VALKNETVIX SECURE INFRASTRUCTURE
Checking network
VIX CORE ONLINE///VIX-MSG 2.3///END-TO-END ENCRYPTION///BIX IDENTITY BRIDGE///MASTER TRUST CONTROL///NODE PLATFORM READY///ZERO PLAINTEXT ON CHAIN
VIX-MSG 2.3 Secure communications · sovereign node infrastructure

Communicate securely.
Operate your own trusted edge.

ValkNet combines device-authenticated end-to-end encrypted communications, VIX/BIX identity, chain-anchored proofs and deployable enterprise nodes under one governed trust architecture.

Deploy a Node Read technical docs ↗

X25519 + Ed25519Per-device agreement + signatures

AES-256-GCMFresh content key per message

#

VIX/BIX proofHashes and identity anchors, never plaintext

SECURE FABRIC / LIVEVIX-MSG 2.3 Secure Beta
EDGEDEVICE AUTHnon-exportable keys
ROUTEVIXNETsealed envelopes
TRUSTVIX / BIXidentity + proof
CONTROLMASTERpolicy + entitlement
CLIENT Aencrypt + sign
EDGE NODEtenant relay
VIX FABRICroute + proof
CLIENT Bverify + decrypt
VVIX
PROOF LAYERSHA-256(ciphertext) → VIX chain
API2.3Authenticated VIX-MSG gateway
MESSAGING1:1 LIVESecure groups live · epoch-controlled
IDENTITYVIX ↔ BIXCryptographic wallet binding
PLAINTEXTZEROServer and chain carry ciphertext/proofs
VIX Core

What VIX is.
Where it takes the lead.

VIX is the distributed trust and execution layer behind ValkNet: a validator-governed chain designed to combine verifiable state, secure identity, private communications and enterprise-operated infrastructure without putting sensitive plaintext or private keys on-chain.

VIX / 01

Privacy-first proof

VIX anchors hashes, identities and state proofs while encrypted content and private keys remain at the edge.

  • Proof without disclosure
  • Client-side key custody
  • Signed, replay-resistant activity
VIX / 02

Deterministic validator consensus

Independent validators verify the same proposal, execution result and state root before a block becomes certified.

  • Multi-validator verification
  • Deterministic execution
  • Auditable finality
VIX / 03

Built beyond payments

VIX is designed as infrastructure for communications, identity, assets, application proofs and enterprise nodes—not only token transfer.

  • VIX-MSG communications
  • VIX ↔ BIX identity
  • Enterprise edge nodes
VIX / 04

One governed trust fabric

The same trust plane can secure messaging, applications and remote nodes while keeping execution privileges separated and controlled.

  • Least-privilege services
  • Governed node enrollment
  • Modular protocol bridges
View Live VIX Explorer
Platform

One secure fabric.
Multiple operating modes.

ValkNet is designed for advanced users, regulated enterprises and operators who need private communications, independently managed edge infrastructure and verifiable trust without exposing message content.

COMMS / 01

Secure communications

Device-authenticated one-to-one messaging is live today; secure groups are live with local key custody, signed envelopes, replay protection and encrypted mailbox delivery.

  • 1:1 encrypted messaging
  • Group engine + membership epochs
  • Delivery/read receipts
  • Cross-device identity
NODE / 02

Enterprise nodes

Deploy a customer-controlled VIX edge node on company infrastructure while retaining master-chain trust, entitlement and policy anchors.

  • Tenant admin
  • Relay + messaging services
  • Signed enrollment
  • Managed update channel
HOST / 03

Secure hosted workloads

Run basic websites and service workloads inside isolated tenant containers with controlled ingress, separate state and centrally governed trust.

  • Container isolation
  • TLS edge gateway
  • Per-tenant storage
  • Backup-ready layout
BRIDGE / 04

Protocol bridge

Connect VIX trust and secure transport to financial, enterprise and Web3 systems through modular adapters instead of weakening the core.

  • FIX / FIXP / FIXS
  • ISO 20022
  • mTLS APIs + SFTP
  • Web3 asset bridge
Security architecture

Zero implicit trust.
Cryptographic proof at every boundary.

Private keys remain local to each client. Sessions authenticate devices, envelopes are digitally signed, recipients are bound to registered device keys and the transport layer never needs plaintext to route a message.

01 / KEY CUSTODY

Non-exportable client keys

X25519 and Ed25519 keys are created inside Web Crypto where supported. P-256 remains an explicit compatibility fallback.

private_key → device only
02 / MESSAGE

Fresh message secrets

Each message receives a new AES-256 content key. HKDF derives wrapping keys from fresh key-agreement material.

