Security
Your audio never leaves the room.
This page explains how Muxvox is put together, what our servers can and cannot see, and which promises are enforced by architecture rather than by policy.
Where the audio goes
Two locks on every microphone
A phone contributes audio only after passing two independent checks. First, the connection itself: audio travels over DTLS (the encryption used by WebRTC calls), and the handshake only completes if the phone holds the room's pairing key. Second, the operator: even with the right key, a new phone waits until someone at the Mac approves it — and until then, anything it sends is discarded. Neither check can substitute for the other, and both are covered by automated tests that try to break them.
What our servers see
Muxvox has exactly one server-side system: licensing. When a desktop on a paid plan checks its subscription, it sends a random installation identifier and its license — nothing else. The licensing service never receives audio, microphone data, meeting contents, participant names, the names of your devices' owners, or your network layout. Phones never talk to our servers at all, and the free Personal plan works without ever contacting them.
If our servers go down — or your internet does — meetings continue unaffected: subscription state is cached on the Mac with at least a week of grace, and the check never runs in the audio path.
What ships inside the apps
No secrets. The desktop embeds two public verification keys used to check the signature on subscription documents; a public key lets you verify, not forge. There are no API secrets, no tokens, and no credentials in any app binary.
No accounts, by design
Nobody creates an account to use Muxvox. Paid plans use a license key; the only personal data our billing system holds is the purchase email, processed by Stripe. Details in the privacy policy.
Responsible disclosure
Found something? Mail hello@muxvox.io with “security” in the subject and it lands directly with the person who wrote the code. We'll respond quickly, credit you if you want, and never take legal aim at good-faith research.
The full engineering threat model lives in the product repository and is summarized honestly here — including the limits: licensing enforcement is a commercial control on the paying Mac, not a security boundary, and is kept deliberately separate from the audio trust chain.