Postern Labs
MAINNET BETA. Unaudited · SHA-256d proof-of-work (standard Bitcoin-style hashcash — not a security claim) · very few nodes, low hashrate, 51%-attackable · not a security · for evaluation — not to protect real secrets yet. Full disclaimer →

Postern Labs · watch

Post-quantum privacy, proven in the open.

A secrets vault, an encrypted file drop, a wallet, and a reproducible OS — post-quantum protection you can build from source and verify yourself, on an ownerless commons no future authority can revoke.

Math, applied. For life.

⛏️ Bloch has migrated to SHA-256d proof-of-work — Genesis-2 is live. The old chain could not sync from genesis: ~95% of block bodies were pruned everywhere and are unrecoverable. Genesis-2 is a new chain that carried every balance over, bound to a published snapshot commitment — coins are not affected, and signatures stay ML-DSA-65 ‖ Falcon-1024, so post-quantum protection of your keys is unchanged.
Said plainly: a small SHA-256 chain is cheap to attack with rented hashrate, and the current chain is not exposed that way. There is no finality gadget coming to fix this — a candidate FFG-BFT committee overlay was evaluated and dropped; the base is pure PoW, finality is confirmation depth, and validity is checked deterministically by every node. The window until real hashrate accumulates is not covered, and that is an open question, not a solved one.  →  Read the full status →
📱 Postern is live on mobile. The full app in your phone's browser — wallet (real post-quantum keygen & signing in WASM), node status, vault, encrypted backup and more. Add it to your home screen, no store. Unaudited beta, software keystore, zero-value.  →  Open Postern →
🛰️ Running a node? Genesis-2 (SHA-256d) is live — here is the current setup. Build from source (cargo build --release), download the required carry-over snapshot (it seeds the 413,743-UTXO set on first start), then peer with the live archival nodes. Your node runs an initial sync and converges to the canonical chain — GhostDAG always follows the heaviest valid chain, so every node and every miner ends up on the same tip, and miners produce on that tip once caught up. Point your node at the archival peer 51.83.249.212 or it can stall waiting for pruned history.  →  Run a node — full step-by-step setup →
Older guides that mention a Module-SIS / k-ramp gate or a downloadable database snapshot describe the retired chain — the live network is Genesis-2 (SHA-256d), and Run a node is the authoritative, up-to-date instructions.

Postern Labs · public beta

🆕 Release · Bloch node v0.1.0-alpha3 — finality fix + ASERT re-anchor →

Running a node? v0.1.0-alpha3 fixes two consensus bugs exposed once block production un-choked: a finality checkpoint unit fix (nodes were freezing on ingest — they converge again) and a height-switched ASERT re-anchor so difficulty can track real hashrate instead of being capped at 4× genesis forever. Both are backward-safe (historical blocks validate byte-for-byte — no fork); the live chain runs SHA-256d proof-of-work. See the release →

Privacy & security products, sold the honest way.

Postern Labs builds owned, rebranded privacy and security products — a secrets vault, post-quantum file drop, a messenger, passkeys, metadata scrub, a panic lock, a wallet, voice tools, an app store, and a reproducible OS — on top of an ownerless, post-quantum protocol it does not own. You pay Postern for protection, support, and provable integrity — never for a coin.

Run a node · a Ulysses contract for the digital age

Run a node. Uphold the commitment.

Mine the ownerless, post-quantum base from Postern Desktop — not to profit, but to uphold a pre-commitment to privacy and security as fundamental rights. Like a people binding itself through a constitution, the ownerless, permissionless base is a self-binding commitment device — a technological Ulysses contract in Jon Elster's sense — that no future authority, and not even the founder, can revoke. From the people, for the peopleWe, the People.

