Whatping

About

Software you don’t have to trust

Most “secure” business tools ask you to trust the operator. Whatping is built so you don’t have to — confidentiality is enforced by cryptography, in the open, and tested.

Whatping started from a simple discomfort: the conversations and documents that matter most — a deal, a case, a diagnosis, a board decision — were running through tools designed for convenience, where the provider can read everything. “Trust us” is not a security model.

So we built the opposite. Identity and media keys are generated in your browser. Every room is an MLS (RFC 9420) group, and chat, audio, video and screen-share keys are derived from it. Our relay and media servers move encrypted bytes they cannot read. We prove that property with end-to-end tests — a wrong-key participant decodes zero frames — rather than asserting it in a policy document.

We’re a small, focused team, and we’re honest about where we are: the crypto core builds on the MLS standard and is continuously tested; formal external audit and SOC 2 / ISO 27001 are on the path as we onboard design partners. If certification status matters to your procurement, ask us directly — we’ll tell you exactly where things stand today.

You can use Whatping hosted in the EU or Switzerland, run it single-tenant, or self-host the entire stack inside your own perimeter. Your data, your jurisdiction, your keys.

Principles

What we believe

🔒 Confidential by construction

If the server can read it, it isn’t private. We design so it can’t.

🧪 Proven, not promised

Security claims are backed by tests you could run yourself.

🌍 Your jurisdiction

EU/Swiss hosting, single-tenant, or fully self-hosted — your call.

🤝 Honest about maturity

We tell you what’s audited, what’s tested, and what’s still ahead.

Work with us early

We’re onboarding design partners who care about real confidentiality. If that’s you, let’s talk.