See the stars

MeshUnion Specification

Home / MeshUnion / MeshUnion Specification

MeshUnion

Your Keys. Your Conversations. Your Node.


MeshUnion is a modular, federated communications and archival infrastructure specification designed for individuals, businesses, organizations, and independently operated network hosts.

MeshUnion enables participants to communicate across independently operated nodes while maintaining control over their identities, encryption keys, conversations, archives, storage relationships, and federation policies.

The system is designed around local operation, optional federation, complete end-to-end encryption, persistent searchable communication history, participant-controlled data, and independently provided infrastructure.


Specification Goals

MeshUnion is designed to provide:

  • Self-hosted communications infrastructure
  • Federated communication between independent nodes
  • Business-to-business communication
  • Peer-to-peer communication
  • Participant-controlled identities
  • Complete end-to-end encryption
  • Participant-controlled encryption keys
  • Persistent communication archives
  • Keyword and date-based historical search
  • Local and federated archive synchronization
  • Modular AI assistance
  • Independent storage hosting
  • One-time and long-duration storage purchasing
  • Perpetual storage arrangements
  • Data portability and migration
  • Host-controlled policies
  • No mandatory recurring platform charges
  • Vendor-independent infrastructure
  • Long-term institutional communication history

Core Principles

Local Ownership

Each node operates independently and maintains control over its local users, policies, data, archives, and infrastructure.

Optional Federation

Federation is optional. A node can operate independently or establish controlled relationships with other nodes.

Participant-Controlled Encryption

Communication content is end-to-end encrypted. Authorized participants and their authorized devices control the cryptographic capability required to decrypt their conversations.

Persistent History

Authorized participation history can be retained locally and across independently selected storage providers for long-term retrieval.

Data Portability

Communication history, archives, identities, and related data should remain portable between compatible nodes and storage providers.

Modular Design

Core capabilities are separated into modules so that implementations can enable, disable, replace, or extend individual capabilities.

Host Autonomy

Each host establishes its own identity, privacy, federation, storage, retention, and participation policies.

Infrastructure Independence

Communication services, storage services, AI services, and federation relationships do not need to be operated by the same provider.


Core Modules

Identity Module

The Identity Module manages participant identities and identity policies.

Features include:

  • Unique network identities
  • Host-controlled naming conventions
  • Organization-controlled naming conventions
  • Verified identities
  • Pseudonymous identities
  • Anonymous identities where permitted
  • Local identity namespaces
  • Cross-federation identity resolution
  • Identity verification
  • Participant cryptographic identities
  • Device identities
  • Identity permissions
  • Identity visibility controls

The module must allow each host to determine how identities are created, formatted, verified, exposed, and managed.

Authentication Module

The Authentication Module manages participant authentication and access to local services.

Features include:

  • Local authentication
  • Credential management
  • Secure session management
  • Account recovery mechanisms
  • Device authorization
  • Trusted-device management
  • Device revocation
  • Multi-factor authentication support
  • Security key support where implemented

Authentication credentials must not be treated as plaintext encryption keys.

Key Management Module

The Key Management Module manages cryptographic material used to protect participant identities, devices, conversations, attachments, and archives.

Features include:

  • Account encryption keys
  • Identity keys
  • Device keys
  • Conversation keys
  • Attachment encryption keys
  • Archive encryption keys
  • Secure key derivation
  • Key rotation
  • Device key authorization
  • Device key revocation
  • Conversation key rotation
  • Membership-change key rotation
  • Encrypted key backup
  • Key recovery mechanisms
  • Cryptographic identity verification

User credentials may be used to unlock protected cryptographic key material through appropriate key derivation mechanisms. Credentials must not be transmitted to federation or storage providers as a means of obtaining plaintext conversation keys.

Communication Module

The Communication Module provides the primary communication capabilities.

Features include:

  • Direct messaging
  • Group messaging
  • Public conversations
  • Private conversations
  • Federated conversations
  • Organization-to-organization conversations
  • Peer-to-peer conversations
  • Multi-organization conversations
  • Replies
  • Threads
  • Mentions
  • Reactions
  • Message editing
  • Configurable message deletion
  • Message delivery status
  • Message read status
  • Notifications
  • File attachments

Communication events must be represented in a form suitable for local storage, synchronization, archival, and federation.

Conversation Module

The Conversation Module manages conversation membership, permissions, metadata, and history.

Features include:

  • Conversation creation
  • Conversation membership
  • Conversation invitations
  • Participant management
  • Organization participation
  • Host participation
  • Conversation permissions
  • Conversation-specific encryption
  • Conversation history
  • Conversation archival
  • Conversation export
  • Conversation migration

Conversation permissions must be independently configurable from broader host permissions.

Contact Module

The Contact Module manages persistent relationships between participants and organizations.

Features include:

  • Personal contacts
  • Organization contacts
  • Federated contacts
  • Peer contacts
  • Customer contacts
  • Vendor contacts
  • Partner contacts
  • Contact groups
  • Relationship metadata
  • Contact verification
  • Shared conversation history
  • Contact discovery controls
  • Contact visibility controls

Contacts may retain references to communication history without granting access to conversations for which the participant is not authorized.

Federation Module

The Federation Module manages connections between independently operated nodes.

Features include:

  • Host-to-host federation
  • Business-to-business federation
  • Peer federation
  • Federation requests
  • Federation approvals
  • Federation rejection
  • Federation revocation
  • Trust relationships
  • Federation permissions
  • Capability-based federation
  • Selective federation
  • Cross-federation identity resolution
  • Federated conversation participation
  • Federated event synchronization
  • Federated history synchronization
  • Federation health monitoring

Federation must not require a node to surrender control of its local users, archives, encryption keys, or unrelated conversations.

