If you are looking at the xPal Chat application for the first time and feel hesitant about choosing it, don’t leave; test it yourself.
It is natural to feel this way because trust must be earned and tested!
The major messaging platforms have been around for years and have become part of everyday life, which is why people already have their contacts there, their conversations there, and their habits built around them. xPal does not have that history of familiarity yet, but it is growing.
That is a reasonable place to start.
But early and security are not the same thing.
No. xPal’s encrypted messaging app has been operating since 2020. The U.S. National Institute of Standards and Technology’s Cryptographic Algorithm Validation Program validated its cryptographic implementation under certificate A7969, and DEKRA independently audited and certified its cybersecurity posture in 2023, 2024, 2025, and 2026. It has also gone through Google CASA/MASA certification through the App Defense Alliance and has quite a good user base.
There is another point worth making, though. No private texting app deserves blind trust, including xPal. A sensible way to evaluate a privacy product is to look at what it collects, how its cryptography is validated, how an account is identified, what happens to data on the device, what independent scrutiny exists, and where the product’s protections stop.
That is what matters here because if users are not aware of all of it, how can they stand for their digital privacy rights?
Just as importantly, calling the xPal encrypted messaging app “new” is understandable if you are comparing it with products that have been part of everyday communication for a decade or more. Nevertheless, it is not accurate if “new” is being used as shorthand for “untested.”
The public record gives users several things to examine:
There is a meaningful difference between messaging platforms that make a security claim and one whose implementation has been subjected to external testing.
What repeated external review does is provide a record that can be examined.
Yes. xPal’s encrypted messaging app uses AES-256, which has been a public standard since 2001 and is used extensively across government, financial and commercial systems. xPal’s use of AES-256 therefore does not depend on asking users to believe that the company invented something clever enough to replace established cryptographic standards.
It means xPal’s cryptographic implementation was tested against official validation requirements and received a publicly listed NIST certificate, A7969.
The important word is implementation here.
Anyone can say that a chat application uses AES-256. The difficult part is implementing cryptography correctly inside real software.
When a cryptographic software implementation undergoes NIST CAVP validation, it is submitted to an accredited independent testing laboratory to verify that its underlying encryption formulas operate correctly.
The lab uses NIST’s Automated Cryptographic Validation Testing System to generate standardized test vectors, specific inputs with predetermined mathematical outputs, and processes them through the software. If the implementation yields exact, error-free results across all test vectors, NIST officially validates the cryptographic algorithm, assigns it a formal certificate number, and publishes the entry in its public registry as proof of mathematical compliance.
In xPal’s case, that number is A7969.
An Important detail is that CAVP validation states the accuracy of specific cryptographic algorithm implementations. It does not evaluate full system architecture, implementation integrity in broader software builds, end-to-end operational security, or user privacy practices.
No. xPal’s private texting app is closed source, and that is a genuine limitation for people who require public code review.
Messaging platforms have no reason to disguise this.
Open source lets security researchers, developers, and other technically capable people inspect the code themselves. Public source code does not automatically make software secure, but it creates a form of scrutiny that closed-source software cannot provide in the same way.
xPal has taken another route of independent external assessment and certification.
DEKRA’s audits provide outside scrutiny of the product, but they are not the same thing as having the entire codebase publicly available for anyone to examine.
It also means different users can reasonably place different weight on the evidence available to them.
For someone evaluating xPal private messaging more broadly, however, the question becomes what other forms of evidence exist and whether those are sufficient for the particular use case.
xPal encrypted messaging app registration requires a screen name and PIN, rather than a phone number, email address, or real name.
An automatically generated nine-digit xID (global) is then given as the account identifier.
| Data | Required by xPal? |
|---|---|
| Phone number | No |
| Email address | No |
| Real name | No |
| Profile photo | No |
| Contacts access | No |
| Location data | No |
| IP address logging | No |
| Permanent message backups | No |
There is a broader principle behind this.
Privacy is partly about what a company promises to do with information. It is also about how much information exists in the first place.
If messaging platforms do not require your phone number to create an account, there is no phone number sitting in that account record. If it does not require your address book, there is no reason for your entire contact list to become part of the service’s account graph.
That does not make a service invisible. It changes the amount of information that has to be trusted.
xPal Chat application also removes metadata from shared media before encryption and transmission because photographs and other files can contain information beyond their visible contents, including details such as device information, timestamps, and, depending on the file, location information.
An xID is a nine-digit identifier generated for an xPal account, allowing people to connect without using a phone number as their messaging identity.
That is one of the more consequential choices in xPal’s design.
A phone number has a life outside a messaging application. It is connected to a carrier account and often to other accounts, recovery systems, services, and people who already know you.
A messaging identity built around that number therefore inherits some of the identity attached to the number itself.
An xID is narrower. Someone can have your xID and contact you on the xPal encrypted messaging app without being given your phone number.
No. A large user base tells you that a service is widely used; it does not, by itself, tell you how much information the service collects or how private messaging is implemented.
Scale and privacy are different.
A platform with hundreds of millions of users can be extremely secure in some respects and still collect considerably more information because of the way its products operate.
Telegram is a useful example. Its ordinary cloud chats are not end-to-end encrypted. Users have to initiate Secret Chats when they want that form of protection.
