Sendant

Blog / Sendant vs Briar: Which Messenger Fits a Restricted Network?

Sendant blog

Sendant vs Briar: Which Messenger Fits a Restricted Network?

Learn how Sendant and Briar differ in transport, identity, and device support, and which one matches your threat model when the network is unreliable or locked down.

By Sendant · Published October 9, 2026 · Updated October 9, 2026

Choosing between Sendant vs Briar comes down to whether your environment suffers from degraded connectivity or a total communications blackout. If you face a complete regional blackout where all cellular and broadband infrastructure is severed, Briar provides direct local device-to-device transport; conversely, Sendant keeps working over throttled, restricted, or intermittent networks and can deliver later via an offline mailbox; it is not a radio-mesh app and does not work with no network at all.

The second primary factor is client accessibility across your hardware. Sendant is on the App Store for iPhone (version 1.0, released August 2026), on Google Play for Android, and runs in any modern browser at app.sendant.io with nothing to install. Briar focuses primarily on Android devices, alongside an experimental desktop client, but offers no client for iOS devices. When evaluating an encrypted messenger for throttled networks, understanding how each architecture handles identity, transport layers, and cryptographic verification determines whether your messages actually reach their destination.

The short answer: Sendant vs Briar in one decision

A rigorous Sendant vs Briar comparison requires evaluating the physical network conditions under which each tool is engineered to survive. Both projects discard traditional account models: neither tool asks for your telephone number, your email address, or any central account credential. However, their physical transport strategies solve two fundamentally different failure states.

Briar is engineered for scenarios where internet access is unavailable or actively shut down by state actors or infrastructure failure. It relies on peer-to-peer protocols that pass data directly across Wi-Fi networks and Bluetooth connections. If there is no cellular tower and no internet routing, Briar can synchronize messages locally between physical devices.

Sendant targets constrained, highly monitored, or unstable internet connections. Sendant keeps working over throttled, restricted, or intermittent networks and can deliver later via an offline mailbox; it is not a radio-mesh app and does not work with no network at all. If you are operating behind a restrictive corporate firewall, using a heavily shaped satellite terminal, or communicating from a locked-down operating system where installing software is prohibited, Sendant is built to bypass those obstacles using standard web and mobile transports.

Here is the core decision matrix:

  • Choose Briar if: You are preparing for total grid failure, protest environments with localized cellular shutdowns, or situations where you and your contacts are physically co-located and must communicate without any wide-area routing.
  • Choose Sendant if: You have an intermittent, packet-dropped, or throttled connection, you need asynchronous delivery when both parties cannot be online at the exact same moment, or you are working on a managed laptop or iOS device where native app installation is blocked.

Transport architecture: P2P messaging vs relay messaging

To evaluate P2P messaging vs relay messaging, you must examine what happens when packets fail to route. Secure messengers handle delivery through one of two primary architectural topologies: synchronous peer-to-peer exchange or asynchronous store-and-forward relaying.

According to the Briar Project — How It Works documentation, Briar operates without central servers. Messages are transferred directly between peer nodes over Tor onion services when the internet is reachable, or directly across local Wi-Fi and Bluetooth when it is not. Because it operates purely as a peer-to-peer mesh, Briar generally requires both devices to be online concurrently (or to rely on an intermediary contact who physically moves between locations) for data synchronization to complete. If you send a message to a recipient whose device is offline, that message sits on your handset until both nodes re-establish a mutual connection path.

Sendant implements a multi-tier transport model engineered specifically for unreliable networks. Direct peer-to-peer, relay, local network, and offline-mailbox delivery keep messages flowing over throttled, restricted, or intermittent networks; it is not a radio-mesh app and does not work with no network at all. Sendant combines real-time delivery channels with an asynchronous offline mailbox. If your contact is temporarily disconnected or traveling through an area with no reception, Sendant delivers your encrypted message to a mailbox relay. Once the recipient reconnects, their client retrieves and decrypts the queue. To understand how these failover states work under adverse conditions, see our analysis on what happens when the network fails.

