# Cove — Private & Verified Dating App > Cove is a zero-trust, post-quantum end-to-end encrypted connection sanctuary and verified dating application. Engineered for authentic daters, Cove enforces biometric liveness verification, renders incoming media behind an opaque blur canvas ("The Veil"), and protects ephemeral communications with post-quantum cryptography. Operated by Hestarion Technologies Private Limited. ## Core Navigation & Canonical Endpoints - [Home](https://covechat.app/): Main landing page, architectural pillars, and sanctuary access requests. - [Privacy Charter](https://covechat.app/privacy): Statutory Privacy Notice and Data Charter complying with GDPR, CCPA, and the Indian DPDP Act 2023. - [Terms of Engagement](https://covechat.app/terms): Terms of Service, member safety code, age verification rules (18+), and binding arbitration. - [Cancellation & Refund Policy](https://covechat.app/refunds): In-app billing terms, digital subscription management, and Sovereign Pass packages. - [RFC 9116 Security Disclosure](https://covechat.app/.well-known/security.txt): Responsible vulnerability disclosure program, encryption keys, and security desk contact. ## Key Facts & Cryptographic Architecture - Post-Quantum Hybrid Cryptography: Key exchanges combine classical X25519 with post-quantum ML-KEM (Kyber-768 / NIST FIPS 203) to secure communications against future quantum decryption ("harvest now, decrypt later"). - Tamper-Evident Signatures: Administrative attestations and audit events utilize ML-DSA (Dilithium / NIST FIPS 204). - Volatile RAM Hygiene: Decrypted chat messages, voice notes, and media decryption keys live exclusively in volatile RAM. No local disk caching in SQLite, Hive, or device storage; memory buffers are zeroed out (0x00) immediately upon view disposal. - Dual-Schema PostgreSQL Architecture: Personal Identifiable Information (PII), phone nonces, and cryptographic key material are strictly isolated in `vault_private` behind database Row-Level Security (RLS). Ephemeral application entities and pseudonym aliases reside in `app`. - 3D Liveness Verification & Carrier Screening: Users must complete a 3D facial liveness verification challenge to eliminate bots and catfishers. Carrier anti-VoIP screening blocks virtual and burner numbers. Verification selfies are purged immediately from validation queues once verified. - The Veil (Tap to Peek): Incoming photos and videos are rendered behind an opaque graphical blur canvas by default, requiring deliberate touch contact to peek, with automatic snapback to protect privacy against shoulder surfing and non-consensual capture. - Cryptographic Scuttle: Either participant in a chat room can trigger an instantaneous scuttle, permanently and irrevocably purging message history from both devices and relay servers. - Sovereign Beta: Cove is in private Sovereign Beta, preparing for iOS (Apple App Store) and Android (Google Play Store) distribution. ## Operating Entity & Contact Information - Operating Entity: Hestarion Technologies Private Limited - Registered Office: Level 4, Dynasty Business Park, Andheri-Kurla Road, Andheri East, Mumbai, Maharashtra 400059, India - Canonical Domain: https://covechat.app - Member Support: support@covechat.app - Security Desk: security@covechat.app - Legal Inquiries: legal@covechat.app - GitHub Repository: https://github.com/deadmantfa/cove-chat-platform