Today marks a major milestone: we are officially releasing encrypted1on1 v1.0.0 — our first stable production release. It provides teams with a dedicated, structured space for 1:1 meetings where the server never sees your plaintext notes, feedback, or goals.

Why 1:1 meetings need zero-knowledge architecture

1:1 meetings between managers and team members are where a company’s most sensitive conversations happen. Performance concerns shared in confidence, compensation and promotion plans, burnout signals, and deeply personal circumstances.

Conventional internal wikis, docs, and cloud SaaS tools ask everyone to rely on trust: trust that database backups won’t leak, trust that vendor staff won’t peek, and trust that IT administrators won’t inspect private conversations.

With encrypted1on1, we replaced trust with mathematics. All meeting content is encrypted client-side in the browser before reaching the server. Even whoever operates the server or owns the database has zero access to the plaintext.

What’s new in v1.0.0

The v1.0.0 release represents months of architectural iteration, security hardening, and real-world usage. Here is what is included out of the box:

  • End-to-end encrypted “anketas” (1:1 meeting forms): X25519 keypairs per participant, XChaCha20-Poly1305 symmetric authenticated encryption for content, and Argon2id password-based key derivation.
  • Asynchronous preparation: Managers and direct reports fill in feedback, priorities, blockers, and mood/workload self-assessments ahead of the call.
  • Goal continuity across cycles: Goals and checkpoints carry forward automatically into subsequent meeting cycles until archived or completed.
  • Privacy-preserving trend reports: A multi-cycle report view with mood and goal-progress sparklines rendered via inline SVG entirely client-side — no tracking scripts, no charting libraries, no server-side plaintext aggregation.
  • Production account controls: Configurable registration modes (invite-only, admin-only, or domain-restricted self-registration with double opt-in), in-app password changes, and full client-side decrypted JSON data exports.

Engineered for verifiable security

We designed encrypted1on1 with defense-in-depth principles across the entire stack:

  • Black-box privacy test suite: Dual-actor Playwright end-to-end tests that run real browser cryptography, make live API requests, and inspect raw database records to mathematically assert that no plaintext ever reaches disk or network payloads.
  • Strict security headers: Content Security Policy (CSP) with Subresource Integrity (SRI) on all bundled assets, and enforced HSTS.
  • Hardened production container: Runs as a non-privileged user on FrankenPHP + Caddy with automatic HTTPS and built-in healthchecks.
  • High-performance storage: SQLite with Write-Ahead Logging (WAL) enabled by default for rapid concurrent writes, plus a validated migration path to MySQL for large installations.

Getting started & Docker deployment

Deploying encrypted1on1 takes just one command using our official production image published to the GitHub Container Registry:

docker pull ghcr.io/aleksejs1/encrypted1on1:1.0.0

If you want to experience the workflow before self-hosting, check out the live sandbox at demo.private1on1.eu — it requires no registration and includes pre-populated meeting history in all supported languages.

The complete source code is licensed under AGPLv3 and available on GitHub.