Security at OBolo is continuous, layered and honestly stated. Here is exactly how we protect identity, relationships and content — and exactly what we will not claim.
Registration credentials sit inside a restricted, audited trust boundary — never exposed to Spaces, businesses or contacts.
Experience-specific end-to-end encryption for eligible private conversations and calls.
Cloud storage, backups and each authorised device’s local store are encrypted, with remote wipe and revocation.
Separate identity, device, conversation, call, file, Space, Circle and recovery keys — and no universal decryption key for ordinary user content.
Only purpose-required attributes and operational evidence are kept — never more.
Capability claims follow technical validation; lawful requests follow restricted, auditable process.
Before any experience or participant receives data, protective checks run — every time.
Identity references are tokenised; Registration Identity is shielded from every external domain.
Only what the declared purpose requires is exposed — nothing incidental.
LifeSpace, Space, purpose and permission are validated at the moment of the action.
Anti-enumeration limits, rate limiting and anomaly detection guard the identity layer itself.
Honest security is specific. Public or moderated content follows different treatment from private conversation — and we say so.
| Experience | Target security treatment |
|---|---|
| OChat | End-to-end encryption for eligible private and group conversations |
| OCall | End-to-end encryption for eligible voice and video calls |
| OMeet | End-to-end mode, or strong media and transport encryption by meeting type |
| OMoments | Audience-encrypted or access-controlled encrypted delivery |
| OTask | Object- or field-level encryption; end-to-end where feasible |
| ODrive | Client-side or object-level encryption with per-file keys and controlled key sharing |
| OCircle | Secure channel encryption; optional end-to-end modes for eligible private Circles |
Distributed-ledger technology is used for tamper-evident proofs — never for personal content.
Records are retained only according to security, legal and published policy.
Permissions end when relationships close; content is deleted or exported under product controls.
Revoked Dynamic IDs are never reassigned; integrity proofs never embed personal content.
Absolute security claims are prohibited by our own brand standards. We state capability status precisely, validate before we claim, and accept accountability when outcomes fall below the standard.
Bring your security questions. Precise answers are the point.