- Signal is our strongest general recommendation for private personal messaging. Messages, calls, groups and profiles are protected with end-to-end encryption by default.
- Signal minimizes server-side data and has repeatedly shown that legal requests can produce very little account information.
- It still requires a phone number for registration. Usernames reduce how often you need to share that number, but they do not create an anonymous account.
- Optional Secure Backups now provide end-to-end encrypted recovery, but losing the recovery key means losing access to the archive.
- Signal cannot protect a compromised or unlocked device, careless screenshots, phishing, or someone you deliberately send information to.
Signal combines excellent privacy defaults, mature cryptography and a nonprofit business model. It is not perfect, but it asks users to make fewer dangerous security decisions than most competing messengers.
What is Signal?
Signal is a free messaging and calling application operated by the nonprofit Signal Technology Foundation. It is available for Android and iPhone, with linked applications for desktop platforms and additional secondary devices. Its defining feature is not simply that encryption exists, but that end-to-end encryption is the normal mode for personal messages, group conversations, voice calls and video calls.
End-to-end encryption means a message is encrypted on the sender’s device and is intended to be decrypted only on the recipient’s devices. Signal’s servers help deliver the encrypted data, but they are not designed to hold the keys needed to read ordinary conversation content.
Download the official app, read Signal’s documentation or learn about the nonprofit organization.
Visit Signal →Signal supports one-to-one chats, groups of up to 1,000 members, disappearing messages, voice and video calls, stories, message requests, usernames and multi-device access. The feature set is now broad enough for ordinary family and social use, although it remains less focused on public channels, huge communities and bots than Telegram.
Signal’s privacy model: collect less, not merely promise more
Many communication services rely mainly on policy: the provider possesses extensive data but promises to handle it responsibly. Signal’s approach is more structural. It tries to avoid receiving readable message content and to reduce the amount of social and account metadata available to its infrastructure.
This distinction matters. A privacy policy can change, an employee account can be compromised and a valid legal order can force a company to disclose data it holds. Data that was never collected in readable form is much harder to leak, misuse or hand over.
Signal’s published government-request records provide a useful real-world test. In a 2026 disclosure concerning 37 phone numbers, the requested information was limited to account creation time and last connection time. Signal states that it could not provide messages, calls, contacts, groups, profiles or call logs because it did not possess them in a readable form. That does not mean Signal knows literally nothing, but it demonstrates unusually aggressive data minimization.
How Signal encryption works
The Signal Protocol is not one single cipher. It is a collection of mechanisms for establishing encrypted sessions, changing encryption keys over time, handling offline delivery and supporting multiple devices. The public technical specifications are detailed, but the practical goals can be explained without advanced mathematics.
End-to-end encryption by default
Users do not need to enable a “secret chat.” Signal applies end-to-end encryption automatically. This removes a major source of human error: people cannot accidentally place a sensitive conversation into a weaker default mode simply because they misunderstood an icon or setting.
Double Ratchet, in plain English
The Double Ratchet derives fresh encryption keys as a conversation progresses. A useful mental model is a lock that continually changes after use. Compromising one current key should not automatically unlock the entire past conversation, and later key changes can help recover protection after a temporary compromise ends.
These properties are commonly described as forward secrecy and post-compromise security. Forward secrecy limits how much past communication can be exposed if a current key is stolen. Post-compromise security aims to protect future messages again after the attacker loses access and the session advances.
PQXDH and SPQR: preparing for quantum computing
Signal introduced PQXDH to add post-quantum material when a secure session is established. The aim is to reduce “harvest now, decrypt later” risk, where an attacker records encrypted traffic today in the hope that a future quantum computer can break part of the cryptography.
In 2025 Signal announced the Sparse Post Quantum Ratchet, or SPQR. It is combined with the existing Double Ratchet in what Signal calls a Triple Ratchet. The important point for normal users is simple: the protocol can regularly advance post-quantum secrets during an ongoing conversation rather than using post-quantum protection only at session setup. Signal said the rollout would happen without users needing to change how they use the app.
Post-quantum does not mean “guaranteed safe forever.” It means the design is being strengthened against a class of future attacks before cryptographically relevant quantum computers are known to exist.
Metadata and Sealed Sender
Message content is only part of communication privacy. Metadata can include who contacted whom, when communication occurred, which groups exist, a user’s IP address and which devices are active. Metadata can reveal relationships and patterns even when the words themselves remain encrypted.
Signal uses several privacy-preserving systems, including private groups, private contact discovery and Sealed Sender, to reduce readable metadata. Sealed Sender is designed to make it harder for the service to learn the sender of a delivered message while still performing abuse controls and delivery.
This should not be exaggerated into total anonymity. Signal’s servers must still receive network connections, deliver queued data and defend the service from spam. Network observers, a compromised device, push-notification infrastructure or the other person in a conversation may reveal information that Signal itself tries not to retain.
Signal is a private messenger, not an anonymity network. It does not hide your IP address from every observer in the way Tor is designed to, and it cannot make a known phone number cease to be associated with you outside the app.
