Communicate securely.
Operate your own trusted edge.
ValkNet combines device-authenticated end-to-end encrypted communications, VIX/BIX identity, chain-anchored proofs and deployable enterprise nodes under one governed trust architecture.
X25519 + Ed25519Per-device agreement + signatures
AES-256-GCMFresh content key per message
VIX/BIX proofHashes and identity anchors, never plaintext
SHA-256(ciphertext) → VIX chainWhat VIX is.
Where it takes the lead.
VIX is the distributed trust and execution layer behind ValkNet: a validator-governed chain designed to combine verifiable state, secure identity, private communications and enterprise-operated infrastructure without putting sensitive plaintext or private keys on-chain.
Privacy-first proof
VIX anchors hashes, identities and state proofs while encrypted content and private keys remain at the edge.
- Proof without disclosure
- Client-side key custody
- Signed, replay-resistant activity
Deterministic validator consensus
Independent validators verify the same proposal, execution result and state root before a block becomes certified.
- Multi-validator verification
- Deterministic execution
- Auditable finality
Built beyond payments
VIX is designed as infrastructure for communications, identity, assets, application proofs and enterprise nodes—not only token transfer.
- VIX-MSG communications
- VIX ↔ BIX identity
- Enterprise edge nodes
One governed trust fabric
The same trust plane can secure messaging, applications and remote nodes while keeping execution privileges separated and controlled.
- Least-privilege services
- Governed node enrollment
- Modular protocol bridges
One secure fabric.
Multiple operating modes.
ValkNet is designed for advanced users, regulated enterprises and operators who need private communications, independently managed edge infrastructure and verifiable trust without exposing message content.
Secure communications
Device-authenticated one-to-one messaging is live today; secure groups are live with local key custody, signed envelopes, replay protection and encrypted mailbox delivery.
- 1:1 encrypted messaging
- Group engine + membership epochs
- Delivery/read receipts
- Cross-device identity
Enterprise nodes
Deploy a customer-controlled VIX edge node on company infrastructure while retaining master-chain trust, entitlement and policy anchors.
- Tenant admin
- Relay + messaging services
- Signed enrollment
- Managed update channel
Secure hosted workloads
Run basic websites and service workloads inside isolated tenant containers with controlled ingress, separate state and centrally governed trust.
- Container isolation
- TLS edge gateway
- Per-tenant storage
- Backup-ready layout
Protocol bridge
Connect VIX trust and secure transport to financial, enterprise and Web3 systems through modular adapters instead of weakening the core.
- FIX / FIXP / FIXS
- ISO 20022
- mTLS APIs + SFTP
- Web3 asset bridge
Zero implicit trust.
Cryptographic proof at every boundary.
Private keys remain local to each client. Sessions authenticate devices, envelopes are digitally signed, recipients are bound to registered device keys and the transport layer never needs plaintext to route a message.
Non-exportable client keys
X25519 and Ed25519 keys are created inside Web Crypto where supported. P-256 remains an explicit compatibility fallback.
private_key → device onlyFresh message secrets
Each message receives a new AES-256 content key. HKDF derives wrapping keys from fresh key-agreement material.
X25519 → HKDF → AES-256-GCMSigned envelopes
The API verifies the registered device signature before accepting ciphertext, and deterministic message IDs reject replay attempts.
session + signature + replay guardProof without disclosure
VIX receives hashes, route proofs and identity anchors. Message plaintext and private keys are deliberately excluded.
SHA-256(ciphertext) → VIXVIX ↔ BIX binding
A BIX wallet binds only after one-time challenge verification and exact Ed25519 public-key address derivation.
challenge → sign → verify → bindMaster-rooted tenant trust
Remote nodes generate their own identity, pin the master key and accept only master-signed entitlement manifests.
tenant node → master trust rootYour infrastructure.
Your admin.
Our trust backbone.
Organizations may operate a ValkNet/VIX edge on infrastructure they control only after registration, explicit owner approval and licensing. Every authorized node remains subordinate to the master VIX trust plane for entitlement, chain authority, policy, proof anchoring, revocation and controlled updates.
Built to connect into serious infrastructure.
Protocol support is modular. Regulated and enterprise adapters terminate into policy-controlled services instead of opening direct access to the VIX core.
FIX / FIXP / FIXS
Session, market-data and execution connectivity with controlled gateway and administrative layers.
ISO 20022
Adapter-ready financial messaging for structured payment and settlement workflows.
mTLS · SFTP · AS2/AS4
Mutually authenticated APIs and secure file/message interchange for partner networks.
PKI · PIV/CAC-ready
X.509 and hardware-backed identity profiles for higher-assurance deployments.
IPsec / IKEv2
Private inter-site connectivity profiles for tenant nodes and protected integration zones.
VIX / BIX bridge
Wallet-bound identity, chain proofs and external asset adapters without placing message content on-chain.
Protocol availability depends on deployment profile, implementation scope and applicable licensing/regulatory requirements. Proprietary or restricted interfaces are not represented as enabled unless specifically implemented and authorized.
Encryption at the edge.
Proof in the fabric.
Use ValkNet wherever the work happens.
The secure browser client is installable today as a PWA. Native packaging follows the same VIX identity and device-key model so communications stay interoperable across platforms.
Secure Web / PWA
Install from a supported browser for a standalone client experience with offline shell caching and local cryptographic key custody.
Android
Signed ValkNet Secure APK with the live VIX-MSG client, local key custody and permission-gated microphone/camera capability.
Download Android APKiPhone / iPad
Native iOS project path with TestFlight/App Store signing handled through Apple/Xcode release infrastructure.
iOS readinessDesktop
Managed installers for Windows, macOS and Linux with the same device enrollment and VIX/BIX identity model.
Desktop roadmapFrom secure client to sovereign edge.
Commercial packaging is designed around entitlement-controlled capabilities rather than separate insecure forks of the platform.
VIX Secure Client
Encrypted 1:1 and group communications, device identity and VIX/BIX binding.
Individual / TeamManaged Edge Node
Company admin, relay, messaging gateway and secure hosting under a licensed, owner-approved VIX entitlement.
Approval + SubscriptionSovereign VIX Node
Dedicated deployment profile, connectors and policy controls under master-signed licensing, authorization and revocation.
Approval + Custom licenseOperator-grade encrypted communications.
Enroll this device, bind your identity and communicate through the live VIX-MSG fabric.