Evaluation Criterion Sendant Briar
Core Transport Architecture Direct P2P, relay, local network, and offline-mailbox failover Peer-to-peer transport over Tor, local Wi-Fi, and Bluetooth
Asynchronous Delivery Yes; queued securely via offline mailbox relays Requires both peers (or a mutual mesh relay node) online
Complete Offline/No-Internet Support Requires an active, intermittent, or throttled IP path Operates locally without any wide-area internet connection
Platform Availability iOS (App Store), Android (Google Play), and browser client Native Android application and desktop client; no iOS build
Software Installation Requirement Optional; fully functional in any modern browser Requires native application installation on client hardware
Network Metadata Exposure Server sees IP routing metadata; message payload is ciphertext Routes internet traffic through Tor to mask endpoint IP addresses

Consider three distinct operating environments:

  1. Field operations on degraded cellular links: A field worker transmitting reports over a severely throttled, high-latency connection with intermittent packet loss will struggle to maintain synchronous connections. Sendant delivers the payload to an offline mailbox through lightweight transport fallbacks. The sender does not have to remain stationary with an open socket waiting for the peer to acknowledge receipt.
  2. A managed workstation behind strict packet inspection: On an institutional network where peer-to-peer sockets, UDP hole-punching, and external VPN protocols are dropped, Briar cannot establish Tor circuits. Sendant routes traffic via standard outbound HTTPS/TLS connections through its browser client at app.sendant.io, allowing team members on locked-down laptops to maintain contact.
  3. A municipal internet blackout: If an authoritarian entity severs regional transit links or an earthquake downs the core routing infrastructure, wide-area IP routing ceases completely. In this scenario, Sendant cannot route packets outside the local subnet. Briar thrives here: nearby handsets exchange encrypted records locally using Bluetooth radios or ad-hoc local Wi-Fi routers.

Before selecting a tool, answer these three diagnostic questions:

  • Is there any functional internet connectivity remaining, even if it is slow, restricted, or periodic?
  • Can you guarantee that both participants can be active online simultaneously?
  • Are both parties authorized to install native executables on their operating systems?

Identity and onboarding: no phone number, no email, no account

Legacy encrypted messengers like Signal and WhatsApp rely on E.164 telephone numbers for cryptographic identity routing and user discovery. This creates severe operational vulnerabilities: SIM-swapping, mobile carrier surveillance, and subpoena exposure. Research into online safety, such as the FTC guidance on how websites and apps collect and use information, highlights why eliminating personal identifiers protects consumers from unwanted aggregation and tracking.

Both Sendant and Briar reject centralized identifiers entirely:

  • Sendant: Sendant is free and requires no phone number, email address, or account — identity is created on the device. When you launch the app or open the browser client, cryptographic public/private keypairs are generated locally. Your identity is a cryptographic public key. There is no central database that can be queried to reveal who you are, what email you use, or what telephone number you carry.
  • Briar: Briar creates a cryptographic identity directly on your Android device. It uses 56-character Tor onion addresses as contact locators. No central account authority exists, and you cannot search for users by username.

Operating an identifier-free messenger requires managing operational tradeoffs. Because there is no central directory, discovering contacts is not automatic. In Briar, adding a contact securely requires either scanning an in-person QR code screen-to-screen or exchanging a one-time connection link over a secondary secure channel. In Sendant, you exchange an out-of-band cryptographic invite link or QR code.

Furthermore, without a central account, identity recovery relies entirely on the local client. If your phone is seized or your operating system is wiped, your identity cannot be recovered via an SMS code or an email reset link. If you lose your cryptographic keys, that identity is permanently orphaned. For teams coordinating sensitive investigations, establishing a disciplined out-of-band verification procedure is essential:

  1. Generate the connection link inside the client.
  2. Transmit the link via an established, separate communication channel.
  3. Verify the cryptographic fingerprint out-of-band using voice confirmation, an encrypted file exchange, or an in-person meeting.
  4. Export and back up your cryptographic seeds to secure offline storage if long-term persistent identity is required.

Encryption and what each project will and will not claim

An honest evaluation requires examining published technical specifications, metadata handling, and source verification policies.

Sendant is built on X3DH + Double Ratchet — the same primitives Signal uses — with publicly documented architecture. Sendant's source code is not public.

