Back to Case Studies
Security & Web Apps
5 min read
Client: Whatshush

Zero-Knowledge Encrypted Messaging: The Whatshush Privacy Web App

Client-side AES-256-GCM encryption with self-destructing secret notes.

100% Client-side cryptography using native Web Crypto API
Zero plaintext stored or transmitted to server logs
Automatic burn-on-read link expiration

1. The Engineering Challenge

Sharing sensitive API keys, passwords, and tokens via standard chat apps creates security vulnerabilities. Whatshush needed a simple web app where messages self-destruct after being read once.

2. Architectural Solution

We engineered Whatshush using client-side Web Crypto API. Encryption keys never leave the browser hash fragment, ensuring even the hosting server cannot read the payload.

Key Technical Architecture Highlights

  • Client-side AES-256-GCM encryption and decryption
  • Zero-knowledge backend storage storing only encrypted ciphertext blobs
  • Atomic read-and-delete database operations

3. Business Impact & Results

Whatshush provides developers and privacy-conscious teams with a safe way to exchange confidential credentials without creating permanent logs.

Technologies Used in this Architecture
ReactNext.jsWeb Crypto APITailwind CSSVercel Edge
HAVE A COMPLEX TECHNOLOGY PROBLEM?

Talk directly with an architect.

Bring us your product, platform, infrastructure, or AI challenge. We'll help you understand the technical path forward — what needs to change, what can stay, and what it will take to build it properly.

Direct communication with senior engineers Mutual NDA available Technical proposal available for qualified projects