Hardware messengers with no operating system — drastically reduced attack surface, no accounts, no trace left behind. Your conversations are mathematically impossible to intercept. Even by us. For governments, military, and those who cannot afford a leak.
A secure messenger with a touchscreen and no operating system at all. No accounts, no SIM card, works without internet. Titanium casing available. Military grade.
Fits in your pocket, looks like ordinary hardware. No accounts, no SIM card. No-screen version available — operates completely silent and blind.
Full Hierophant protection on your existing Android phone. No registration, no accounts. Your traffic looks like ordinary browsing — nothing suspicious, no servers in between.
All your passwords in hardware, not the cloud. Works offline. Log in anywhere without typing a password. One code destroys everything in an emergency.
No servers. No SIM cards. No accounts. Mathematically impossible to intercept. 10+ patents. Developed in Austria.
Your message is encrypted before it leaves your browser. No logs, no tracking.
The HSM-T is a hardware messenger with a touchscreen — like a phone, but with no operating system. No app layer, no driver stack, no attack surface for malware. You write a message, it gets encrypted and sent. No trace remains anywhere — not on your device, not on any server, not on the network. Works via radio even without internet.

The HSM-S fits in your pocket and looks like an ordinary USB device. Nobody around you knows what it is. Available in a no-screen version — operates entirely by touch and sound signals, leaving no visual clue of what you're doing. The plain polymer casing is intentional: it looks like cheap, unremarkable hardware.

Install the Hierophant app on your Android phone and get the same level of protection as the hardware devices. Your traffic looks like ordinary internet browsing — surveillance systems see nothing suspicious. No accounts, no phone numbers, no registration. Works directly between devices — no servers in between. Connect an HSM-T or HSM-S for the highest level of key protection.

All your passwords, notes, and logins stored directly in a hardware device — not in any cloud or app. Even if someone seizes the device, a special PIN instantly destroys all data. Log into websites and corporate systems by just plugging in the device — no typing, no passwords stored anywhere.

A patented method for entering next-generation encryption keys through a physical device — no keyboard, no clipboard, no interception possible. The only hardware solution that makes truly isolated key setup practical for people who are not cryptographers.

Up to 50 passwords stored in the device itself — not in a browser, not in a cloud, not on a server anywhere. Two PINs: one to access your passwords, another to silently destroy all data if you're under pressure.

Write down sensitive information — meeting decisions, access codes, confidential data — and store it in the device's encrypted memory. Nothing on your phone, nothing on any server. If the device is seized, one PIN erases everything.

Plug in the device and log into any website or corporate system — no username, no password typed, nothing stored on the server. Even if the service is hacked, there is nothing to steal. Compliant with GDPR by design — because no personal data ever exists on a server.
C-suite and board members who need passwordless access without creating audit trails or metadata footprints.
Banks and investment firms migrating to post-quantum cryptography with secure key ceremonies.
Secure access to classified systems with hardware-verified authentication that leaves no digital traces.
HIPAA and GDPR-compliant authentication for accessing patient records without storing personal identifiers.
Your own private network — completely cut off from the public internet. We build a communication infrastructure for your organization where nothing passes through foreign servers, nothing crosses foreign borders. If the internet goes down, your network keeps running. For governments, armies, and organizations that need total control over their own communications.