Phone numbers and usernames
A phone number is still required to register a Signal account. This helps account discovery and limits some forms of automated abuse, but it is also Signal’s most obvious privacy compromise. Phone numbers are often tied to legal identity, billing records and mobile-network metadata.
Signal’s username system substantially improves how people connect. You can create an optional username and share it instead of your phone number. By default, people who do not already have your number saved will not see it in your Signal profile. You can also prevent people from discovering your account by searching for your phone number.
Signal usernames are deliberately different from public social-media handles. They are not shown as permanent public identities in every chat, and someone generally needs the exact username to initiate contact. You can change or delete a username.
The limitation is important: a username does not replace phone-number registration. It reduces disclosure between users; it does not make the underlying account anonymous or remove the number from registration.
How private contact discovery works
A messenger is far easier to adopt when it can tell you which existing contacts already use the service. A basic implementation would upload an address book and compare it on the server, creating an attractive database of social relationships.
Signal has developed private contact-discovery systems intended to perform this matching without keeping a plaintext copy of users’ contact lists. The engineering has changed over time as Signal has improved its infrastructure, so the durable conclusion is more important than any one implementation detail: the service is designed to learn less than a conventional server-side address-book database would reveal.
No contact-discovery system eliminates every risk. Your own operating system still controls contact permissions, and a malicious or compromised device can read what the legitimate Signal application can access. Users who prefer not to grant contacts permission can still connect manually using an exact username or number.
Signal PIN and Registration Lock
A Signal PIN protects encrypted account data such as your profile, settings, contacts and block list, and it supports Registration Lock. It is not the same as your phone’s screen-lock code, the SMS registration code or a backup recovery key.
Registration Lock adds the PIN to the process of registering your number on another device. This helps reduce the damage from SIM swapping or a stolen SMS verification code. Signal says it does not know the PIN and cannot reset it for you. Forgetting it while Registration Lock is enabled can leave you locked out for up to seven days.
Most importantly, a Signal PIN is not a message backup. It cannot restore lost conversation history. That requires a supported transfer method or backup.
Signal Secure Backups
Older reviews often say Signal has no cloud-style backup. That is now outdated. Signal offers optional Secure Backups, an end-to-end encrypted archive that can restore message history after a lost, damaged or replaced phone, including cross-platform restoration.
The archive is protected with a 64-character recovery key that is not shared with Signal. Without it, neither Signal nor anyone else can decrypt or restore the backup. This is strong privacy, but it transfers responsibility to the user: lose the key and the archive is effectively lost.
The free Secure Backup tier includes text messages and the most recent 45 days of media. A paid plan, listed by Signal at $1.99 per month when this review was verified, can store up to 100 GB of media. View-once messages and messages due to disappear within 24 hours are excluded.
Secure Backups are opt-in. Signal also documents on-device backup options for supported platforms. Backup choices, formats and platform support have changed over time, so readers should follow the current official backup page rather than an old tutorial.
Linked devices
Signal can be registered on one primary mobile device and linked to up to five secondary devices. Current support includes computers, iPads and supported Android secondary devices. Linked devices can continue sending and receiving messages without the phone remaining continuously online.
Each linked device expands the security boundary. A well-protected phone does not help if an unlocked laptop on the same account is stolen. Signal provides a linked-device list so users can review and remove devices they no longer recognize or use.
When connecting a new device, verify that you initiated the process and periodically check the device list. For high-risk conversations, the security of every endpoint matters as much as the protocol between them.
Open source code, audits and reproducible builds
Signal publishes client code and the core protocol libraries. Public specifications allow cryptographers and developers to examine how the protocol is intended to work, while open repositories make it possible to inspect implementation changes.
Open source is valuable, but it is not a magic safety certificate. A vulnerability can exist in public code, reviewers may miss it, and a secure protocol can be undermined by a device, operating system or implementation bug. The benefit is verifiability and wider scrutiny—not perfection.
Signal Android documents a reproducible-build process. A successful independent reproduction can provide evidence that a released Android application corresponds to the public source code. This is a meaningful supply-chain safeguard, although reproducibility depends on the release, tooling and ability of independent parties to repeat the process. It should be treated as one layer of trust, not the only layer.
Signal and its protocol have received substantial academic and independent scrutiny over the years. However, readers should be cautious with the phrase “audited.” An audit usually covers a particular version, component and scope at a particular time; it does not permanently certify every future app release.
Everyday usability
Signal’s strongest achievement may be making robust encryption feel ordinary. New users can send messages, create groups and make calls without understanding key exchange. Safety numbers allow people with higher-risk threat models to verify a conversation through another trusted channel.
Groups support up to 1,000 members, with links, QR invitations, administrator controls, mentions and disappearing-message settings. This is enough for families, teams and many communities, though it is not a replacement for Telegram-style public broadcasting or a full workplace collaboration platform.
