Cellular Defense

Who it's for

Confidentiality duties, ordinary staff, no security team

The people below already handle other people's most sensitive documents, and today most of them do it over email. The threat is a breached mailbox, a forwarded thread or a curious administrator — and that is squarely inside what this handles.

Law firms

Client material that shouldn't sit in a mailbox

Settlement terms, discovery, engagement records. Publish the firm's intake key once and clients send documents in from a browser tab — no portal enrolment, no password reset call, nothing for the client to install.

CPAs · tax prep

Stop emailing SSNs

Every January, W-2s and bank details move by email attachment because the alternative is too much friction for the client. Removing the account requirement from the sending side is what actually changes that behaviour.

Title · escrow

Wire instructions under dual control

Wire fraud works by producing a convincing document that one person acts on alone. A k-of-n document cannot be opened alone, so a forged instruction fails before anyone has to notice it looks wrong.

MSPs

Credentials and audit material across client boundaries

Handing over infrastructure documentation without leaving it in a shared drive, and with a disposal term attached at the operator side rather than in a policy document.

Ethics intake

Confidential reporting that a mid-size company can actually run

Whistleblower-protection and SOX obligations require a confidential channel. Publishing a verified intake listing gives one that the compliance team can stand behind, without operating specialist infrastructure.

Scope

What this is not for, stated up front

Being specific about the threat model is part of the product. Two things we will not claim until they are built, tested and independently reviewed:

This is not anonymity

End-to-end encryption hides the contents of a document. It does not hide that a delivery happened, and we do not market it as protection for a source facing a well-resourced adversary.

This is not a compliance package

Strong encryption is one control among many. Regulated healthcare workloads need a signed agreement and a documented control set — ask us where that stands before assuming it.

Getting started

Publishing a key takes about a minute

Generate a keypair in your browser, prove the address is yours with a magic link, and your listing becomes discoverable. Anyone can then encrypt to you without an account.