How do I know I'm running the real app?

Check that the TACENZA Chat code in your browser matches the published release, get the desktop app from the right place, and verify your contacts.

First, check the address. TACENZA Chat runs at chat.tacenza.app. If you’re on any other address, don’t log in there.

Check the app’s code

TACENZA Chat isn’t open source at the moment. So that you don’t have to take our word for what you’re running, every release publishes the SHA-256 of the app’s JavaScript in two places:

  1. On the app’s security page, at chat.tacenza.app/security. In Chat, Settings › Advanced › Diagnostics › Code fingerprint links there.
  2. On GitHub, in the public tacenza/releases repository, apart from our servers. A published hash is never replaced.

If the hashes on the two match, the code we serve is the code we published. The README in tacenza/releases explains how to check the files your browser actually loaded.

You can also open your browser’s developer tools and watch the network log: every request goes to TACENZA, never to anyone else. Push notifications are the one exception, and only if you turn them on.

The desktop app

Only download the desktop app from Chat itself: Settings › Security Center › Download for Windows. The installer isn’t code-signed yet, so Windows warns the first time you run it. See Using the desktop app.

Verify the people you talk to

Checking the app protects you from changed code. To be sure nobody is in between you and a contact, compare safety numbers with them in person or on a call you trust. See Someone’s safety number changed.

Warning

TACENZA will never ask for your password, your recovery key or your authenticator codes – not in a chat, not by email, not on a website. Anyone who asks is trying to take over your account.

Honest limits

An independent security review is planned but hasn’t happened yet. The known limits of the design are listed on the security page.

Read more: Verify the app you’re running in the docs.

Still stuck?

If a hash doesn’t match or something looks wrong, report it privately: report a vulnerability. For anything else, contact support.