End-to-End Encrypted, Peer-to-Peer First

GSTNet uses AES-256-GCM encryption to protect communication content, combined with a peer-to-peer-first architecture: direct device-to-device connectivity is preferred whenever network conditions allow.

Get Your GST-ID Free
Security Stack — Bottom to Top
1

Physical Transport

WebRTC P2P — direct device-to-device

P2P
2

Key Exchange

ECDH-P-256 — Elliptic Curve Diffie-Hellman

ECDH
3

Encryption

AES-256-GCM — 256-bit authenticated encryption

AES-256
4

Forward Secrecy

New keys per session — past sessions protected

PFS
5

Identity

GST-ID — account identifier, Supabase-backed, RLS-protected

AUTH
6

Content Protection

Global Space Technology cannot decrypt protected message content

E2E

Security Specifications

Encryption

AlgorithmAES-256-GCM
Key Size256 bits
IV Size96 bits
Auth Tag128 bits
StandardNIST FIPS 197

Key Exchange

ProtocolECDH-P-256
CurveP-256 (secp256r1)
Key Length256 bits
Forward Secrecy✓ PFS
StandardNIST SP 800-56A

Transport

ProtocolWebRTC
DTLS1.2 / 1.3
SRTPAES-128-CM
ICERFC 8445
STUN/TURNRFC 5389

Why WebRTC Changes Everything

WebRTC (Web Real-Time Communication) is an open standard that enables direct peer-to-peer communication between devices, minimizing reliance on a central server to relay data.

When two GSTNet users connect, GSTNet attempts to establish a direct encrypted channel between their devices. Backend infrastructure supports account management, authentication, and connectivity assistance (signaling); when a direct peer-to-peer connection can't be established due to network conditions, a secure relay may be used to maintain the connection.

Regardless of the connection path, Global Space Technology does not possess the cryptographic keys required to decrypt protected communication content.

🔑

Ephemeral Keys

New encryption keys generated for every session. Keys exist only in device memory and are never saved.

🌊

Perfect Forward Secrecy

If one session key is compromised, all other sessions remain secure. Past messages cannot be decrypted.

📡

ICE/STUN/TURN

Industry-standard protocols ensure connectivity even behind firewalls and NAT configurations worldwide.

🔒

DTLS-SRTP

All WebRTC streams are protected by DTLS handshake and SRTP encryption — double-layered security for calls.

Next Generation Protocols

🛰️

Satellite Communication

Phase 4 roadmap includes Starlink and Iridium satellite integration. Communicate from anywhere on Earth without ground-based internet infrastructure.

📻

RF Mesh Network

Radio frequency communication for battlefield and disaster scenarios. Devices form self-healing mesh networks with no dependency on existing infrastructure.

🔮

Quantum-Ready Encryption

Post-quantum cryptography integration planned to ensure communications remain secure against future quantum computing attacks.

Does GSTNet Use Servers?

Yes. GSTNet uses backend infrastructure for account management, authentication, security and abuse prevention, entitlement management, and connectivity assistance. Communication is designed to use direct peer-to-peer connectivity whenever possible.

The important distinction: backend infrastructure does not mean Global Space Technology possesses the cryptographic keys required to decrypt protected end-to-end encrypted communication content. That protection comes from the encryption itself, not from an absence of servers.

Experience End-to-End Encrypted Communication

90 days of introductory access. No technical knowledge required.