Chat Security, Privacy, and Administration

Team chat holds some of the most candid conversations in a company, so the questions people ask about it are exact: who can read my messages, what does the provider see, and what can an administrator do. This guide answers each one precisely. After this page you will be able to explain Backbuild Chat's protection to a colleague, a security reviewer, or an auditor, and set up who may do what.

How a Message Is Protected

After this section you will know what happens to a message between your keyboard and a colleague's screen.

  • Sealed on your device. Before a message leaves your device it is encrypted with that conversation's key, using hybrid post-quantum cryptography (classical and post-quantum key exchange together), and its integrity is bound to the conversation, the sender, and the message, so a message cannot be altered or moved to another conversation without the change being detected.
  • A key per device. Each device you use Chat on creates its own keys the first time, and keeps the private half on that device. When you sign in on a new device, it is given access to your conversations. When you leave the organization, you are removed from its conversations and their keys are replaced.
  • Keys change when members do. When someone leaves a conversation or is removed, the conversation's key is replaced, so they cannot open messages sent after they left.
  • An honest indicator. In a channel or a group conversation, the lock in the header turns green only when your device holds the keys and every loaded message opened and passed its integrity check; until then it stays grey, and if something is wrong it turns red and says what in its hover text. A one-to-one conversation does not show the lock. In every conversation, a message that fails its integrity check is hidden and marked This message could not be verified and is hidden, and a message whose key is not on your device yet says so in its place.

Who Can Open a Message, and What the Service Sees

After this section you will be able to answer the provider question precisely. Being exact matters here, because overstating protection does real harm.

  • The members' devices can open the conversation's messages.
  • Your organization's chat key can open them too. Backbuild holds this key, one per organization, and uses it on the server to check the mentions in a message and to build a search index for it. Every use of the organization's chat key is recorded.
  • The search index. The message itself is stored only encrypted. The search index built from it holds the message's words, in a normalized form, readable by the service, and a short preview of the message is stored encrypted under a separate key the service holds. Searching message text is not in the app yet.
  • Metadata the service can read: channel names, topics, and descriptions; who is a member of what; who sent a message and when; who was mentioned; reactions; delivered and read markers; and the names, types, and sizes of attached files. The service needs these to route, list, and authorize your conversations.

So Backbuild Chat is end-to-end encrypted between devices, and it is not zero-access: the service can open messages with your organization's key. Zero-knowledge conversations, which would remove that ability at the cost of search and previews, appear as an option when you create a channel but cannot be created yet.

What Chat Encryption Does Not Cover

  • Attached files are stored in Backbuild Files and protected there, encrypted at rest under Files' own access controls, not with the conversation's key. A conversation reaches a file only through its chip, and every open is checked against the current members.
  • Virtual worker sessions are AI conversations, stored with your organization's AI sessions, not Chat conversations, and carry no Chat encryption.

Permissions and Roles

After this section you will set up who may do what. Chat uses the same roles and permissions as the rest of the workspace. These are the Chat permissions and the built-in roles that include them; a custom role can include any of them that you hold yourself:

  • Use Chat: open Chat and take part in conversations you are a member of. Every built-in role.
  • Create Chat Channels: create public and private channels. Member, Developer, Manager, Admin, and Owner.
  • Manage Chat Channels: govern channels across the organization: rename, archive, set who may post, make private, and manage members and roles, without reading a private channel's messages. Manager, Admin, and Owner.
  • Chat @everyone: use @everyone in the general channel. Admin and Owner.
  • Administer Chat: everything Manage Chat Channels allows, plus deleting another person's message, or withdrawing a file from it, in a conversation they are a member of. Admin and Owner.
  • Export Chat: Admin and Owner. The app has no conversation export yet.

Inside a channel, the channel's own roles (owner, manager, member) decide who edits it, as described in Channels, Conversations, and People.

What an Administrator Can and Cannot Do

  • Can govern channels: rename, archive, change who may post, make a channel private, and manage the members of public channels.
  • Cannot read a private channel or a direct conversation they are not a member of, and cannot add people to a private channel they do not belong to, because a new member sees the channel's history.
  • Cannot post as another person or edit another person's messages.
  • Can, with Administer Chat, delete another person's message, or withdraw a file from it, in a conversation they are a member of, through the Chat API while signed in. The app itself offers Delete and Remove access only to the message's sender. A deleted message leaves This message was deleted in its place, and the deletion is recorded in the audit trail.

The app does not offer an export of conversations or retention settings for Chat yet.

The Audit Trail

Sending, editing, and deleting messages, membership and role changes, channel changes, settings changes, and every use of the organization's chat key are recorded in the workspace's append-only audit trail, attributed to the person who acted. The audit trail records who did what and when, never the content of a message.

Frequently Asked Questions

Can my administrator read my direct messages? Not in the app. No administrator screen shows the messages of a conversation they are not in, and governing channels never gives read access. The service itself can open messages with your organization's chat key, for indexing and mention checks, and each such use is recorded.

What happens when I get a new laptop? Sign in and open Chat. The new device creates its keys and is given access to your conversations; nothing is copied by hand.

Is Backbuild Chat end-to-end encrypted like a consumer messenger? Messages are encrypted on the sender's device and opened on the members' devices, as in a consumer messenger, and in addition your organization's chat key, held by Backbuild, can open them. If you need a provider that cannot read messages at all, know that zero-knowledge conversations are not available yet.