Back to Insights

Secure in Transit, Clear About the Rest

MPower encrypts every call and message in transit, keeps messages and stories encrypted at rest, and runs on infrastructure we own. Here is precisely what that protects — and what it does not.

MPower SecurityJuly 7, 20263 min read
Security

Security claims age badly. The industry has spent a decade attaching the phrase "end-to-end encrypted" to products that are not, and users have learned to discount the language. So we will be exact about MPower, including where the protection stops.

What "encrypted in transit" means, and what it does not

Every MPower call and every message travels over an encrypted channel. Voice, video, text, photos, files, voice notes, live location: all of it is protected in transit between your device and our systems, and onward to the person you are reaching. Someone on the same public Wi-Fi, a hostile network operator, or anyone sitting on the path between endpoints cannot read what passes.

This is encryption in transit. It is not end-to-end encryption, and we will not describe it as such. The distinction is real. Because traffic is decrypted on our own infrastructure so it can be routed, translated across the 57 languages we support, and delivered, MPower is not architecturally blind to content the way an end-to-end system claims to be. Anyone who tells you a routed, translated calling service is "zero-knowledge" is describing a wish, not the architecture. We would rather you trust the smaller statement that is true.

Encrypted at rest, on hardware we own

Messages and stories are also encrypted at rest. When your text or your 24-hour story sits in storage, it sits as ciphertext, protected with AES-256-GCM. A stolen disk is not a readable archive.

Two facts sit behind that guarantee. First, MPower runs on the company's own infrastructure: our servers, in Germany, under our operational control, not rented capacity we cannot inspect. Second, the keys are ours to protect. Encryption at rest is only as strong as key custody, and we treat the loss of a key as catastrophic by design: without it, the data is unrecoverable, to us as much as to anyone. That is the correct trade.

Identity you can see

A large share of real-world fraud is not decryption. It is impersonation. MPower binds identity to a verified phone number. The number is confirmed on the network before it becomes your identity, and other users see you by it. When you place a call to an ordinary landline or mobile, your own number is shown as caller ID once you have verified it with the carrier under Settings, Caller ID; until then a shared MPower number stands in. Verification is the point. A recognisable, confirmed number is a defence against the class of attack no cipher addresses.

The controls you hold

Protection you cannot operate is decoration. The account-level controls are built to be used. Two-step verification adds a PIN to your account, so a hijacked SIM is not a hijacked identity. A block list ends contact on your terms. Chat lock keeps individual conversations behind a second gate on a shared or borrowed device. Archive and delete let you decide what remains. Story privacy — who may view a story, and the seen-by record — keeps a 24-hour broadcast from reaching an audience you did not intend.

None of these is novel in isolation. Together, and honestly described, they are the difference between a product that protects you and one that photographs well.

Security is not a finished state. Protocols weaken, threat models shift, and the honest position is to keep the claims matched to the engineering as both change. We would rather narrow a promise than inflate one, and we intend to keep publishing what we actually run, so that the description and the system remain the same document.

Talk in any language, free between users

MPower Space is free to download. Calls, video and messages between users cost nothing, with live voice translation across 57 languages.

Download the app