identity only