Encryption with no key on our side.
Every linked device, ours included, decrypts WhatsApp messages to show them. For the conversations where that is not enough, advanced security seals the content on the two devices themselves, and nothing in between can open it.
WhatsApp's encryption ends inside our boundary.
The WhatsApp session runs on our managed servers, so WhatsApp's own encryption ends there. If those servers were breached, the database copied, or we were ordered to hand over stored messages, WhatsApp's encryption would not help. This layer keeps the content of those conversations unreadable in every one of those cases; what we hold, and what we could be made to hand over, is ciphertext.
One person enables it, the other accepts. From then on, the content is sealed.
From the moment of acceptance, every message, photo, voice note and file is encrypted on the sender's device and decrypted on the recipient's, with a fresh key per message and envelopes padded to fixed sizes. The carrier is an ordinary WhatsApp message; inside MobileB it is never shown as one. The header shows a closed lock and "Advanced security on", with a quiet Verify row in the conversation sheet: compare safety numbers in person or on a call you trust, then mark the contact verified. That comparison is how you confirm that nobody sits in between.
Keys stay on the device
Keys live in a vault on your device that opens with your passkey (Face ID, Touch ID or a security key) or your passphrase, and relocks after 15 minutes idle, sooner in the background, and when you sign out. No biometric data reaches us. Our servers hold no key, on purpose; the only thing they record is which conversations are protected and who turned that on, so they can refuse plain sends into them.
Files, sealed with their names
A sealed file travels as a WhatsApp document with a meaningless name. The real name, type, caption and preview are inside the envelope, because a filename often says most of what a file does. Up to 16 MiB per file.
Erase after reading
Set a timer per conversation: when you leave the chat, or after an hour, a day or a week, measured from reading. Each side chooses its own. The message key is spent on first decryption, so nothing is restorable.
Agents and advanced security
An agent can see that a conversation is protected and how many messages went in the clear, so it can say what it could not read. It never sees the content, and it cannot send text that pretends to be encrypted.
What travels sealed
Text, photos, videos, voice notes, camera shots and shared files. Scheduled messages, locations, contact cards, reactions and forwarding are not available inside a sealed conversation.
Two people, two devices
A session runs between exactly two devices, one per person. Encrypted groups are not built.
Said plainly.
- It hides what is said, not that two people are talking, how often, or roughly how much.
- It cannot protect an unlocked phone, and it cannot stop the other person from saving or photographing their screen.
- Messages typed in the WhatsApp app, outside MobileB, travel in the clear and are marked that way inside the conversation.
- The carrier messages sit in WhatsApp's own history and in any phone backup the other person keeps, as ciphertext.
- The app is delivered as code from our servers. A malicious change to that code could affect future messages; earlier messages stay protected. That limit is inherent to a web app and we say so rather than pretend otherwise.
- Key agreement is classical, and no claim beyond that is made.