A messenger no one owns needs an institution that owns nothing.
The Onym Foundation funds audits and shared infrastructure, awards grants, coordinates standards, and stewards a permanent endowment — for the Onym network of independently owned roles.
01
No single owner
The product splits into independently owned roles. Nobody holds the whole. The product, at onym.app →
Identity stays with the person
Keys are held by the user. No account to seize, sell, or subpoena.
Interfaces compete
Any app can present the network. The window is not the gatekeeper.
Carriers are designed blind
The contract requires that the courier cannot read the letter. Delivery is a service, not a vantage point.
Verifiers are designed roster-free
Group decisions are confirmed without seeing who is in the group — that is what the notary contract fixes.
Where this stands — plain words
Exists today
- Native iOS and Android clients, and one replaceable default deployment of message carriage, media storage, and group verification — plus, on iOS only, a live moderation authority and the DeviceCheck enforcement backend that executes its verdicts.
- Public, technology-neutral contract documents for fifteen seats. The moderation seat's Apple profile is finalized and implemented; its Android sibling is still draft. The device backup seat has a merged Object-HTTP implementation profile but no conforming code at all.
Designed to guarantee
- The courier cannot read the letter; the verifier never sees the member list; the name is never the identity.
- These are contract obligations the documents fix — not yet independently verified properties of the running code.
Open and unaudited
- The system is alpha-grade and has had no independent audit. Identity rotation, forward-secret messaging, and conformance fixtures are explicitly open work.
- Banking and naming seats are proposals in review. The device backup contract has a merged Object-HTTP implementation profile, but no conforming code exists, so nothing conforms to it yet. Metadata-exposure assumptions are documented in the whitepaper's threat model.
02
The seat economy
Every role is open to implementation. Payment follows an explicit choice by the person, group, buyer, or legal authority entitled to choose that role. “Seat” is shorthand across protocol, service, application, and organizational layers—not a promise that every role has the same exit boundary.
Explore the seats →
Implementation docs — what's built, seat by seat ↗
Register interest to take a seat — lead@onym.app
User
the centerControls personal choices; group and legal roles keep their declared selection authority. Identity boundary →
Interface
Earns app pricing. Contract →
Message carriage
Earns subscriptions. Contract →
Media storage
Earns storage plans. Contract →
Group verification
Earns per-operation fees. Contract →
Naming
in reviewEarns issuance fees. Proposal →
Banking
in reviewEarns payment fees. Proposal →
Audit
Earns engagement fees. Contract →
Discovery
Finds compatible instances across every seat. Contract →
Moderation
Earns per report adjudicated, never per ban. Contract →
+ 8 more seats
Each earning when chosen. All seats →
Seat contracts, as proposed in the public repository — Interface · Message carriage · Media storage · Group verification · Audit & attestation · Arbitration · Discovery · Charitable coordination · Distribution · Acquisition · Recruitment · Recovery trustee · Sponsorship · Moderation authority · Bankingin review · Namingin review. Device backupprofile merged, no code. Identity is not a seat — it stays with the person, and seed custody is not a seat either: it is how the recovery trustee's profiles differ. What durable copies cost everyone →
03
User safety without a master switch
Encrypted does not mean lawless. The moderation seat lets users report abuse — child sexual abuse material, credible violence, unsolicited pornography — to an independent authority they accepted when they joined, and lets apps keep banned devices out. The powers stay separate: the authority judges, the app enforces, and neither can reach a message nobody disclosed. What an authority may accept — including photographs — how long it keeps it, when it deletes it, and which classes it preserves and refers to the state are published terms, pinned when a user consents rather than restated later. The moderation contract →
On iOS this now runs in production: an authority adjudicating live reports, and the DeviceCheck backend executing its verdicts — both from the Rust reference implementation → and both currently operated by Onym as the replaceable default, which is one operator holding two halves the contract means to keep apart. The Android device-recall path is draft and not deployed. Nothing is audited.
01 · REPORT
You disclose what you received
Reporting shares the specific offending message — text, or a photograph where the authority accepts them — from your own device, with cryptographic proof of who sent it. Nothing else leaves your phone: no mailbox, no undisclosed message, and nobody scans anything.
02 · CASE
A case, not a black box
The accused is notified, sees the evidence and the exact rule they agreed to at onboarding, and gets a response window before any decision.
03 · VERDICT
Signed, reasoned, expiring
Bans carry written reasons, published durations, and an appeal path — including for a device's next owner. An authority that goes silent means dismissal, never a freeze.
04 · ENFORCEMENT
The app executes, mechanically
A banned device stops working in apps that adopted the authority — marked via Apple DeviceCheck or Google Play device recall, so reinstalling doesn't reset it. The open protocol itself is untouched.
No scanning, no backdoors — evidence exists only when a recipient chooses to disclose it.
Judges never profit from convictions — authorities earn per report adjudicated, never per ban or per case opened.
Consent precedes the case — the rules you can be judged by are the rules you signed, resolved from the manifest you pinned rather than today's.
04
Where the Foundation stands
Outside the transaction ring. Arrows go out — to audits, grants, infrastructure, standards, recognition. Never into the message path or any seat's revenue.
Money flows out
Audits · grants · conformance infrastructure · standards coordination · recognition.
Nothing flows in
No Foundation arrow enters the message path or any seat's revenue. We take no toll.
05
Why sponsors, why now
The network's commons — independent audits, conformance test suites, reference infrastructure, grants to seat pioneers — need funding before the seat economy can pay for itself. Founding sponsors make that possible, and are remembered for it.
Audits
Independent security and conformance examinations, published openly.
Grants
Seeding the first operators of new seats — registries, auditors, couriers.
Endowment
A default share of every unrestricted gift is endowed, and a donor may decline that share. Most of each gift still funds current work, so the commons outlives any single donor without starving its first years.
06
Money can fund the mission. It cannot buy a majority.
3 sponsor-class directors, 3 ecosystem directors, 3 independent public-interest directors — the supervisory board of an Estonian foundation. No seat has a contribution-linked selection route. Chair and treasurer: never sponsors. Selection, transition, and spending rules →
Proposed governance — no entity or board exists yet.
3 Sponsor-class Directors
Seats where sponsor affiliation is declared and capped. Selection route undecided; no contribution reaches one.
3 Ecosystem Directors
Elected by a non-pay-to-enter Ecosystem Council.
3 Independent Public-Interest
Openly nominated and elected by a separate, non-pay-to-enter Public Interest Council.