WhatsApp, meanwhile, provides end-to-end encryption by default, but its account system is built around phone numbers and its wider service ecosystem involves metadata and other information.
None of that makes a simple equation out of privacy. A larger service may offer things a smaller service cannot: enormous reliability, broad contact networks, mature infrastructure and a huge existing user base. Those are real advantages.
A smaller service can make different architectural choices because it does not have to preserve the same ecosystem.
That is where xPal’s approach becomes interesting. Its smaller scale is not evidence of security by itself. What matters is what the Chat application has chosen to collect, retain, and expose.
xPal private texting app provides several tools designed to remove message history and private data from devices.
Devices get lost, and phones also get stolen sometimes. People replace them, of course. If devices are inspected, accounts can be compromised.
xPal includes several controls intended for these situations:
Start with the claims that you can verify yourself.
A practical test would be:
This is not advice that applies only to xPal private messaging.
It is a useful way to approach almost any privacy product.
xPal differs from the major messaging platforms mainly in identity design, data minimization, source availability, and device-level privacy controls. You can also read the fuller comparison of modern secure messengers.
| Feature | xPal | Signal | Telegram | |
|---|---|---|---|---|
| Phone number required for registration | No | Yes | Yes | Yes |
| End-to-end encryption by default | Yes | Yes | Yes | No (Only in Secret Chats) |
| Open source | No | Yes | No (Uses open-source Signal Protocol) | Partially (Clients open, Server closed) |
| Independent annual audit | Yes (DEKRA) | Yes (Cure53, NCC Group, public code) | Yes (Internal Meta & 3rd-party cryptographic checks) | Yes (Custom MTProto audited, Server closed) |
| NIST CAVP certificate | Yes (A7969) | Standard crypto libraries (No individual CAVP) | Standard crypto libraries (No individual CAVP) | Standard crypto libraries (No individual CAVP) |
| Contacts access required | No | Optional | Effectively yes | Optional |
| Remote wipe | Yes | No | No | Limited (Account self-destruct) |
| Owned by an advertising company | No | No | Yes (Meta) | No |
Is the xPal chat application free?
Yes. xPal’s free plan includes unlimited encrypted text
messaging and unlimited encrypted audio calls. The free plan uses the same encryption as
the paid Gold plan, while video calling is time-limited on free accounts. The important
point for someone evaluating the private messaging is that the privacy architecture is
not presented as something available only after upgrading. Privacy, as always, is the
greatest priority of xPal.
Can someone find you on xPal without your xID?
No. A person needs your exact nine-digit xID to contact you. xPal does not provide a
phone-number directory or contact scanning for discovering users. That means someone who
knows your phone number cannot simply use that number to locate your xPal account.
Can deleted xPal messages be recovered?
No, they can’t be because xPal does not store messages or user data
permanently, so if something is never saved, how can it be recovered? Messages
removed through Terminate™ or Wipeout™ are not recoverable by xPal either.
Does xPal track your location?
No, location data is not required or collected by xPal. That removes one category of
information from the account model.
What happens if you lose your xID?
xPal provides an account recovery process and an additional Access
ID mechanism. The sensible time to configure recovery is when you create the account. A
recovery mechanism becomes considerably less useful if the only time you discover it is
after you have already lost access.
Is a messaging app without a phone number safer?
Yes. It can reduce identity exposure because your messaging account is not directly tied
to your phone number. Removing the phone number can eliminate one important link between
a messaging identity and a real-world identity. It can also remove some risks associated
with phone-number-based account recovery and SIM-based attacks.
Why do most messaging apps still use phone numbers?
Phone numbers make account creation and contact discovery much easier, but they are not
a cryptographic requirement for encrypted private messaging. A phone number gives an
application a familiar identity system. It can help users find friends, connect address
books, and determine which contacts are already using the service. It also means the
messaging account is built around an identifier that already exists outside the
application.
Can closed-source encryption be trusted?
Closed-source software can be subjected to meaningful independent scrutiny, but public
source code and independent audits provide different kinds of evidence. Public code
review lets many people inspect the implementation. Independent audits put the software
through defined external assessment. Neither sentence should be stretched into a
universal guarantee. For xPal, the relevant fact is that the source code is not public
while the product has pursued external validation and regular audits.
Can encrypted messages be read by governments?
End-to-end encryption is designed to prevent an intermediary from reading messages in
transit, but it cannot protect a device that has already been compromised or a person
who voluntarily reveals the conversation. That is why endpoint security matters. If a
phone can display the message, something on that phone can potentially access it. This
is also why message deletion, device security, and
operational habits deserve attention alongside encryption. Encryption is a
powerful protection. It is not magic.
You should know both what xPal can demonstrate and where its evidence has limits.
The strongest evidence is:
For xPal, being a newer and smaller platform means it has less cultural familiarity than the names most people already know. It cannot manufacture decades of public history overnight.
However, xPal puts privacy first, and it is seen in all the layers of its architecture.
Start small, verify the product yourself, and let your own experience determine how much you rely on it.
You do not have to make a dramatic switch.
Install it. Look at what it asks for. Check the permissions. Verify the externally available security claims. Try the messaging and calling experience. Test the deletion features with something that does not matter. Set up recovery before you need it.
Then use it for a conversation where the additional privacy actually has a purpose.
That is enough to begin with.