03 — We & Them

The rows we lose are in here too.

A comparison that only flatters us would tell you nothing, and you would find the missing rows in an afternoon. So this page marks every place a competitor beats us in red, and says what we are doing about it — or that we are not.

The giants

Scale figures are public estimates from 2026 and vary by source; treat them as directional. The column that matters is the third one.

PlatformScalePhone number E2E by defaultE2E callsAdvertisingHow it earns
WhatsApp~2B+RequiredYesYesYes, since 2025Business API, click-to-message ads, in-app ads
WeChat~1.3BRequiredNoNoYesSuper-app: payments, mini-apps, ads
iMessage~1B devicesApple IDYesYesNoSells hardware
Telegram~1BRequiredOpt-in only1:1 onlyYesPremium (~$342M by 2023), channel ads
Messenger~1BAccountYes, since 2023MostlyYesAds, business messaging
Snapchat~800MAccountSnaps onlyNoYesAds, Snapchat+ (~$4/mo)
Signal~40–70MRequiredYesYesNoDonations. ~$50M/yr burn, publicly acknowledged as a question
Spojitipre-launchNeverYes, alwaysYes, alwaysNeverFree + Premium /yr India, /yr elsewhere
One row has "never" in the phone-number column. Combine that column with end-to-end calls and no advertising, and among the giants the intersection is empty. That intersection is the product.

The privacy-native field — where the real fight is

These are the people we actually compete with, and the honest read is that each of them is missing exactly one leg. So are we. The question is whether ours is the one that can be fixed with money.

ProjectUsersHow it earnsTheir strengthThe leg they are missing
Signal~40–70MDonationsThe brand, a decade of public audits, published formal analyses of their protocolNo revenue model. ~$50M/yr covered by a founder's loan and giving
Threema~5–10MOne-time purchase, ~CHF 6Profitable for a decade. The existence proof that paid, identity-free messaging worksNo free tier — you pay before your first message, so it never goes viral. And the store purchase re-attaches the identity the app avoided
Session~1MToken stakingOnion-routed, open source, no company infrastructure to compelNo forward secrecy today, by their own documentation. Their Protocol V2 was still in design as of December 2025
SimpleXnicheDonations and investmentThe most radical privacy design in the field — no identifiers at all. Post-quantum first, in 2024. Trail of Bits auditsNo revenue model. Signal's fragility on a smaller network
Spojitipre-launchFree + Premium, paid on a rail that cannot identify youPost-quantum authentication ahead of Signal and Apple; anonymous payments; a free tier that never paywalls safetyNo users, no audit, not open source yet. All three are what this round buys
The line we would put on a single slide

Session has no forward secrecy yet. Threema has no free tier. SimpleX and Signal have no revenue model. We are the only project attempting mainstream usability, zero identity, strongest-available cryptography and customer funding that stays unlinkable — all four at the same time. That is a genuinely defensible square. It is also, today, an empty one: we have not proved we can hold it.

Against Signal, row by row

Signal is the benchmark and it would be dishonest to pretend otherwise. Here is where each of us actually stands.

DimensionSignalSpojitiWho wins
Root identityPhone number at registration; usernames arrived 2024 but the number is still the rootA twelve-word phrase. No number, everSpojiti
Core protocolX3DH + Double Ratchet — they invented itThe same science, inherited gratefullyTie
Post-quantum key agreementIn production since 2023In production since August 2026Closed
Post-quantum authenticationClassical signaturesML-DSA-65 beside Ed25519 on every published keySpojiti
Sender metadataSealed sender, years of productionSealed sender, shipped build 317Closed
Recipient metadataAlso visible to their serversAlso visible to oursNeither
Protocol assurancePublished formal analyses by outside cryptographersKnown-answer tests on the device and a deliberately small design. No outside analysisSignal
TransparencyFully open source for a decade, repeatedly auditedClosed and unaudited today. Extraction tooling built; repositories not yet publicSignal
JurisdictionUS non-profitIndian company under a traceability mandate, and we cannot leave homeSignal
Feature surfaceTen years of accumulated productThree platforms, one year, five peopleSignal
SustainabilityDonations; ~$50M/yr; a stated open questionCustomers pay, and still cannot be identifiedSpojiti

Two places nobody else is

Having said all that, there are two claims we will defend against anyone.

Post-quantum authentication. We carry a post-quantum signature beside the classical one on every published key, and our safety number commits to both. Signal uses classical signatures. Apple's PQ3 uses classical signatures and says it will continue to assess the need. Neither has shipped this leg, and both say so themselves.

Verification on the device, every launch. Signal and Apple verify their cryptographic primitives when they build. We verify ours on your phone, at every launch, against the standards body's own published test vectors — and a device that cannot prove a primitive publishes nothing post-quantum and accepts nothing post-quantum. It fails closed.

Previous
Our Answer