AES-256-GCM Encryption
Every message is encrypted client-side with AES-256-GCM before embedding. The encryption key is derived locally and never touches our servers.
Embed AES-256-GCM encrypted messages inside any photo. Share it anywhere. The image looks completely ordinary. Only City of Hats Premium can decrypt what's inside.

Watch how to hide an encrypted message inside an ordinary image — and decode it on the other end. Invisible to anyone without City of Hats.

GhostFrame combines image steganography with AES-256-GCM encryption and a hybrid token architecture — designed to remain intact across common image-sharing platforms.
Every message is encrypted client-side with AES-256-GCM before embedding. The encryption key is derived locally and never touches our servers.
A small token is embedded in the image pixels. The encrypted payload is stored separately on our servers. This hybrid approach remains intact across WhatsApp, LINE, and other image-sharing platforms.
Set your GhostFrame to self-destruct after first read, after a set number of retrievals, on a time delay, or after a countdown timer. Once burned, the payload is permanently deleted.
Choose who can decrypt: anyone with City of Hats Premium, or lock it to a specific Hat identity. Without the right permissions, the image looks like any ordinary photo.
From import to decode — the entire process happens client-side. Your plaintext never touches our servers.
Pick any photo from your camera roll, Google Photos, or local files. Any standard image format works.
Write your secret message. AES-256-GCM encrypts it client-side. Set lifecycle rules — burn-after-read, time-lock, auto-destroy.
The encrypted token is embedded into the image pixels. Share the image normally — email, Dropbox, WhatsApp, anywhere.
The recipient imports the image into City of Hats. The token retrieves and decrypts the message. Then it's gone.
When the channel itself needs to be invisible — not just encrypted.
Receive sensitive documents and tipoffs hidden inside ordinary photos. No metadata trail, no suspicious file names — just a family photo that happens to contain classified information.
Share transaction approvals, compliance alerts, and sensitive financial data through images that look routine. Audit-ready with burn-after-read timers.
Exchange privileged communications inside image attachments. Attorney-client privilege protected by steganography and AES-256-GCM — invisible to discovery tools.
Share confidential information through images in environments where standard encrypted channels draw attention. GhostFrame provides a discreet transport layer for sensitive operations.
Share HIPAA-sensitive patient data between practitioners without exposing it in email bodies or chat logs. Burn-after-read ensures zero retention.
Distribute vulnerability disclosures, breach reports, and incident response instructions inside images. No one knows the image contains critical security data.
Every architectural decision is designed to minimize exposure and prevent recovery after burn.
Import any image. Write a message. Embed it. Share it. The image looks ordinary — only City of Hats Premium can decrypt what's inside.