Arpokrat is legally domiciled in Switzerland and runs its relay network across independent jurisdictions, on hardware built to resist physical compromise — not just remote attack. This page shows how it is built, so you do not have to take our word for it.
Our servers are dumb by design. They never learn who's talking to whom — and forget the rest.
Arpokrat’s infrastructure runs on none of the major US cloud platforms — not Amazon Web Services, Google Cloud, Microsoft Azure, or Cloudflare — and others. That is a deliberate architectural choice with a concrete legal consequence: a US CLOUD Act order works by compelling a US-based provider to hand over data it controls, and Arpokrat operates no infrastructure on those providers for such an order to reach. These four are simply the best-known examples — the same reasoning rules out any provider under US jurisdiction.
New to the CLOUD Act?
Where a company is based decides which governments can compel it. We chose Switzerland deliberately.
Our legal entity is established in Zug, under the same Crypto Valley framework that made the canton a home for cryptographic and decentralized projects. Our public web servers run in Geneva, in Tier III+, ISO-certified data centres, and fall under the strict Swiss Federal Act on Data Protection (FADP).
Encryption protects data in transit. But a relay is a physical machine in a rack — so we also design for the day someone gains physical access to it.
Messages awaiting delivery live only in volatile RAM, never on disk. Swap is disabled, so the system can’t page that memory out to storage — which is what makes RAM-only actually hold.
Because pending data lives only in RAM, cutting power clears it instantly. A relay examined after shutdown holds no message content on disk.
Administrative access is limited to two people — redundancy if one is unavailable, without widening the attack surface.
Release manifests for ArpokratOS, the Messenger, and the web installer are signed on a dedicated, air-gapped Qubes OS machine that has never touched the internet — and never will. The signing keys never reach a networked device.
Relays in privacy-law countries, independent of major surveillance alliances — no single jurisdiction controls the network.
This is the deeper reference behind what the Messenger page summarises.
Our warrant canary is updated and PGP-signed on a regular schedule. As long as it keeps appearing, we have received no secret order we could not tell you about.
View Warrant Canary Read the CodeEvery canary entry is PGP-signed — you can verify the signature yourself.
See what this means for your messages on the Messenger page
.
Running communications for an organisation? Explore Enterprise
.