Coming 2026 / 2027
Premiera 2026 / 2027

CesaConn — Ready. Set. Connect.

Your files. Your phone. Your computer. All talking to each other — privately.

Twoje pliki. Telefon. Komputer. Wszystko połączone — prywatnie.

CesaConn syncs everything between your devices. No cloud, no middleman, no snooping. Not even the FBI could read your data. That's not marketing — that's math.

CesaConn synchronizuje wszystko między Twoimi urządzeniami. Bez chmury, bez pośredników, bez podsłuchiwania. Nawet FBI nie może odczytać Twoich danych. To nie marketing — to matematyka.

0 Servers. Ever. Serwerów. Nigdy.
0 Data we store Danych o Tobie
0 People who can read your data Osób które czytają Twoje dane
Years to crack the encryption Lat na złamanie szyfrowania
What it does
Co robi

Like AirDrop.
But for everyone. And actually private.

Jak AirDrop.
Ale dla każdego. I naprawdę prywatny.

🔒

Nobody Can Read Your Stuff

Nikt Nie Może Czytać Twoich Danych

Not hackers. Not your ISP. Not us. Not the government. Your data is scrambled before it leaves your device — and only your other device can unscramble it.

Ani hakerzy. Ani operator. Ani my. Ani rząd. Twoje dane są szyfrowane zanim opuszczą urządzenie — i tylko Twoje drugie urządzenie może je rozszyfrować.

🖧

No Cloud. No Middleman.

Bez Chmury. Bez Pośredników.

Your files go directly phone → laptop. No passing through Google's, Apple's or anyone else's servers. There's simply nothing in the middle to hack.

Pliki idą bezpośrednio telefon → laptop. Bez przechodzenia przez serwery Google, Apple czy kogokolwiek innego. Po prostu nie ma nic pośrodku do zhakowania.

⚙️

You're in Charge

Ty Rządzisz

After every update, all features start turned off. Nothing changes without your permission. No surprises. No "we added this feature and forgot to ask".

Po każdej aktualizacji wszystkie funkcje startują wyłączone. Nic się nie zmienia bez Twojej zgody. Bez niespodzianek.

📋

Sync Everything

Synchronizuj Wszystko

Files, clipboard, notifications, SMS and more. Copy something on your phone — it's on your laptop instantly. Windows, Linux, Android.

Pliki, schowek, powiadomienia, SMS i więcej. Skopiuj coś na telefonie — pojawia się na laptopie natychmiast. Windows, Linux, Android.

🛡️

We Know Nothing About You

Nie Wiemy Nic O Tobie

No account. No email. No tracking. No "personalized experience" that's actually surveillance. We literally cannot tell you who our users are — because we don't know.

Bez konta. Bez emaila. Bez śledzenia. Dosłownie nie możemy powiedzieć kim są nasi użytkownicy — bo nie wiemy.

🔑

Prove It Yourself

Sprawdź Sam

The security code is public on GitHub. You don't have to trust us — you can verify every single line. That's the whole point.

Kod bezpieczeństwa jest publiczny na GitHubie. Nie musisz nam ufać — możesz sprawdzić każdą linię. O to właśnie chodzi.

Under the hood
Pod maską

Military-grade security.
Even the FBI can't read your data.

Bezpieczeństwo klasy wojskowej.
Nawet FBI nie odczyta Twoich danych.

That's not an exaggeration. CesaConn uses the same encryption standard approved by the NSA for top-secret communications. The math behind it means there is no known way to break it — with any computer on Earth, in any amount of time.

To nie przesada. CesaConn używa tego samego standardu szyfrowania zatwierdzonego przez NSA do komunikacji ściśle tajnej. Matematyka za tym stoi — nie ma znanych sposobów na złamanie, żadnym komputerem na Ziemi, w żadnym czasie.

🔐
The key never leaves your device
Klucz nigdy nie opuszcza urządzenia

Think of it like two people independently doing the same math problem and arriving at the same answer — without ever comparing notes. That answer becomes your encryption key. Nobody intercepts it because it's never sent.

Wyobraź sobie dwie osoby rozwiązujące ten sam problem matematyczny niezależnie i dochodzące do tego samego wyniku — bez porównywania notatek. Ten wynik staje się kluczem szyfrowania. Nikt go nie przechwytuje bo nigdy nie jest wysyłany.

X25519 ECDH — same as WireGuard & Signal
✍️
If anyone touches your data — it's rejected
Jeśli ktoś tknie Twoje dane — są odrzucone

Every piece of data gets a unique digital fingerprint before being sent. If even a single bit changes in transit — CesaConn knows and throws it away. No silent corruption. No silent tampering.