Step-by-step, narrated — open Run a node, point at the bloch binary, tick Mine, Start, watch blocks seal, Stop. Participation, not a purchase: this is a zero-value, pre-mainnet testnet; mining yields no sellable reward. BLCH is worthless by design and is not a security. Honest limit: the desktop node mines and serves RPC locally, but cannot yet fully sync or produce blocks on the live mainnet (whose PoW is standard SHA-256d) — local / testnet / reference mining. Reference prototype, unaudited. The walkthrough is captured in the labeled browser preview (simulated node). Read “We, the People” →

Run a node · overview video

Set up a Bloch node in about three minutes.

Set up a Bloch node in ~3 min · narrated · English captions. Honest note: the video predates Genesis-2 and shows the retired old-chain snapshot flow — treat it as an older overview only. The written steps on Run a node are authoritative for the current Genesis-2 setup. Unaudited research chain; the coin has no value.

When mathematics and language communicate to foster privacy.

Why Postern

A protocol tied to the mast.

Freedom, property, privacy — why Postern was built, drawn from the founder's essay on pre-commitment (Ulysses at the mast), Locke on property, and privacy as a constitutional penumbra. English narration (unmute) + captions. * The Bloch protocol is ownerless — no owner, no board. Postern Labs is a company, and has an owner. It is a vision piece, not a claim — everything remains pre-mainnet and unaudited.

The part most launch pages hide

This is a beta launch, and we say exactly what that means.

Honest status — read before anything else

  • Everything here is pre-production. The Rust product cores are built and test-verified. The OS images have started to exist: the x86_64 node and desktop ISOs are built, hosted, and release-signed — the node ISO now QEMU/TCG-boots to a login prompt (boot log recorded, grader rc=0); the desktop ISO's QEMU boot is still pending, and a physical-hardware boot is further out; the mobile image (aarch64, PinePhone / Mobile NixOS) is now built, hosted, and release-signed, but not yet boot-tested on any platform — it has not been booted on QEMU aarch64 or on hardware, so it is the least-proven of the three. The UIs and cloud/enterprise editions remain designs and reference prototypes. Hosting a signed image is not attestation, and built is not booted — we don't claim otherwise. Each item is labelled with its exact status wherever it appears.
  • The underlying protocol now runs a mainnet beta — a designation, not a security claim. The live chain runs standard SHA-256d proof-of-work — double SHA-256, Bitcoin-style hashcash, with a little-endian target-compare hard fork at height 2400. The PoW is a standard work function, not a security claim, and no security is claimed. Real security is cumulative SHA-256d work — hashrate × time. A brand-new node can sync from genesis, or use the signed snapshot as an optional one-command fast-sync. The network is nascent: very few nodes, low hashrate → 51%-attackable. It is unaudited — a third-party audit is contracted but not done yet, and the concrete-security analysis and IACR ePrint are still outstanding.
  • The coin is not a security and not an asset. No token sale, no listing effort, no market-making, no price. Disclosed in full: a 17% founder premine (10-year cliff, 40-year vest), structurally passive.
  • Do not use any of this to protect real secrets yet. It is a public beta for evaluation, feedback, and reproduction of our claims.

Every claim on this site is audit-gated: if a thing isn't true yet, we phrase it as the plan. The full text lives on the disclaimer page.

The model

Owned products ⟂ ownerless protocol.

Think Bitcoin and the businesses built around it. The base protocol — Bloch-SIS-PoW, a post-quantum, pure-PoW BlockDAG — is a neutral commons: no owner, no foundation, no official site, no token sale. It is software plus a documented RPC/API surface, and nothing more. Anyone runs it; anyone builds on it.

Postern Labs is one builder among many on that neutral base — a company, with products it owns and a name deliberately rebranded away from “Bloch”. It sells the BlackBerry thing: protection, support, and integrity you can verify, on permissive Linux.

Postern Labs — owned products, rebranded

Vault · Courier · Messenger · Keys · Hygiene · Panic Lock · Seal Companion · Wallet · Postern OS · the apps — permissively licensed, sold for the protection.

