Skip to content
helloinfotech
CapabilitiesWorkApproachInsightsAboutStart a project

In-house product

NorthStar — end-to-end encrypted conferencing for regulated organisations

Browser-based video conferencing where the media server never holds the keys — built for organisations whose legal team needs a better answer than "trust the vendor".

Period
2026
Role
Product ownership, security architecture, platform engineering
Disciplines
SoftwarePlatformNetworking
Ownership
Built and owned by Hello Infotech

In-house product. This is a product we are building and own, not a delivered client engagement. Where something is designed but not yet proven, this page says so rather than leaving you to find out in a demo. Status: In pilot with design partners. End-to-end encrypted two-party calling and screen share, verified across desktop and mobile browsers. Multi-party is in development and ships as secure only when its cryptography is verified.

The problem it addresses

Most enterprise video platforms are encrypted in transit and at rest, which sounds comprehensive until someone asks the question that actually matters: can the vendor decrypt the meeting? For most platforms the honest answer is yes — and for organisations in defence, healthcare, legal and finance, that answer is increasingly something they must justify to a regulator rather than to a procurement team.

NorthStar starts from the opposite default. Media is encrypted by the participants, and the infrastructure routing it is not in a position to read it. When the legal team asks what happens if the platform receives a subpoena, the answer is a property of the architecture rather than a promise in a contract.

How it works

The group key agreement is MLS — RFC 9420, the IETF standard now underneath E2EE at Discord, Wire and Webex. The MLS state machine is OpenMLS, compiled to WebAssembly and executed inside the browser.

Every participant performs MLS key exchange over an authenticated relay. The group’s epoch secret is exported to key AES-GCM encryption of every video, audio and screen-share frame before it leaves the browser. The media server routes ciphertext it cannot decrypt, and when membership changes the epoch advances and the media plane re-keys.

Three consequences a security team will care about:

  • The server holds no media keys. Compromising the infrastructure does not yield the meeting.
  • It runs in a browser. No client to deploy, no agent to get approved, no MDM programme. For an organisation that needs to bring outside counsel or an external auditor into a call, that is often the difference between a secure platform being used and being bypassed.
  • The cryptography is public and reviewable. MLS is a published IETF standard with independent implementations, not a proprietary scheme you must take on faith. The design can be assessed by someone who does not work for us.
Where the keys live in a NorthStar callTwo participant browsers each hold the encryption keys. Between them sits the media server, which relays encrypted media and holds no keys.Participantbrowser — no installholds the keysParticipantbrowser — no installholds the keysMedia serverroutes the callholds no keysencryptedencrypted— outside the trust boundary —audio · video · screenreadable hereaudio · video · screenreadable hereciphertext onlynot readable here
FIG 01Where the keys live. Participants encrypt and decrypt; the server between them relays media it cannot read.

What has been verified

Two-party calling is verified end to end: encrypted audio, video and screen share between browsers on desktop and Android, on a self-hosted SFU with TLS termination and an operator runbook behind it. Screen share is encrypted on exactly the same terms as camera and microphone. Re-keying on membership change is verified to actually re-key the media plane.

We put the system through structured adversarial review — separate security and cryptography passes — and remediated and documented every critical and high finding individually. One was a genuine re-keying defect the review caught; it is now covered by test.

Multi-party is the current engineering priority. Group sessions run today and are moving through the same verification the two-party path has already passed. We present a session as secure only once that verification is complete — that bar is the product, and holding it is the reason to trust the rest.

Where it stands

NorthStar is in pilot with design partners. No claims of production-readiness, no external audit yet, no compliance certification. Confidential-computing infrastructure and the wider compliance surface are designed and scoped rather than delivered.

We are engaging a small number of design partners in regulated sectors who want to shape the platform against their own obligations, and who value a vendor that distinguishes between what is built and what is planned.

Talk to us about

Secure real-time communications, applied cryptography in production systems, privacy-preserving architecture, or building a platform that has to satisfy a regulator rather than merely a security questionnaire.


More work

Start here

Have a system that has to work?

Bring the hard part. Architecture reviews, greenfield builds, firmware bring-up, network design, or a platform that has stopped being predictable — start with a conversation, not a contract.

Typical reply within one business day · IST (UTC+5:30)