Secure Drop
Anonymous · Encrypted · No login required
Your message is sealed and anonymous. We cannot identify you. No account or login is needed.
Your message
Max 3 files, 10 MB each
Secure Channel
Anonymous · Bidirectional · Encrypted
Start an anonymous conversation. You'll receive a thread code to check for replies later.
Your message
Max 3 files, 10 MB each
Thread Code
Enter your thread code above to check for replies.
Secure communication platform

For work where a leak is not an option.

Journalists, lawyers, executives, field teams — exchange messages, files, and calls under post-quantum end-to-end encryption. No phone number. No email. And if your device is gone, so is everything on it. By design.

60 seconds. No phone number. No email.

Sealed on your device End-to-end encrypted Keys only on your devices Post-quantum ML-KEM-768 hybrid Your rules You choose, per message 11 SECURITY MODES View Once Recall Sealed File Unlock Content Verified Eyes Only GeoLock Voice Lock Hold to Reveal Certified Send Hat Tap to Unlock Invisible Watermark View Once Recall Sealed File Unlock Content Verified Eyes Only GeoLock Voice Lock Hold to Reveal Certified Send Hat Tap to Unlock Invisible Watermark a7f2 91c4 e08b 3d5a 6e1d bb70 4c93 f2a8 05fc 8a2e d417 9b60 Our server carries it — and sees only this YOUR HAT · BURN & SEAL Keep this Hat Channel Seal — 1 hour Channel Seal — 24 hours Channel Seal — 7 days Burn this Hat Keep this Hat Channel Seal — 1 hour Channel Seal — 24 hours Channel Seal — 7 days Burn this Hat Keep this Hat Channel Seal — 1 hour 3 2 1 You Their Hat Burned. Nothing left to seize. Burnable Hats · burnable messages · Channel Seal
No phone number, no email Reachable by Phrase ID No recovery — nothing to seize Post-quantum E2EE (ML-KEM-768) Burnable identities Channel Seal — chats vanish on a timer
Verify, don’t trust

Don’t trust us. Check us.

Security claims are cheap. Here is what you can verify — and what we deliberately cannot do.

No recovery. That’s the feature.

Lose your device and your messages are gone — there is no backup vault, no recovery email, no support desk that can restore your account. Nothing exists for anyone to seize, subpoena, or force out of you. Get a new phone, create a new Hat, keep going.

Learn More →

Warrant canary

A regularly updated public statement that changes if we are ever compelled and gagged. Watch it — don’t take our word for it.

View the canary →

Named cryptography, not adjectives

X25519 + ML-KEM-768 hybrid key agreement feeding a Double Ratchet. AES-256-GCM. Fresh keys for every call. Group keys rotate on every membership change.

Learn More →

Key transparency log

Identity keys are published to a signed, append-only log that your app verifies and cross-checks with your peers. A swapped key becomes evidence, not a secret.

Learn More →

Calls never expose your IP

There is no peer-to-peer mode to leak your location to the other side. Every call is relayed with end-to-end encrypted media — by architecture, not by a setting you have to find.

Learn More →

How we compare — on facts

Capability City of Hats Signal WhatsApp Telegram
Phone number to sign up Never Required Required Required
Burnable pseudonymous identities Unlimited Hats No No No
Post-quantum key agreement Yes — ML-KEM-768 hybrid Yes Not yet No
Message recovery path None — by design PIN-based recovery Cloud backups Everything on their cloud
Per-message security controls 11 modes — view-once, GeoLock, NFC, watermark, recall… Limited Limited Limited
E2EE on by default, everywhere Yes — including groups & calls Yes Yes No — Secret Chats only
Controlled sharing after you hit send Yes — 11 modes on every message and file: view-once, recall, GeoLock, biometric, NFC tap, PIN-sealed, invisible watermark Disappearing messages only View-once & delete-for-everyone Self-destruct timer (Secret Chats)

Comparison reflects publicly documented behavior of each app’s default configuration at the time of writing.

Security modes

11 security controls no other messenger offers

You stay in control after you hit send. Every message and file carries sender-side locks the receiver cannot strip.

#ModeDescription
1 View Once Self-destructs after a single view
2 Recall Pull it back anytime, even after delivery
3 Sealed File PIN-locked; share the code on your terms
4 Unlock Content Recipient pays to access
5 Verified Eyes Only Requires biometric face liveness verification
6 GeoLock Only viewable from an approved location
7 Voice Lock Recipient must pass voice verification
8 Hold to Reveal Must physically hold the screen to read
9 Certified Send Opens in a Protected Viewer with cryptographic proof of who opened it and when
10 Hat Tap to Unlock Recipient must tap their NFC Hat to view the file — physical presence required
11 Invisible Watermark Marks the file with the viewer’s identity — if it leaks, the trail points back to who opened it.
1

View Once

Self-destructs after a single view

2

Recall

Pull it back anytime, even after delivery

3

Sealed File

PIN-locked; share the code on your terms

4

Unlock Content

Recipient pays to access

5

Verified Eyes Only

Requires biometric face liveness verification

6

GeoLock

Only viewable from an approved location

7

Voice Lock

Recipient must pass voice verification

8

Hold to Reveal

Must physically hold the screen to read

9

Certified Send

Opens in a Protected Viewer with cryptographic proof of who opened it and when

10

Hat Tap to Unlock

Recipient must tap their NFC Hat to view the file — physical presence required

11

Invisible Watermark

Marks the file with the viewer’s identity — if it leaks, the trail points back to who opened it.

CHECK
> check email you@example.com
✓ 3 breaches found · risk: high
> check phone 0801110656
✓ carrier verified · no SIM swap
> check domain example.com
✓ 2 open ports · SSL valid
status: monitor active...
Built-In Intelligence

Cyber intelligence inside your conversations

No dashboard. No separate login. Just type a command in the chat.

  • Risk scoring and exposure analysis
  • Credential detection across security databases
  • Carrier verification and SIM swap detection
  • IP reputation with VPN/proxy/Tor detection
  • Results delivered as self-destructing secure reports
See It In Action

Get started in 30 seconds

No phone number. No email. No sign-up form. Watch how to create your first anonymous Hat identity and start a secure conversation.

Running a hotel, clinic, school, or team?

The same security architecture powers branded guest and staff experiences.

City of Hats for business
Questions

Straight answers

Can City of Hats read my messages?
No. Messages, files, and calls are end-to-end encrypted — X25519 + ML-KEM-768 hybrid key agreement feeding a Double Ratchet, with AES-256-GCM. The keys exist only on your devices. We cannot read your conversations, and neither can anyone who compels us.
What happens if I lose my phone?
Your messages are gone. There is no backup vault, no recovery email, and no support desk that can restore them — by design. Nothing recoverable exists for anyone to seize, subpoena, or coerce out of you. Get a new phone, create a new Hat, and continue.
Do I need a phone number or email to sign up?
No. Create a Hat — a pseudonymous identity — in about 60 seconds with no phone number and no email. People reach you through your Phrase ID, a memorable phrase you choose.
What is a warrant canary?
A regularly updated public statement affirming we have not received secret legal demands. If it stops updating or changes, that silence is your signal. You watch it — you don’t take our word.
How much does City of Hats cost?
Free forever for secure messaging, calls, and core security modes. Premium features are available for advanced and business use.

Your first Hat takes 60 seconds.

No phone number. No email. Nothing to recover — by design.

Available on

Free forever. Premium features available.