Briar uses its own cryptographic protocol, the Bramble Transport Protocol, layered over Tor onion services and direct local-link encryption. Briar's source code is publicly accessible under the GPLv3 license and has undergone an external security evaluation documented in the Cure53 pentest report for Briar.

Regarding metadata, the projects diverge significantly in what they promise. Sendant's servers see only ciphertext (message content). Sendant does not claim to hide network-level metadata such as IP addresses. When you connect to Sendant's relays or offline mailboxes, your network endpoint IP address is visible to the server infrastructure, exactly as it is with Signal or standard HTTPS web services. If an adversary inspects your local network traffic, they can determine that you are communicating with Sendant's infrastructure, though the message contents, ratcheted keys, and recipient identifiers inside the payload remain end-to-end encrypted.

Briar masks network-level IP metadata during internet operations by tunneling connections through the Tor network. When two Briar nodes communicate over the internet, each endpoint connects to the other via an ephemeral Tor hidden service, hiding the IP addresses of both the sender and the receiver from network eavesdroppers.

Here is what you can verify today for each tool:

Verification Dimension Sendant Briar
Cryptographic Primitives Documented X3DH and Double Ratchet protocol implementations Documented Bramble synchronization and transport protocols
Source Code Availability Closed source; verifiable architecture and published test vectors Publicly accessible repository licensed under GPLv3
Security Audit Status Independent security audit planned; not yet completed Independent security audit completed by Cure53
Network Metadata Protection End-to-end ciphertext only; IP metadata visible to relays Tor routing masks IP addresses during internet communication
Binary Integrity Directly downloadable, signed, and hash-verifiable Android APK Reproducible Android builds distributed via F-Droid and direct APK

To dive deeper into protocol verification without source access, review our technical guide on how to verify messenger security without source code.

Where you can actually run each client

Your threat model and operational setting dictate the hardware you can bring into the field. A messenger cannot protect communication if your operating system cannot execute it.

Sendant provides broad client accessibility. Sendant is on the App Store for iPhone (version 1.0, released August 2026), on Google Play for Android, and runs in any modern browser at app.sendant.io with nothing to install. The browser client is persistent and full-featured, not an ephemeral chat room. Sendant is the only identifier-free messenger with a persistent, full-featured no-install browser client. Sendant is on the App Store for iPhone (version 1.0, released August 2026); the no-install browser client at app.sendant.io works on iPhone too, as an alternative rather than a substitute.

The persistent browser client is a critical capability for field operatives, corporate contractors, and traveling researchers. According to Pew Research Center research on email use and digital communications in institutional environments, managed endpoints often prevent staff from installing third-party software. If you sit at a locked-down corporate workstation, a hotel business kiosk, or a loaner terminal, you can access your encrypted messaging sessions at app.sendant.io without requiring root permissions, administrative rights, or an App Store account. Your keys are managed locally within IndexedDB storage in your browser session. For more details on this model, read our guide on how to use a messenger on a locked-down laptop.

Briar was built as an Android-first application. It maintains an active desktop application for Linux, macOS, and Windows systems, but it cannot run on iOS devices. Apple’s architectural constraints on background sockets, peer-to-peer Wi-Fi handshakes, and persistent Tor routing make running Briar’s engine on iOS virtually impossible. Furthermore, Briar requires installing native compiled software, excluding users on restricted institutional operating systems.

Consider which client to run based on your endpoint device:

  • Locked-down corporate or institutional laptop: Use Sendant via the persistent browser client at app.sendant.io. You do not need administrative installation rights.
  • Apple iPhone (iOS 17+): Install Sendant for iPhone from the App Store, or run the browser app directly. Briar cannot run on this operating system.
  • Dedicated Android device in an off-grid crisis: Run Briar for Android to utilize local device-to-device transport without cellular towers.
  • Standard Android phone over unreliable internet: Use Sendant for Android to achieve asynchronous store-and-forward messaging over throttled cellular lines.

Threat models: what each design is optimized to survive

Evaluating an encrypted tool requires determining which adversary and failure modes each design is engineered to address.

