Progress & limits / 15 September 2026

Know what you can
rely on.

A rule in the profile, a working library and a proven journey on your phone are different stages of delivery.

This page summarises the project's recorded evidence through 15 September. It is not a certification, a live service check or a claim that the complete profile is ready.

Implemented and exercised

Released preview

Paired private conversations

KithMoot Android 0.5.12 and Bothy 0.1.3-pre.2 carry a two-emulator journey covering distinct signer personas, public-WSS Link pairing, scoped circle access, encrypted chat, process/server restart and server-first route retirement.

This proves that bounded preview journey. It does not prove the complete sheltered carrier profile, two physical phones or background delivery.

Client implementation

Know the route and the device

Web and Android clients have lane indicators, contact-card handling, verified box discovery and person-scoped device credentials.

Full device pairing, identity succession, onion fallback and downgrade/hold acceptance remain incomplete.

Released infrastructure

Storage and bounded intake

Bothy has keeper event custody and scoped grants. The 0.1.4-pre.1 delivery adds separate public and paired intake, a reserved share of storage and socket limits, with rollback/restoration evidence.

Newer source adds encrypted archive export/restore and a bounded private history path. That is separate from this released storage preview; circle replication and signer-backed epoch storage remain open.

Connection and restore evidence

A second carrier route

The second independently hosted relay passed Tor and native I2P stream, TLS and WebSocket probes after restoration on 14 September.

No application message was sent for that gate. Box cadence activation, end-to-end delivery and carrier outage acceptance remain separate.

Source is ahead of the public preview

Implemented does not mean released.

The 15 September handover records the public web release as 20260914T201338Z and Android as the 0.5.12 preview. New history and anonymous-room work must not be assumed available in those releases.

Bothy and Android also have bounded NIP-77 comparison primitives: authenticated, ID-only groundwork for checking what each side holds. These do not fetch messages, retain missing history or provide automatic replication. A browser Link carrier and the complete cross-device journey remain open.

Being built

The missing integrations have a purpose.

Stronger message secrecy

The sheltered-lane design targets RFC 9420 MLS. The new vmls-core crate validates bounded outer envelopes; it does not encrypt messages or manage MLS groups, and no client or box consumes it yet. OpenMLS is a compile-proven candidate, not an adopted dependency.

Quiet and anonymous modes

Quiet-message libraries, client transports and box scheduling code exist. Box-owned cadence still needs controlled activation and physical-device evidence. KithMoot web and Android now implement constrained anonymous rooms with a fresh identity, onion-only relays and fail-closed Orbot routing. Release and real carrier/phone acceptance remain open; this is not a general anonymity guarantee.

Recovery and resistance to coercion

The reviewed epoch-seal library supports sealing older history to a circle, delayed recovery and refusal. Signer-backed box storage, recovery/duress integration and travel mode remain open. A single-period exposure limit must not be claimed for the running preview.

Admission and family use

Relationship tiers, scoped grants and resource limits address access and storage abuse. Complete kin-only client mode, family authority flows and parts of contact onboarding remain to integrate. Moderating an admitted person's behaviour is still a separate concern.

Keep and move the whole archive

KithMoot source now has bounded, resumable history import, encrypted device-local search and box-first deletion. Bothy source adds encrypted archive export/restore and deletion records that can be reapplied after restoring an older archive. Public deletion requests are limited to verified account-authored notes and record each relay's response, not proof that third-party bytes disappeared. Fresh-box, multi-relay and two-phone acceptance remains open, as does circle replication.

Production installation and everyday phones

The owner-held production key has produced an independently verified Android 0.6.2 production-lineage artifact. The public download remains the debug-signed 0.5.12 preview. The actual preview-to-production update on a real phone, background delivery and battery acceptance remain open. The profile's release identity and signed publication also remain separate work.

Lasting boundaries

What remains even when the design is complete.

People and endpoints

Recipients can copy content; compromised endpoints can expose it. Revocation cannot erase an existing copy. Cryptography cannot prevent physical harm or guarantee that a coerced circle refuses recovery.

Observation

Public activity remains observable. Direct peers may learn addresses. Carriers and quiet scheduling have specific protections and residual signals; they do not establish global invisibility.

Operating responsibility

Boxes need maintenance. Connectivity can fail. Recovery depends on preparation and enough available participants. A circle controls infrastructure but still depends on hardware, software and networks.

Other applications

Vennel's protection applies to its configured journeys. It is not a host firewall or VPN for unrelated applications.

Where these statements come from

The source records are the Vennel profile, its section-by-section status ledger and dated delivery records for the paired preview, quiet custody, Android signing, second relay and the 15 September history, anonymous-room, NIP-77 and VMLS work.

This static site includes the reader-facing summary so it works when served on its own. In the source checkout, maintainers should consult STATUS.md, VENNEL.md, RELEASE-GATE.md and the delivery records in docs/gate/ before updating a claim. The older comparison document is not a current release ledger.

Back to the reason for Vennel