SentientSecurity

Hybrid message encryption

Protection built for today—and tomorrow.

Sentient combines ML-KEM-768 and X25519 in a hybrid message-encryption design. Their cryptographic contributions are combined with HKDF-SHA-256, and XChaCha20-Poly1305 then authenticates and encrypts the message payload.

Encryption key material is derived on user devices

Two complementary systems

Why Sentient combines both.

X25519

Classical cryptographic contribution

X25519 is a widely used elliptic-curve Diffie–Hellman function. In Sentient’s hybrid construction, it contributes shared secret material to the message-encryption key.

ML-KEM-768

Post-quantum contribution

ML-KEM-768 is one of the parameter sets standardized by NIST in FIPS 203. In Sentient’s hybrid construction, it contributes post-quantum shared secret material to the message-encryption key.

The hybrid design

Two contributions. One protected message.

X25519shared secret contribution
+
ML-KEM-768shared secret contribution
Derived message-encryption keyHKDF-SHA-256 combines the two cryptographic contributions into message-encryption key material.

The hybrid construction is designed so that message protection does not depend entirely on only one of the two cryptographic components.

Behind the send button

How a message is protected.

Recipient key material is obtained

The sender uses the recipient’s published encryption-key material together with newly generated sender-side cryptographic material.

Both systems contribute

ML-KEM-768 and X25519 each contribute shared secret material for the message.

The contributions are combined

HKDF-SHA-256 combines the two contributions into message-encryption key material.

The payload is authenticated and encrypted

XChaCha20-Poly1305 protects the confidentiality and integrity of the message payload before it is sent through Sentient’s servers.

What this means for you

Security without extra steps.

Protection applied before transmission

Sentient authenticates and encrypts each message payload on the sender’s device before it is sent through Sentient’s servers. The recipient’s device verifies the protected payload before presenting the message.

Designed for long-term resilience

The post-quantum contribution helps address “harvest now, decrypt later” attacks, in which an adversary records encrypted traffic today in hopes of decrypting it later with a sufficiently powerful quantum computer.

Understanding the encryption

Establishing key material is not the same as encrypting a message.

ML-KEM-768 and X25519 each contribute shared secret material. HKDF-SHA-256 combines those contributions into message-encryption key material. Neither ML-KEM-768 nor X25519 directly encrypts the message payload.

XChaCha20-Poly1305 uses the derived key material to authenticate and encrypt the message payload before it is sent through Sentient’s servers. Sentient’s servers receive encrypted message payloads rather than the plaintext contents of those messages.

Encryption is only one part of security.

Sentient’s security architecture extends beyond message encryption. Apple App Attest and Google Play Integrity provide device and application integrity signals, while device-bound credentials help prevent account access from unauthorized installations. Cryptographic keys are protected using hardware-backed storage through the iOS Keychain and Android Keystore. The trusted devices feature gives users visibility into connected devices and allows access to be revoked, while secure recovery credentials protect account restoration on a replacement device.

Official references

Read the standards.

These references describe the underlying algorithms and general hybrid-design principles. They do not constitute certification or independent validation of Sentient’s implementation.