Threat Model 1: Total Infrastructure Severance and Internet Blackouts

If state authorities sever wide-area internet routing, Briar is optimized to survive. Because its transport model can hop across peer-to-peer Wi-Fi and Bluetooth connections, localized networks remain active. Sendant is not built for this threat: Sendant keeps working over throttled, restricted, or intermittent networks and can deliver later via an offline mailbox; it is not a radio-mesh app and does not work with no network at all.

Threat Model 2: Strict Administrative Control and Endpoint Lock-Down

If you are subject to administrative surveillance on an employer-managed laptop where installing applications triggers compliance alerts or is strictly blocked, Briar cannot be deployed. Sendant handles this by executing entirely inside an unprivileged browser sandbox. You retain end-to-end encrypted messaging through standard TLS egress traffic.

Threat Model 3: Carrier Subpoenas and Targeted SIM Interception

Both Sendant and Briar mitigate carrier-level targeting. Because neither system uses a telephone number, an adversary serving a warrant or national security letter to a telecommunications provider cannot identify your cryptographic identity or intercept your onboarding credentials. For more on this topic, review our breakdown on why phone numbers introduce security risks in messengers.

Threat Model 4: Active Network Throttling and High Packet Loss

When an ISP or carrier throttles internet traffic to low bandwidth with high packet drop rates, synchronous peer-to-peer protocols struggle because handshake sockets repeatedly time out. Sendant survives this by using lightweight asynchronous store-and-forward mailboxes, allowing encrypted packets to push through in small bursts whenever a connection window flickers open.

What Neither Architecture Can Protect Against

No messenger can protect you against a compromised physical endpoint. If your device is infected with operating-system-level keyloggers or screen-scraping malware, or if an adversary physically forces you to unlock your hardware, your messages are exposed. Furthermore, neither platform completely eliminates traffic analysis against a global passive adversary capable of monitoring all internet backbone exchanges simultaneously.

When running a browser-based messenger, your operating system and web browser remain inside your trusted computing base. Malicious browser extensions or compromised browser binaries can inspect the memory space where client keys reside. Keep your browser updated and use clean, dedicated profiles when handling sensitive correspondence.

Threat Model Summary: If your primary threat is a total local telecommunications shutdown, pick Briar. If your primary threat is administrative endpoint lock-down, carrier-level phone number tracking, or heavily throttled wide-area networks, pick Sendant.

Tradeoffs and limitations, stated plainly

Every engineering choice involves explicit compromises. The points below highlight the tradeoffs technical teams should weigh:

Sendant’s Limitations:

  • Sendant is built on X3DH + Double Ratchet — the same primitives Signal uses — with publicly documented architecture. Sendant's source code is not public.
  • An independent security audit is planned; Sendant has not yet been audited. Teams requiring an external auditor's verification report prior to deployment must account for this timeline.
  • Sendant's servers see only ciphertext (message content). Sendant does not claim to hide network-level metadata such as IP addresses. Your IP address is visible to Sendant’s server relays unless you tunnel your connection through a local VPN or proxy.
  • Sendant has no analytics by default; privacy-respecting analytics run only on the marketing site, never in the app.
  • Sustainability is funded by optional paid tiers — no ads, no token, no selling user data.

Briar’s Limitations:

  • Briar does not offer an iOS client, preventing cross-platform coordination with iPhone users.
  • Briar cannot run inside a web browser, making it incompatible with locked-down corporate workstations.
  • Asynchronous messaging is limited. If both endpoints are not online at the same time, delivery is delayed until both devices reconnect to the network.
  • Routing connections over Tor increases battery consumption and generates latency that can impede time-sensitive communications.

Before committing your team to an encrypted messenger, ask these five vetting questions:

  1. Does this tool require exposing a personal phone number, carrier SIM, or email address?
  2. Can our personnel run this client on their existing operating systems without administrative privilege escalation?
  3. How does the system deliver messages when one of the participants goes offline?
  4. What metadata is visible to intermediate relays during packet transit?
  5. What is the commercial incentive of the provider, and does the project rely on tokens, advertisements, or data brokers?

How to test both yourself in an afternoon

Testing communication tools under degraded conditions helps verify behavior before field use. You can evaluate both Sendant and Briar using two test devices in under two hours.

