Private conversations that leave proof, not exposure.
Two end-to-end encrypted communicators for chat, voice, video and conferences. Messages are sealed on each device with hybrid post-quantum encryption, and every message, call and policy change leaves a signed receipt on a private ledger. The content never does.
X-Comm
The leadership communicator inside a Cloudflare Zero Trust perimeter. Every person signs in with a verified email, devices connect through Cloudflare WARP, and the app checks the tunnel before anyone enters the workspace.
- Chat, voice, video and conferences, with chat during calls
- Hybrid post-quantum E2E encryption (X25519 + ML-KEM-768)
- Encrypted file sharing: storage only ever holds ciphertext
- Rings and chimes when closed, with no message content in the notification
- New people onboarded through a governed request a named approver signs off
ZERO TRUST COMM
The same encrypted core with nothing to install. Sign in with a one-time code to your email, and the built-in tunnel routes every call through encrypted relays, so participants never see each other's network address.
- No VPN client or device enrollment
- In-app tunnel: calls relay-only over TLS on port 443
- Invite by QR code or link: opening it adds the guest to the allow list
- Every person added is recorded with who invited them
- Separate workspace: its own rooms, contacts, ledger and storage
Built the way AXIOM builds everything: verify, then trust.
Post-quantum by default
Each message is encrypted on the sender's device with a hybrid X25519 and ML-KEM-768 (FIPS 203) key exchange. Relays and storage carry ciphertext only. When every participant supports it, the session runs at the strongest level; otherwise it settles at the level all can meet.
Receipts, not recordings
A hash of each ciphertext, call and governance change is chained into a ledger signed with ML-DSA-65 (FIPS 204) and anchored to Q-Chain. You can prove what happened and when, without anyone being able to read it.
No phone numbers
People are identified by their verified email through Cloudflare Access, never by a phone number or public handle. Membership is per room, and only members can invite.
Same protection. Different front door.
| X-Comm | ZERO TRUST COMM | |
|---|---|---|
| Best for | Internal leadership on managed devices | Working with partners, clients and investors |
| Sign-in | Email code + WARP device client | One-time code to email, nothing to install |
| Network protection | WARP Zero Trust tunnel for the whole device | Built-in relay tunnel for the app's own traffic |
| Adding people | Governed request, approved by a named approver | QR code or link from a member |
| Messages and files | Hybrid post-quantum end-to-end encryption, ciphertext-only storage | |
| Proof | ML-DSA-65 signed ledger anchored to Q-Chain | |
Voice and video use the browser's standard WebRTC encryption (DTLS-SRTP); in ZERO TRUST COMM that media also travels inside the TLS relay tunnel. Both run in any modern browser and install to the home screen.
Bring your team into the corridor.
Tell us who needs to talk and how they work today. We will set up the right communicator, invite your people, and walk you through the receipts.
Request access How AXIOM governs itML-KEM-768 + X25519
ML-DSA-65 receipts
Identity on every session
Email identity only