Our devices run no operating system. No installed apps, no driver stack, no update manager — nothing for malware to attach to. The firmware does one thing: send an encrypted message. The fewer moving parts, the fewer ways in. Security here is an architectural property, not a promise in terms of service.
The system is designed so that servers never see who is communicating with whom, when, or for how long. No contact lists, no user IDs, no message history. Unlike traditional messengers, metadata is never generated at all.
Hierophant operates independently of internet providers or mobile networks. Communication can use radio transmission, satellite channels, QR codes, or NFC transfer. Ideal for locations with no cellular coverage or when internet connectivity is unavailable.
Encryption keys can be transferred securely without cables or wireless connections — via QR codes, NFC, or optical signals. Keys are never stored on servers and never transmitted over networks.
| Parameter | Hierophant | Signal | Element | AWS Wickr | Threema | Wire |
|---|---|---|---|---|---|---|
| OS-Free Hardware | ✓ YesDedicated hardware, no OS attack surface. | ✗ NoSoftware only. | ✗ NoSoftware only. | ✗ NoSoftware only. | ✗ NoSoftware only. | ✗ NoSoftware only. |
| Zero Knowledge Protocol | ✓ YesHides the very fact of communication. | ✗ NoServer knows who talks to whom. | ✗ NoFederation knows relationships. | ✗ NoServer has knowledge of comms. | ✗ NoServer routes via IDs. | ✗ NoServer syncs conversations. |
| Metadata Generation | ✓ Mathematically ZeroNo sender, receiver, or timing data. | ~ PartiallySealed Sender — but server sees recipient. | ✗ ExtensiveHomeservers store metadata. | ✗ ExtensiveLogs for admin oversight. | ~ MinimizedDeleted after delivery. | ✗ PresentRequired for sync. |
| User Identification | ✓ NoneNo accounts, phones, or emails. | ✗ Phone NumberRequired for registration. | ~ Matrix ID@user:server.com | ✗ Corporate IDSSO-managed. | ✓ Threema IDAnonymous; phone optional. | ✗ EmailRequired for account. |
| Post-Quantum Security | ✓ Native by DesignNIST PQC algorithms standard. | ✓ PQXDHCRYSTALS-Kyber deployed. | ✗ NoNo public PQC roadmap. | ✗ No (E2EE)Transport may be PQC, E2EE is not. | ✗ NoClassical ECC only. | ✓ MLSPQC-agile by design. |
| Secure Element / TEE | ✓ YesAll crypto in dedicated SE. | ✗ NoSoftware cryptography only. | ✗ No | ✗ No | ✗ No | ✗ No |
| Digital Sovereignty | ✓ AbsoluteCustomer-owned hardware & infra. | ✗ NoneCentralized, no self-hosting. | ✓ Self-hostedNative Matrix feature. | ~ On-prem option | ~ On-prem option | ~ On-prem option |
| Core Architecture | ✓ Hierophant Network ProtocolProprietary military-grade protocol, independent of TCP/IP. | ✗ Client-Server (TCP/IP)Relies on standard internet infrastructure. | ~ Federated (TCP/IP)Decentralized network of independent servers. | ✗ Client-Server (TCP/IP)Relies on AWS cloud infrastructure. | ✗ Client-Server (TCP/IP)Centralized server-based architecture. | ✗ Hybrid (TCP/IP)Cloud or on-premise server architecture. |
| PKI / Certificate Dependency | ✓ NoneOperates without Certificate Authorities, eliminating a central point of failure. | ✗ YesRelies on traditional PKI and TLS certificates for server authentication. | ✗ YesRelies on TLS certificates for client-server and server-server security. | ✗ YesRelies on AWS's PKI for transport layer security. | ✗ YesUses TLS certificates for securing connections to its servers. | ✗ YesRelies on TLS certificates for server and federation security. |
| Traffic Analysis Resistance | ✓ Not based on TCP/IPHierophant Network Protocol makes traffic correlation fundamentally infeasible. | ✗ Based on TCP/IPVulnerable to network-level analysis despite Sealed Sender. | ✗ Based on TCP/IPFederation may complicate analysis, but it's not a designed defense. | ~ Based on TCP/IPOffers an "Open Access" proxy feature as a countermeasure. | ✗ Based on TCP/IPOperates over standard internet protocols, exposing traffic to analysis. | ✗ Based on TCP/IPOperates over standard internet protocols, exposing traffic to analysis. |
| Air Gap Communication | ✓ YesSupports secure, offline key exchange and setup in fully air-gapped environments. | ✗ NoRequires an internet connection for registration and initial key exchange. | ✗ NoRequires a network connection for initial key exchange and setup between users. | ✗ NoRequires a network connection for initial key exchange and setup. | ✗ NoRequires an internet connection for registration and initial key exchange. | ✗ NoRequires an internet connection for registration and initial key exchange. |