Każdy pakiet danych dostaje unikalny cyfrowy odcisk palca przed wysłaniem. Jeśli choć jeden bit się zmieni w drodze — CesaConn to wykrywa i odrzuca. Żadnej cichej modyfikacji.

Ed25519 digital signatures
🧠
Keys vanish from memory after use
Klucze znikają z pamięci po użyciu

After encrypting or decrypting, the keys are immediately overwritten in RAM. Even if someone grabbed your device mid-session and dumped the memory — there's nothing to find.

Po zaszyfrowaniu lub odszyfrowaniu klucze są natychmiast nadpisywane w RAM. Nawet gdyby ktoś zabrał urządzenie w trakcie sesji i zrzucił pamięć — nie ma nic do znalezienia.

Zeroize — RAM wiped after every operation
🤝
Devices verify each other — not a server
Urządzenia weryfikują się nawzajem — nie serwer

Before transferring anything, your devices prove their identity to each other directly. There's no certificate authority, no login server — nothing that can be hacked to impersonate you.

Przed transferem urządzenia udowadniają sobie nawzajem tożsamość bezpośrednio. Bez urzędu certyfikacji, bez serwera logowania — nic co można zhakować żeby podać się za Ciebie.

Mutual authentication — dual key system
Protection
Ochrona

Every attack.
Blocked.

Każdy atak.
Zablokowany.

Man-in-the-middleMan-in-the-middleBlocked
Packet tamperingModyfikacja pakietówBlocked
Replay attackAtak replayBlocked
EavesdroppingPodsłuchBlocked
Brute forceBrute forceBlocked
Key theft from RAMKradzież klucza z RAMBlocked
Auth key compromiseKradzież klucza authBlocked
Server breachAtak na serwerBlocked
Data interceptionPrzechwycenie danychBlocked
Our Algorithm
Nasz Algorytm

Post-quantum connection security.
Designed by Cezary Judka — CPQHA.

Post-kwantowe bezpieczeństwo połączeń.
Zaprojektowany przez Cezarego Judka — CPQHA.

CesaConn runs on CPQHA — a post-quantum hybrid authentication protocol designed by Cezary Judka, co-founder of CesaSec. It composes established primitives — SPAKE2, X25519, ML-KEM-1024, HKDF and Noise — into a cohesive pairing flow resistant even to future quantum computers. Click any step to see exactly what happens under the hood.

CesaConn działa na CPQHA — post-kwantowym protokole hybrydowego uwierzytelniania zaprojektowanym przez Cezarego Judka, współzałożyciela CesaSec. Składa sprawdzone prymitywy — SPAKE2, X25519, ML-KEM-1024, HKDF i Noise — w spójną procedurę parowania odporną nawet na przyszłe komputery kwantowe. Kliknij dowolny krok, żeby zobaczyć co dokładnie dzieje się pod maską.

CPQHA · Cesa Post-Quantum Hybrid Authentication

startstart secret generationgenerowanie sekretów handshake / sessionhandshake / sesja human verificationweryfikacja przez człowieka

PIN established

Ustanawianie PIN

Shown on device A, typed on device B

Wyświetlany na urządzeniu A, wpisywany na B

Device ADevice B
Generates a 6-digit PIN, displays itGeneruje 6-cyfrowy PIN, wyświetla go
User reads the PIN, types it inUżytkownik odczytuje PIN, wpisuje go

The PIN travels through a human, never over the network — so a network attacker never sees it.

PIN trafia przez człowieka, nigdy przez sieć — atakujący sieć nigdy go nie zobaczy.

SPAKE2 exchange

Wymiana SPAKE2

Protects the PIN from offline brute-force

Chroni PIN przed offline brute-force

Device ADevice B
start_a(pin) → message 1
 
 
start_b(pin) → message 2
finish() → spake2_secret
finish() → spake2_secret

An eavesdropper learns nothing. An active attacker gets exactly one guess at the PIN per attempt — easy to rate-limit.

Podsłuchujący nic się nie dowie. Aktywny napastnik dostaje dokładnie jedną próbę odgadnięcia PIN na połączenie — łatwe do rate-limitowania.

X25519 + ML-KEM-1024 ephemeral

X25519 + ML-KEM-1024 efemeryczne

Pubkey exchange — classical + post-quantum

Wymiana kluczy publicznych — klasyczna + post-kwantowa

Device ADevice B
Generates ephemeral X25519 + ML-KEM keypairGeneruje efemeryczną parę kluczy X25519 + ML-KEM
Generates ephemeral X25519 + ML-KEM keypairGeneruje efemeryczną parę kluczy X25519 + ML-KEM
Sends x25519_pub_A + mlkem_pub_A
Receives A's public keysOdbiera klucze publiczne A
Receives B's public keysOdbiera klucze publiczne B
Sends x25519_pub_B + mlkem_pub_B
DH(privA, pubB) → x25519_ss. Encapsulates to pubMLKEM_B → mlkem_ss
DH(privB, pubA) → x25519_ss. Decapsulates ciphertext → mlkem_ss

Public keys and the ML-KEM ciphertext are safe to send in the clear — that's what "public" means. Only the resulting shared secrets are sensitive.

