Your privacy is in your hands.
Every system we build starts with the same question: what does a security professional actually need? Then we build it without ads, without profiling, and without trading user data as a product.
A private vault, a post-quantum encrypted messenger, and a place to publish what you choose to publish — in one application. Your keys are generated on your device and stay there. Formerly Aleph Vault.
Release status →An AI assistant with an open governance protocol built into it — the Entropy-Gated AI Framework — so what it is permitted to do is defined, auditable, and not left to the model. Offline while both are rebuilt, and returning after Cryptaverse ships.
Returning after CryptaverseCryptaverse is released in the United States. We will consider additional markets individually, and only where the operating conditions are compatible with how the product is built — keys held by users, no mandated access, no weakening of encryption.
Where those conditions cannot be met, we do not distribute. That is a product decision, not a commercial one: a version of Cryptaverse built to satisfy them would not be Cryptaverse.
JC Laboratories builds independent security systems across encrypted storage, cryptographic platforms, and governed AI. The products are different. The standard is the same: defined architecture, standard primitives, and controlled execution.
Message sessions are established with a hybrid PQXDH handshake combining ML-KEM-768 with X25519, so a session stays protected even against an adversary storing traffic today to decrypt later.
Each conversation advances a Double Ratchet with per-message keys, giving forward secrecy and post-compromise recovery. Content is sealed with AES-256-GCM and signed with Ed25519.
Identity is an Ed25519 anchor key generated on your device, with X25519 for key exchange. Your fingerprint is derived from that key. We never hold your private keys.
Argon2id protects the vault and Safety Deposit Box, using memory-hard derivation tuned for resistance to offline attack on captured data.
Your vault, profile screen, messages and files are encrypted before they leave the device. Blocks and stacks you publish are public by design. Nothing crosses that line without you doing it.
The Entropy-Gated AI Framework defines what an AI assistant is permitted to do before it runs, so behaviour is bounded and auditable rather than left to the model. It returns with Abe.
Flutter and Dart on the client, Cloudflare Workers, D1, KV and R2 for platform infrastructure. Standard primitives, no bespoke cryptography.
The portfolio combines an encrypted application, a cryptographic platform architecture, and an AI governance framework under one company.
Some JC Laboratories systems are published now. Others are active builds progressing toward release.
Availability and build status vary by system. See individual product pages for current status.