Per-hop encryption
Each hop derives its own content key from a fresh ECDH exchange between exactly the two peers on that hop. Keys are never reused across hops and never derived from a long-lived secret, so compromising one hop's key yields one hop's payload and nothing else.
envelope opened →