Klucze publiczne i kryptogram ML-KEM można wysłać jawnie — to właśnie oznacza słowo „publiczny". Tylko wynikowe wspólne sekrety są wrażliwe.

HKDF + transcript hash

HKDF + hash transkryptu

Combines three secrets into one PSK

Łączy trzy sekrety w jeden PSK

Device ADevice B
spake2_ss + x25519_ss + mlkem_ss + hash(transcript)
spake2_ss + x25519_ss + mlkem_ss + hash(transcript)
HKDF-expand → 32-byte PSK
HKDF-expand → 32-byte PSK

If any message in transit was swapped by an attacker, the transcript hash differs on each side and everything downstream fails closed — no silent compromise.

Jeśli napastnik podmienił jakąkolwiek wiadomość, hash transkryptu różni się po obu stronach i wszystko kończy się błędem — żaden cichy atak nie przejdzie.

Noise XXpsk2 handshake

Handshake Noise XXpsk2

Mutual auth, AES-256-GCM transport

Wzajemne uwierzytelnianie, transport AES-256-GCM

Device ADevice B
→ e
 
 
← e, ee, s, es — PSK mixed in here
→ s, se
 
into_transport_mode()
into_transport_mode()

Both devices prove ownership of their static identity keys. From here, every message is encrypted and authenticated.

Oba urządzenia udowadniają posiadanie swoich statycznych kluczy tożsamości. Od tej chwili każda wiadomość jest szyfrowana i uwierzytelniana.

SAS comparison

Porównanie SAS

Only for an unrecognized device

Tylko dla nieznanego urządzenia

Device ADevice B
Computes 6-digit code from handshake hashOblicza 6-cyfrowy kod z hashu handshake
Computes 6-digit code from handshake hashOblicza 6-cyfrowy kod z hashu handshake
Shows: 482 916
Shows: 482 916

The user visually confirms the two codes match. A mismatch means someone tampered with the exchange — abort and re-pair.

Użytkownik wzrokowo potwierdza, że oba kody się zgadzają. Niezgodność oznacza ingerencję w wymianę — przerwij i sparuj ponownie.

Trusted peer + PQ ratchet

Zaufany peer + PQ ratchet

Key storage + per-session ML-KEM re-key

Zapis kluczy + ML-KEM re-key per sesja

Device ADevice B
Stores peer's static X25519 pubkey + PSKZapisuje statyczny pubkey X25519 peera + PSK
Stores peer's static X25519 pubkey + PSKZapisuje statyczny pubkey X25519 peera + PSK
On every reconnect — no PIN, no SAS Przy każdym reconnect — bez PIN, bez SAS
Noise_IKpsk2 → into_transport_mode()
Noise_IKpsk2 → into_transport_mode()
Gen ephemeral (pk, sk); sends pk inside AEADGeneruje efemeryczne (pk, sk); wysyła pk wewnątrz AEAD
Encapsulate(pk) → mlkem_ss + ctEncapsulate(pk) → mlkem_ss + ct
Decapsulate(ct, sk) → mlkem_ssDecapsulate(ct, sk) → mlkem_ss
sends ct inside AEADwysyła ct wewnątrz AEAD
HKDF(session_key ‖ mlkem_ss, info=pk ‖ ct) → re-keyed AEAD
HKDF(session_key ‖ mlkem_ss, info=pk ‖ ct) → re-keyed AEAD
Zeroizes ephemeral ML-KEM skZeruje efemeryczny sk ML-KEM
 

The ML-KEM exchange is a round-trip: A sends a fresh pubkey, B encapsulates and sends the ciphertext back, A decapsulates — only then do both sides have mlkem_ss. Binding pk and ct in the HKDF info label prevents reflection attacks. Zeroizing A's ephemeral sk after decapsulate is what makes PQ forward secrecy real — no future device compromise can recover this session's secret.

Wymiana ML-KEM to round-trip: A wysyła świeży pubkey, B enkapsuluje i odsyła ciphertext, A dekapsuluje — dopiero wtedy obie strony mają mlkem_ss. Związanie pk i ct w info HKDF zapobiega atakom reflection. Wyzerowanie efemerycznego sk A po dekapsulacji gwarantuje PQ forward secrecy — żadna późniejsza kompromitacja urządzenia nie odtworzy sekretu tej sesji.

Coming Soon
Już Wkrótce
2026/27