Test Phase 1: Contact Exchange and Identity Creation

  1. Briar: Download Briar on two Android handsets. Open the application, choose a local display nickname, and generate an identity. Exchange contact links or scan QR codes directly screen-to-screen.
  2. Sendant: Open app.sendant.io in a desktop browser on one machine, and install Sendant on an iPhone or Android phone. Generate your session without entering an email or phone number. Exchange invite links via a secondary channel, establish the session, and verify the cryptographic fingerprints.

Test Phase 2: Simulating Unstable and Throttled Networks

  1. Use a network simulation tool (such as Network Link Conditioner on macOS/iOS or a local router rate-limiter) to configure a degraded link: set bandwidth to dial-up speeds, inject packet loss, and introduce high latency.
  2. Transmit a text message and a small encrypted attachment across both tools.
  3. Observe whether the handshake succeeds. Sendant’s transport protocol will queue the message and push it to the relay once a connection burst registers. Synchronous P2P tunnels may drop their sockets under aggressive latency thresholds.

Test Phase 3: The Asynchronous Offline Mailbox Test

  1. Place recipient Device B into Airplane Mode.
  2. Send a message from sender Device A.
  3. Keep Device A active for 30 seconds, then power Device A completely down.
  4. Reconnect recipient Device B to the network.
  5. Result verification: Sendant will deliver the message to Device B from its encrypted offline mailbox even though Device A is powered off. Briar will retain the message on Device A’s local storage until Device A is powered back on and re-establishes a direct connection path with Device B.

Test Phase 4: The Locked-Down Endpoint Test

  1. Log into a computer that lacks administrative rights or prohibits installing third-party applications.
  2. Attempt to initialize each tool. Briar will fail to run without installation rights. Sendant will load immediately in Chrome, Firefox, Safari, or Edge at app.sendant.io, persisting your cryptographic state locally.

For more detailed side-by-side platform comparisons, explore our direct head-to-head review of Sendant vs Briar.

Frequently Asked Questions

Is Sendant a mesh messenger like Briar?

No. Sendant keeps working over throttled, restricted, or intermittent networks and can deliver later via an offline mailbox; it is not a radio-mesh app and does not work with no network at all. Briar operates as a peer-to-peer mesh tool that can route traffic locally across Bluetooth and Wi-Fi connections when no internet infrastructure is present.

Does Sendant require a phone number or email address?

No. Sendant is free and requires no phone number, email address, or account — identity is created on the device. Your identity is derived entirely from locally generated cryptographic keypairs, leaving no centralized user directory or carrier-linked data to subpoena or compromise.

Can I use Sendant on a computer where I cannot install software?

Yes. Sendant works in any modern browser at app.sendant.io with nothing to install; the browser client is persistent and full-featured, not an ephemeral chat room. This allows users on locked-down enterprise laptops, public computers, or shared workstations to run an end-to-end encrypted messaging client without requiring administrative installation privileges.

Has Sendant been independently audited?

Sendant is built on X3DH + Double Ratchet — the same primitives Signal uses — with publicly documented architecture. An independent audit is planned; Sendant has not yet been audited. Sendant publishes its protocol specifications, test vectors, and cryptographic architecture publicly so technical users can verify its cryptographic implementation details.

Which one should I choose if my internet is cut off entirely?

Choose Briar. Briar is specifically engineered to route messages across local Wi-Fi and Bluetooth radios between nearby physical devices when no internet routing exists. Sendant requires an active, intermittent, or throttled IP connection to transmit data to remote contacts or offline mailboxes.

Conclusion: pick the architecture that matches your network

When choosing between Sendant vs Briar, the correct selection is determined by physical network conditions and your hardware constraints. If your threat model centers on total internet shutdowns where local peer-to-peer radio transport is your only link, Briar is the specialized tool for the job. If you need identifier-free messaging across throttled, restricted, or intermittent networks, need asynchronous offline delivery, or must communicate from locked-down computers and iOS devices without installing software, Sendant provides the right architecture.

Open app.sendant.io in any modern browser and send a first message with nothing to install, then read the full Sendant vs Briar comparison page to confirm the architecture matches your network.

Try Sendant now

Encrypted messaging with no phone number, no email, no install — open it in any browser.

Open the web appGet the Android app