│ consumes the protocol via its public RPC / API — nothing privileged │
Bloch-SIS-PoW — ownerless protocol

SHA-256d proof-of-work · Falcon‖ML-DSA · GhostDAG-Q · the coin. No owner, no curator, no official site or explorer. Just the protocol.

This distinction matters enough that it has its own page.

The suite

A tour of what's in the workshop.

The Rust cores below are built and test-verified; the front-ends are reference prototypes; everything is unaudited. Honest labels on every card — the full catalog is on the products page.

Postern Vault

A secrets / password vault, sealed at rest with the one canonical seal (XChaCha20-Poly1305 + Argon2id).

core: built · tests pass unaudited

Postern Courier

Serverless person-to-person file drop: ML-KEM-1024 payload seal over an ephemeral Tor onion service.

core: built · tests pass unaudited

Vestnik

The messenger — Slavic вестник, ‘herald’ (renamed from ‘Messenger’ to steer clear of Meta's mark). The Megolm E2EE core (via vodozemac, Apache-2.0) now drives a real, offline-testable Matrix client — login/sync/room-tier/tier-gated send with PQ-sealable saved-session custody — behind a desktop pane. Live homeserver contact is user-action-only, never in CI; Megolm is classical (not PQ) and the homeserver sees the social graph.

core: built · tests pass unaudited

Panic Lock

A panic button that instantly re-locks and destroys nothing.

core: built · tests pass unaudited

Postern Keys

A passkey / FIDO2 credential core for the permissive-license world.

core: built · tests pass unaudited

Postern Hygiene

Scrubs the document metadata nobody fixes — OOXML, ODF, JPEG.

core: built · tests pass unaudited

Postern Svitok — encrypted office suite (in design)

An encrypted office suite (свиток, ‘scroll’) — deliberately not named after the Word/Excel/PowerPoint/Office marks; ‘office’ is used only as a plain descriptor. It gives .docx / .pptx / .xlsx-compatible editing by aggregating unmodified LibreOffice (MPL — never forked) under a Postern shell: documents are sealed at rest by default with the one canonical seal (postern-core), scrubbed on export (Hygiene) and sanitized on import (Quarantine). In design / scaffold: the seal-at-rest + panic-evict session core is started and tested; the LibreOffice-aggregate editor is planned. Honest limit — an inherent, non-zero plaintext-while-editing window (minimized via secured scratch / no-swap / secure-delete / Panic-Lock eviction; never claimed zero). Name pending trademark clearance.

design / spec name proposed · pending trademark clearance unaudited

Seal Companion

The attestation verifier: self-audit and peer-verify, so you check our claims instead of trusting them. It now validates a genuine AWS SEV-SNP attestation report end-to-end (VLEK→ASVK→ARK chain to AMD's pinned root, nonce-bound) against real AMD Milan silicon — an unaudited reference verifier; verified-against-real-hardware is not audited/production.

core: built · tests pass unaudited

Postern Wallet

Post-quantum hybrid wallet (Falcon‖ML-DSA), diversified addresses, on-device key vault — on the unaudited, 51%-attackable mainnet beta; the coins carry no value claim.

core: built · tests pass reference prototype unaudited

Porog — Android container

The door between two worlds (a proposed name, pending trademark clearance; the porog / threshold of the Izbushka tale): a hardened, self-enrolled managed-profile workspace on stock Android — StrongBox key-attestation skeleton + the shared managed-profile DPC. A scaffold, not shipping; key-attested device, not measured-boot workspace; hardened, not anonymous; a rooted host defeats it. Never “Postern OS”.

design / spec reference prototype unaudited

NoporIS — the bridge

The bridge between two worlds (the Kalinov crossing): a dual-persona layer that joins your personal side and a second, Google-Play-enabled persona on one device. The Google side is honestly the less-private side (it phones home to Google) — NoporIS sells separation, not privacy, and respects Google/Android licenses (no GMS redistribution, no Play-Integrity circumvention). A concept scaffold; name pending trademark clearance.

design / spec unaudited

For the deep read, engineers and auditors can pull the Technical Whitepaper (PDF) ↓ and the Audit-Readiness Dossier (PDF) ↓ — code-derived, every UNAUDITED / not-booted marker intact. Neither is an audit.

