Agent A sender
Seals a message for B’s public key
1 Recipient key
Fingerprint of the key A will encrypt to (computed by A)
2 Message
Want a draft? The optional local AI can write one. You decide whether to use it.
3 Seal
| Step | Bytes | ms |
|---|
Live demo · runs entirely in this tab
Agent B makes a post-quantum key pair. Agent A uses B’s public key to seal your message. Then you change one bit, or use the wrong key, and watch B refuse it. It all runs in this tab, with no server and no account.
Four checks: key fingerprint, round trip, one-bit tamper, wrong key. Every result shown is computed live. Use two tabs or two browsers instead.
Seals a message for B’s public key
Fingerprint of the key A will encrypt to (computed by A)
Want a draft? The optional local AI can write one. You decide whether to use it.
| Step | Bytes | ms |
|---|
Public. Anything here could be read or changed in transit.
A packet moves only after the real operation behind it has finished. The movement itself is a fixed animation, not a measured network time.
Public records only: sizes, timings and results. Never keys, shared secrets or message text.
Holds the only secret key
Fingerprint of B’s public key (SHA-256)
The secret key exists only in this tab’s memory, inside B’s worker. Refreshing or closing the tab destroys it, and envelopes sealed to it can then never be opened.
| Step | Bytes | ms |
|---|
A small language model can draft a message for Agent A or explain the latest result. It runs on your device. It never receives keys or shared secrets, and it plays no part in deciding whether decryption succeeded: those verdicts come from ordinary code and work without the model.
Ordinary code turns the public event log into a few plain facts about the latest attempt, and only those facts are sent. The exact prompt appears below the answer.
Encryption protects a message only for whoever holds the private key matching the public key you used. An attacker’s key has a fingerprint too. Compare all 64 hex digits with B through a channel you already trust before you seal anything that matters.
That this implementation encrypts and decrypts in your browser, and that the tested changes were detected with no plaintext released. Not that the system is secure in general, that any quantum attack was tried, or who sent a message: there is no sender authentication.
ML-KEM comes from noble-post-quantum , which has not been independently audited and does not claim constant-time execution. LatticeLink is a research preview, not an audited secure messenger. Security model →