Privacy should be owned, not implied.
Today privacy is a promise someone else makes about data you cannot reach. A policy. A provider. A jurisdiction. Every one of them survives being wrong.
Owned privacy is a key you hold. Without it the data does not open — not for the platform, not for an interceptor, not for us.
Data is sealed by two keys and opens only for the pair it was meant for. The publishable half is re-derived on every request, so an intercepted key is already dead.
Two keys. Re-derived every request.
Both parties contribute to the key that seals a transaction. Neither half opens it alone, and the publishable half never repeats.
Both sides contribute key material. Neither holds a value that opens the exchange alone.
A key is derived for this transaction only.
The payload is sealed to the recipient. In transit it is opaque to everyone else, operator included.
The key just used is retired. It cannot reconstruct the next one or the last one.
An authenticated key exchange with a per-message ratchet — not a rotating code from a fixed seed. A rotating code collapses when its seed leaks; a ratchet does not expose the messages before or after a compromised key. Construction specified in RAN-01.
Anonymous governance.
Token votes are public. Holders self-censor, and a large position that reveals intent early has published a trade.
A sealed ballot opens only into the tally. Verifiable in full, attributable to no one — including by us.
What we do not claim.
RAN is a specification. No verifier is live and no verification has been performed.
Encryption conceals contents, not the fact that two addresses spoke. Protecting the IP layer needs relaying, and it is not built.
A group of forty gives one-in-forty. No engineering changes that number, so the size is published in the interface.