Skip to content
helloinfotech
CapabilitiesWorkApproachInsightsAboutStart a project

In-house product

NorthStar — end-to-end encrypted conferencing for regulated organisations

Browser-based video conferencing where the server never holds the keys — built for organisations whose legal and compliance teams need a better answer than "trust the vendor".

Period
2026
Role
Product ownership, security architecture, platform engineering
Disciplines
SoftwarePlatformNetworking
Ownership
Built and owned by Hello Infotech

In-house product. This is a product we are building and own, not a delivered client engagement. Where something is designed but not yet proven, this page says so rather than leaving you to find out in a demo. Status: Pilot with design partners. Two-party encrypted calling verified end to end, including screen share; multi-party is in active development and is not yet verified as secure.

The problem it addresses

Most enterprise video platforms are encrypted in transit and at rest, which sounds comprehensive until someone asks the question that actually matters: can the vendor decrypt the meeting? For the majority of platforms, the honest answer is yes — and for organisations in defence, healthcare, legal and finance, that answer is increasingly one they have to justify to a regulator rather than to a procurement team.

NorthStar starts from the opposite default. Media is encrypted by the participants, and the infrastructure that routes it is not in a position to read it. When the legal team asks what happens if the platform receives a subpoena, the answer is a property of the architecture rather than a promise in a contract.

What makes it different

  • The server routes; it does not decrypt. Confidentiality is a structural property, not a policy. Removing the vendor from the trust equation is the entire point of the product.
  • It runs in a browser. No client to deploy, no agent to get approved, no mobile device management programme. For an organisation that needs to bring outside counsel or an external auditor into a call, that difference decides whether a secure platform is used at all.
  • Built on open, published standards. The cryptographic foundations are public IETF work rather than a proprietary scheme, which means the design can be reviewed by someone who does not work for us. We are also contributing back to the standards process in this area.
  • Designed for the compliance conversation. The awkward questions — who can access what, under which circumstances, and how would anyone know — are treated as first-class design inputs rather than as documentation written after the architecture is frozen.

Where it actually stands

NorthStar is a pilot, in front of design partners. It is not an enterprise-grade product yet, and we would rather say so here than have a prospect discover it.

Verified today: encrypted two-party calling between browsers on desktop and mobile, with screen sharing encrypted on the same terms as camera and microphone, running on a containerised, TLS-terminated deployment with an operator runbook behind it.

Not yet verified: multi-party calling. Group sessions work as an interface, but the group key handling is not yet proven correct for participants joining and leaving mid-call, so we do not present multi-party as secure and are not asking anyone to rely on it. It is the current engineering priority. Longer-dated work — hardware-isolated infrastructure and the full compliance surface — is planned and scoped rather than delivered.

We are engaging a small number of design partners in regulated sectors who want to shape the product against their own compliance obligations. If that is you, the conversation is a genuine one, not a disguised sales call.

Talk to us about

Secure real-time communications, applied cryptography in production systems, privacy-preserving architecture, or building a platform that has to satisfy a regulator rather than merely a security questionnaire.


More work

Start here

Have a system that has to work?

Bring the hard part. Architecture reviews, greenfield builds, firmware bring-up, network design, or a platform that needs to stop paging you at 3am — start with a conversation, not a contract.

Typical reply within one business day · IST (UTC+5:30)