X25519 → HKDF → AES-256-GCM
03 / AUTHENTICITY

Signed envelopes

The API verifies the registered device signature before accepting ciphertext, and deterministic message IDs reject replay attempts.

session + signature + replay guard
04 / CHAIN

Proof without disclosure

VIX receives hashes, route proofs and identity anchors. Message plaintext and private keys are deliberately excluded.

SHA-256(ciphertext) → VIX
05 / IDENTITY

VIX ↔ BIX binding

A BIX wallet binds only after one-time challenge verification and exact Ed25519 public-key address derivation.

challenge → sign → verify → bind
06 / PLATFORM

Master-rooted tenant trust

Remote nodes generate their own identity, pin the master key and accept only master-signed entitlement manifests.

tenant node → master trust root
VIX Node Platform

Your infrastructure.
Your admin.
Our trust backbone.

Organizations may operate a ValkNet/VIX edge on infrastructure they control only after registration, explicit owner approval and licensing. Every authorized node remains subordinate to the master VIX trust plane for entitlement, chain authority, policy, proof anchoring, revocation and controlled updates.

MASTER VIXTrust · Chain · Policy · EntitlementROOT
TENANT CONTROLCompany Admin · RBAC · AuditMANAGED
RELAYVIXNet
COMMSVIX-MSG
HOSTINGIsolated Web
EDGETLS Gateway
Owner approval requiredActive license requiredOne-time enrollmentMaster-key pinningSigned entitlementsContinuous license checksRevocation enforced
Connector framework

Built to connect into serious infrastructure.

Protocol support is modular. Regulated and enterprise adapters terminate into policy-controlled services instead of opening direct access to the VIX core.

FINANCIAL

FIX / FIXP / FIXS

Session, market-data and execution connectivity with controlled gateway and administrative layers.

PAYMENTS

ISO 20022

Adapter-ready financial messaging for structured payment and settlement workflows.

ENTERPRISE

mTLS · SFTP · AS2/AS4

Mutually authenticated APIs and secure file/message interchange for partner networks.

IDENTITY

PKI · PIV/CAC-ready

X.509 and hardware-backed identity profiles for higher-assurance deployments.

NETWORK

IPsec / IKEv2

Private inter-site connectivity profiles for tenant nodes and protected integration zones.

WEB3

VIX / BIX bridge

Wallet-bound identity, chain proofs and external asset adapters without placing message content on-chain.

Protocol availability depends on deployment profile, implementation scope and applicable licensing/regulatory requirements. Proprietary or restricted interfaces are not represented as enabled unless specifically implemented and authorized.

VIX-MSG 2.3

Encryption at the edge.
Proof in the fabric.

1IdentityVIX + BIX bind
2AgreementX25519
3EnvelopeAES-256-GCM
4SignatureEd25519
5ProofVIX anchor
Clients

Use ValkNet wherever the work happens.

The secure browser client is installable today as a PWA. Native packaging follows the same VIX identity and device-key model so communications stay interoperable across platforms.

AVAILABLE

Secure Web / PWA

Install from a supported browser for a standalone client experience with offline shell caching and local cryptographic key custody.

AVAILABLE

Android

Signed ValkNet Secure APK with the live VIX-MSG client, local key custody and permission-gated microphone/camera capability.

Download Android APK
PACKAGING

iPhone / iPad

Native iOS project path with TestFlight/App Store signing handled through Apple/Xcode release infrastructure.

iOS readiness
PLANNED

Desktop

Managed installers for Windows, macOS and Linux with the same device enrollment and VIX/BIX identity model.

Desktop roadmap
Commercial deployment

From secure client to sovereign edge.

Commercial packaging is designed around entitlement-controlled capabilities rather than separate insecure forks of the platform.

CLIENT

VIX Secure Client

Encrypted 1:1 and group communications, device identity and VIX/BIX binding.

Individual / Team
BUSINESS

Managed Edge Node

Company admin, relay, messaging gateway and secure hosting under a licensed, owner-approved VIX entitlement.

Approval + Subscription
Secure client

Operator-grade encrypted communications.

Enroll this device, bind your identity and communicate through the live VIX-MSG fabric.

Local keys · signed envelopes · authenticated mailbox
V
ValkNet Secure ConsoleSelect or start a conversation
X25519AES-256-GCMED25519
V

Secure session not initialized.

Enroll this device to generate local cryptographic keys, then open a registered VIX or bound BIX identity.

Encrypted + signed locally before uploadIdle