Public challenge · 10 minutes

Break VeilType.

Do not trust a privacy claim because it sounds good. Run five concrete checks and send the first failure, confusing step, or compatibility issue.

Goal: verify whether VeilType can encrypt before the messenger receives plaintext while keeping the claim testable and honest.

5 checks

Run the proof, then try to break it.

1. Inspect permissions

Install the APK and confirm Android does not show an INTERNET permission request for the production keyboard.

2. Encrypt before chat

Type a short message in VeilType, press Encrypt, and send the encrypted output through Telegram, WhatsApp, SMS, email, or another app.

3. Open offline

On another Android device with the same key, enable airplane mode and open the encrypted message or capsule without a VeilType cloud account.

4. Tamper rejection

Copy the encrypted payload, change one character, and confirm that VeilType refuses to open the modified content.

5. Usability failure

Try a real workflow: long text, photo, video, file, or voice capsule. Report the first compatibility or UX problem instead of only saying whether it worked.

Honest limits

What this challenge does not prove.

No independent audit yetLimit

This is a public product test, not a formal crypto audit, certification, or pentest report.

Metadata still existsLimit

The messenger can still see that something was sent, when it was sent, and who participated.

Compromised device riskLimit

No Android keyboard can protect plaintext on a fully compromised device or stop screenshots after reveal.

Compatibility mattersLimit

Keyboard behavior varies by app, Android version, OEM skin, and messenger attachment rules.