| Works With SCADA / ICS | ✓ YesTransport-agnostic protocol is designed for critical infrastructure and industrial control systems. | ✗ NoDesigned for human-to-human communication, not industrial telemetry protocols. | ✗ NoDesigned for human-to-human communication, not industrial telemetry protocols. | ✗ NoDesigned for human-to-human communication, not industrial telemetry protocols. | ✗ NoDesigned for human-to-human communication, not industrial telemetry protocols. | ✗ NoDesigned for human-to-human communication, not industrial telemetry protocols. |
| Transport Agnostic | ✓ YesProtocol is independent of the transport layer (e.g., TCP/IP, radio, mesh). | ✗ NoRequires a standard TCP/IP-based internet connection to function. | ✗ NoRequires a standard TCP/IP-based internet connection to function. | ✗ NoRequires a standard TCP/IP-based internet connection to function. | ✗ NoRequires a standard TCP/IP-based internet connection to function. | ✗ NoRequires a standard TCP/IP-based internet connection to function. |
| Decoy Traffic | ✓ YesNatively generates decoy traffic to mask real communication patterns and resist traffic analysis. | ✗ NoDoes not generate decoy traffic; relies on protocol-level metadata protection. | ✗ NoNo native decoy traffic generation. | ✗ NoNo native decoy traffic generation; uses proxy routing as an alternative. | ✗ NoNo native decoy traffic generation. | ✗ NoNo native decoy traffic generation. |
| Emergency / Duress Features | ✓ YesIncludes duress PINs for wiping data, SOS modes, and pre-configured emergency messages. | ✗ NoDoes not offer specialized duress or emergency features. | ✗ NoStandard collaboration features; no built-in duress or SOS functionality. | ✗ NoEnterprise-focused features; does not include personal duress or SOS modes. | ✗ NoStandard messaging features; no built-in duress or SOS functionality. | ✗ NoStandard collaboration features; no built-in duress or SOS functionality. |
| Passwordless Auth Provider | ✓ YesFunctions as a secure, password-free authenticator for logging into third-party services and websites. | ✗ NoFunctions only as a messenger; cannot be used as an external identity provider. | ✗ NoFunctions only as a messenger; cannot be used as an external identity provider. | ✗ NoIntegrates with external identity providers for login, but does not act as one itself. | ✗ NoFunctions only as a messenger; cannot be used as an external identity provider. | ✗ NoFunctions only as a messenger; cannot be used as an external identity provider. |
| Jurisdiction | ✓ Austria (EU, Neutral)Non-NATO, no backdoor laws. | ⚠ USASubject to CLOUD Act. | ⚠ UK/EU | ⚠ USAAWS jurisdiction. | ✓ Switzerland | ✓ Switzerland/Germany |
Hierophant is built upon a portfolio of over 10 patents that fundamentally redefine secure networking. Our core distinction is the complete replacement of standard Internet protocols with a proprietary, Zero-Knowledge Network Protocol that is transport-agnostic. This is not an overlay on the existing internet — it is a clean-slate, sovereign communication architecture designed for zero-metadata operation from the ground up. The distribution and use of this technology is subject to Austrian and EU export controls.
Protecting C-level strategic discussions, board meetings, and executive communications from corporate espionage and insider threats.
Safeguard multi-billion dollar deals, financial roadshows, and market-sensitive data, ensuring absolute confidentiality before public announcements.
Protect next-generation IP in AI, biotech, pharmaceuticals, and semiconductor research from state-sponsored industrial espionage.
Maintain absolute attorney-client privilege across jurisdictions in high-stakes international litigation, arbitration, and internal investigations.
Create a fully isolated control channel for private data centers, financial networks, and industrial control systems (ICS), invulnerable to external threats.
Establish a failsafe communication channel for crisis management teams to coordinate response during cyberattacks or infrastructure failure.
Enable secure negotiations, intelligence coordination, and crisis diplomacy between nations and agencies without leaving any trace or metadata footprint.
Exchange medical records, research data, and patient information across institutions with mathematically guaranteed privacy compliance and zero data residue.
Secure websites and corporate systems with unphishable, quantum-resistant hardware keys for ultimate access control.
Implement authentication systems that don't require traditional usernames or passwords, relying on the hardware for secure access.
Create login solutions that are inherently GDPR compliant by design, as no personal identifiable information is ever stored or transmitted.
Your message is encrypted in your browser with our public PGP key before transmission. This page has no analytics or trackers.
Optional: You may reveal the ciphertext and send it manually.
Email: oleg.shumar@gettrusted.io