Roadmap · designed, not shipping

Next: Kalinov Bridge — private, post-quantum backups for your Postern OS files.

Kalinov Bridge — Postern backups on Filecoin design / spec unaudited

Bloch-SIS-PoW + Postern Labs + Filecoin — privacy and post-quantum security for your Postern OS files. The plan: private user backups stored on Filecoin, but sealed client-side with the Postern seal (XChaCha20-Poly1305) before anything leaves the sealed base — Filecoin only ever sees ciphertext, and the keys never leave your device. Post-quantum integrity and authenticity come from Bloch cryptography: a SHAKE-256 manifest signed with ML-DSA-65 ‖ Falcon, anchored to the ownerless Bloch base as an ordinary zero-value on-chain commitment (“DATA0”).

Honest status: the full Kalinov Bridge — the ML-DSA-65 ‖ Falcon-signed SHAKE-256 manifest anchored to the base — is still roadmap / planned. What exists today is a first slice of the path as an unaudited reference prototype: the Encrypted Backup pane in Postern Desktop seals a file locally, writes the SHAKE-256 “DATA0” integrity anchor, and does a real upload of the sealed ciphertext to Filecoin (real CID; only ciphertext leaves the device). That is a prototype, not audited and not production — don't entrust a real backup to it yet. Newer: the ML-DSA-65 ‖ Falcon-1024 signer over the SHAKE-256 manifest is now implemented and tested at the crate level (postern-backup-net — an end-to-end test seals, hashes, packages, signs, spools and restores a backup, independently verifies both signature halves, and rejects a single tampered byte), still unaudited; the on-chain DATA0 broadcast and the desktop-pane wiring on top of that signer are not shipped yet. Designed ≠ built ≠ booted. It touches the ownerless base only as an ordinary zero-value transaction; BLCH is not a security and Postern's revenue never touches the token. Tracked on the Postern products roadmap ↓.

About · the founder

Tiago Tenório (“TT”) — Founder & CEO.

Tiago Tenório (TT) is the founder and CEO of Postern Labs. He comes from Brazil's payments and fintech sector — a Visa prepaid/third-party ISO agent (2018–2020); founder of the AG47 office and a member of C6 Bank's Conexão C6 program, operating across São Paulo, Goiás, the Federal District, Alagoas and Paraná (2020–2021); a national distribution partner in First Data Corporation's Ignite program for acquiring products and services (2020–2021); PMO lead on a cards project at Havan (2021–2022); and Commercial Director at Avalon Capital, an asset manager (2022). In 2026 he founded Postern Labs to build privacy-first, post-quantum software — and the ownerless Bloch-SIS-PoW protocol its products build on, in which he holds no privileged role beyond a fully disclosed, structurally passive 17% founder premine.

The companies named above state his prior roles only — none of them endorses, backs, funds, or is affiliated with Postern Labs or Bloch-SIS-PoW.

Tiago B. de A. Tenório on LinkedIn — an outbound link; this site still loads nothing external and makes no network requests of its own.

Standing commitments

What we will never do.

  • Never sell you the coin. No token sale, no listing effort, no “ecosystem fund”, no yield marketing. Postern's revenue story never touches the token.
  • Never overclaim to the people who'd pay for it with their safety. No product here says “100% private”; every app carries an honest privacy panel.
  • Never embed copyleft, never close the source. MIT / Apache-2.0; the free build is always buildable from source.
  • Never ship a security claim before its audit. Claims for the protocol and for the products are separate, and each is audit-gated.
  • No covert surveillance, no tracking — including this website, which makes zero network calls.