Encrypted lawyer–client chat with no firm server

Privilege protects a conversation in court. It does not protect the copy sitting on your practice management platform, your client's employer's mail server, or a cloud backup neither of you thought about. Btwinus is a direct, encrypted, browser-to-browser chat that leaves none of those copies behind.

The problem

Lawyers and clients need to talk quickly, and they usually reach for whatever is at hand: email, WhatsApp, a text message. Each of those creates a durable record on infrastructure controlled by somebody else. That record can be reached by a breach at the provider, a discovery request against a third party, a client's employer who owns the device, or a family member who shares the phone.

The moments that matter most are also the ones where a record is most dangerous: an initial consultation before the client has decided to engage, a frank assessment of a weak position, or a conversation the client does not want a spouse or employer to find.

Why ordinary tools leak

How Btwinus fits

Btwinus runs entirely in the browser. When you start a chat, your browser creates an encrypted invite link and a passphrase. The WebRTC handshake inside the link is encrypted with AES-256-GCM, with the key derived from the passphrase via PBKDF2 (100,000 iterations), and carried in the URL fragment, which browsers never transmit to any server. Once the client opens the link and enters the passphrase, both browsers connect directly to each other. Messages never touch a firm server, a cloud provider, or Btwinus. There is no account and nothing is written to disk. When either side closes the tab, the conversation is gone.

The important habit is keeping the link and the passphrase on different channels. Then no single compromised mailbox or chat app is enough to open the conversation.

Step by step for a lawyer

  1. Agree a time on the phone. Btwinus is live only while both of you are in the tab. Set a time the way you would set a call.
  2. Start the chat and email the link. Open btwinus.com, click Start a new chat, and send the invite link to the client by email or any messenger. On its own the link is unreadable.
  3. Give the passphrase by phone. Call the client and read the passphrase out loud. It is designed to be spoken, something like storm-fox-river-4821. Never type it into the same channel as the link.
  4. Receive the reply link. The client opens the link, enters the passphrase, and Btwinus copies a reply link to their clipboard. They send it back to you by the same route the invite took.
  5. Paste it and verify. Paste the reply link and you are connected. Compare the short authentication string with the client over the phone. If it matches, nobody intercepted the handshake.
  6. Record what the file needs, then close. Anything that must be on the file goes into your own notes, on your own terms. Then close the tab and there is nothing left to secure.

If the client is with you in person, you can show the invite link as a QR code instead of sending it, and say the passphrase across the desk.

Honest limitations

Btwinus is free and open source, so your IT lead can read every line of what runs in the browser.

Have a conversation with a client that lives nowhere but your two browsers. No account, no firm server, gone on close.

Start a private chat →

← All use cases