Call quality and battery use depend heavily on devices and networks, so universal performance claims would be misleading. In ordinary use, the main adoption obstacle is usually social rather than technical: the people you need to reach must also install Signal.
The interface is relatively simple, but privacy-respecting choices sometimes create friction. Recovery keys cannot be reset by support, a PIN cannot magically restore messages, and encrypted data cannot always be recovered after mistakes. These are not accidental inconveniences; they are consequences of keeping control away from the provider.
Important limitations and realistic threats
Signal is not anonymous
Registration uses a phone number, network connections expose information to internet providers or other observers, and contacts may already associate your number or profile with your identity. Use Tor or other specialized tools when network anonymity—not only message confidentiality—is the primary requirement.
Endpoint compromise defeats message encryption
Malware, an unlocked phone, an exposed desktop notification or physical access can reveal messages after decryption. Enable a strong device passcode, operating-system updates, full-disk encryption and Signal’s screen-lock and notification-privacy options.
The recipient can copy what you send
Disappearing messages reduce retention; they cannot stop a recipient from photographing a screen, copying text or using another device. Never treat disappearing messages as enforceable deletion from every possible record.
Phishing and impersonation still work
Encryption faithfully protects a conversation with whoever controls the account at the other end. It does not prove that a stranger claiming to be support, a colleague or a family member is genuine. Signal says its staff will not contact users in chat to ask for PINs, registration codes or recovery keys.
Centralized service availability
Signal relies on centrally operated service infrastructure. This enables a polished experience and rapid security upgrades, but it creates dependence on Signal’s servers, app distribution and resistance to blocking. Signal supports proxy-based censorship circumvention, yet no centralized messenger can promise uninterrupted access in every country.
Signal vs Telegram and WhatsApp
| Area | Signal | Telegram | |
|---|---|---|---|
| Personal message encryption | End-to-end by default | Cloud chats are not E2EE; Secret Chats are optional | End-to-end by default |
| Business model | Nonprofit, donation-supported | Commercial platform with premium and advertising features | Owned by Meta; broader commercial ecosystem |
| Phone number | Required for registration; usernames reduce sharing | Required; usernames widely used | Required |
| Public channels and huge communities | Limited focus | Major strength | Channels and communities, but not Telegram’s scale model |
| Server-readable ordinary chat content | Designed not to have it | Cloud-chat model permits server-side access to ordinary chat data | Message content E2EE, but more ecosystem metadata and integrations |
| Best fit | Private personal and group communication | Public communities, channels and feature-rich cloud messaging | Convenient encrypted communication with a very large user base |
Signal’s main advantage over Telegram is simple: users do not need to remember to start a special chat for end-to-end encryption. Compared with WhatsApp, both protect personal message content by default, but Signal collects less account and ecosystem data and is not part of an advertising company.
That does not automatically make Signal best for every task. Telegram is substantially better for public broadcasting and massive communities, while WhatsApp may be easier when nearly every contact already uses it. The right choice depends on whether privacy defaults or network reach is the priority.
Who should use Signal?
Signal is an excellent choice for:
- families and friends who want strong protection without configuring encryption;
- journalists, researchers and professionals handling sensitive conversations;
- people moving away from advertising-driven communication platforms;
- small and medium groups that do not require public channels or complex bots;
- users who value open technical documentation and data minimization.
Signal may be less suitable for:
- people who cannot or will not register with a phone number;
- anonymous communities that require identity separation from telephone infrastructure;
- large public broadcasts, discovery feeds, bots and extensive community tooling;
- organizations needing formal retention, e-discovery, centralized administration or compliance archiving;
- anyone unwilling to manage recovery keys and device security responsibly.
Official sources and further reading
This review prioritizes Signal’s primary documentation for current product behavior and protocol design. Product details can change, so the linked pages should be treated as the source of truth after the “Last verified” date.
- Signal technical documentation and protocol specifications
- Signal Protocol and Post-Quantum Ratchets
- Phone number privacy and usernames
- Signal Secure Backups
- Signal PIN and Registration Lock
- Linked-device limits and support
- Signal group features and limits
- Signal government-request disclosures
- Signal Android reproducible-build documentation
Signal is the best default recommendation for most people who want private messaging without turning security into a hobby. Its strongest qualities are end-to-end encryption everywhere it matters, unusually limited server-side data, transparent protocol documentation and a nonprofit model that does not depend on profiling conversations for advertising.
The score is not perfect because registration still depends on a phone number, the service remains centralized, backups and linked devices create additional responsibilities, and no messenger can protect an already compromised endpoint. Those limitations are real, but Signal explains and engineers around them more honestly than most mainstream alternatives.
VeilNorth is an independent publication focused on privacy, cybersecurity, AI and digital rights. We prioritize primary documentation, explain technical tradeoffs in plain language and separate verified facts from editorial judgment.
How we researched this article
We reviewed Signal’s current support documentation, protocol specifications, public source repositories, nonprofit materials and government-request disclosures. We avoided treating marketing language as proof and highlighted areas where encryption cannot compensate for device compromise, identity exposure or user error.