Federation Contract Module

The Federation Contract Module defines the capabilities permitted between connected nodes.

Features include:

  • Connection identity
  • Connection status
  • Trust designation
  • Permitted communication types
  • Permitted file exchange
  • Permitted history synchronization
  • Directory visibility
  • Archive permissions
  • AI permissions
  • Storage permissions
  • Data retention terms
  • Connection expiration
  • Connection revocation

A federation relationship should allow individual capabilities to be approved independently.

Synchronization Module

The Synchronization Module manages the exchange and reconciliation of authorized communication events between nodes.

Features include:

  • Event synchronization
  • Message synchronization
  • Conversation synchronization
  • Attachment synchronization
  • Historical event retrieval
  • Missing-event recovery
  • Reconnection synchronization
  • Conflict handling
  • Synchronization status
  • Synchronization integrity verification
  • Selective synchronization
  • Permission-aware synchronization

Synchronization must not transmit content to nodes that lack authorization to possess or decrypt that content.

End-to-End Encryption Module

The End-to-End Encryption Module protects communication content from unauthorized infrastructure access.

Features include:

  • End-to-end encrypted messages
  • End-to-end encrypted conversations
  • End-to-end encrypted attachments
  • End-to-end encrypted archives
  • Participant-controlled decryption capability
  • Device-specific cryptographic keys
  • Conversation-specific encryption keys
  • Key rotation
  • Membership-change key rotation
  • Device revocation
  • Cryptographic integrity verification
  • Forward secrecy capable architecture

Federation hosts, storage hosts, network operators, and other infrastructure providers must not receive usable plaintext conversation keys merely because they transport or store encrypted content.

Archive Module

The Archive Module maintains persistent historical records of authorized participation.

Features include:

  • Local conversation archives
  • Federated conversation archives
  • Participant-local history
  • Long-term retention
  • Configurable retention policies
  • Permanent archival options
  • Archive integrity verification
  • Archive replication
  • Archive restoration
  • Archive export
  • Archive migration
  • Historical conversation retrieval
  • Encrypted archive storage

The archive must remain associated with the data owner’s permissions and encryption controls rather than becoming the property of the infrastructure provider.

Search Module

The Search Module provides retrieval of authorized communication history.

Features include:

  • Keyword search
  • Phrase search
  • Participant search
  • Organization search
  • Conversation search
  • Date search
  • Date-range search
  • Attachment search
  • Message-type filtering
  • Combined search criteria
  • Historical archive search
  • Federated history search where authorized
  • Local encrypted search indexes

Search operations must respect conversation, participant, archive, and federation permissions.

Search functionality should allow queries such as:

  • Messages containing a specified keyword
  • Messages from a specific participant
  • Messages involving a specific organization
  • Messages within a specified date range
  • Attachments associated with a conversation
  • Historical conversations involving a particular contact

Storage Module

The Storage Module manages local and remote storage used by communication nodes.

Features include:

  • Local storage
  • Remote storage
  • Federated storage
  • Active storage
  • Archive storage
  • Deep archive storage
  • Storage redundancy
  • Geographic redundancy
  • Storage capacity monitoring
  • Storage health monitoring
  • Encrypted storage
  • Storage migration
  • Storage replication
  • Archive restoration

Storage providers must not require access to plaintext communication content in order to provide storage services.

Storage Hosting Module

The Storage Hosting Module allows participating hosts to offer storage capacity to other network participants.

Features include:

  • Storage capacity offers
  • Storage provider profiles
  • Storage availability
  • Storage duration
  • Storage pricing
  • Storage redundancy options
  • Geographic storage options
  • Encrypted archive hosting
  • Storage contracts
  • Storage migration
  • Provider replacement
  • Storage health reporting

Hosts may independently provide storage without becoming the owner of the stored communication data.

Storage Contract Module

The Storage Contract Module manages one-time, fixed-term, and perpetual storage arrangements.

Supported arrangements include:

  • One-year storage
  • Multi-year storage
  • Five-year storage
  • Ten-year storage
  • Custom-duration storage
  • Perpetual storage

Storage contracts may define:

  • Capacity
  • Duration
  • Price
  • Number of copies
  • Geographic requirements
  • Availability requirements
  • Migration rights
  • Data ownership
  • Encryption requirements
  • Provider responsibilities

Perpetual storage should represent an arrangement without a scheduled expiration while remaining subject to the continued operation of the storage provider and the network’s migration mechanisms.

Storage Replication Module

The Storage Replication Module maintains multiple copies of encrypted archives.

Features include:

  • Multiple storage providers
  • Configurable replica count
  • Independent replica locations
  • Replica health monitoring
  • Replica integrity verification
  • Automatic replacement of unavailable replicas where configured
  • Archive recovery
  • Geographic redundancy
  • Provider redundancy

Storage Migration Module

The Storage Migration Module allows encrypted archives to move between storage providers.

Features include:

  • Provider replacement
  • Archive migration
  • Provider failure recovery
  • Contract expiration migration
  • Storage expansion
  • Storage reduction
  • Replica relocation
  • Integrity verification after migration
  • Migration status reporting

Migration must preserve encryption controls and data ownership.

AI Assistant Module

The AI Assistant Module provides assistance using information the participant is authorized to access.

Features include:

  • Communication Q&A
  • Archive Q&A
  • Conversation summarization
  • Project summarization
  • Historical information retrieval
  • Search assistance
  • Action-item extraction
  • Decision extraction
  • Commitment identification
  • Question identification
  • Topic identification
  • Conversation classification
  • Archive analysis

The AI assistant should operate against the participant’s authorized information rather than receiving unrestricted access to the node.

AI Permission Module

The AI Permission Module controls what information AI services can access.

Features include:

  • User-level AI permissions
  • Conversation-level AI permissions
  • Organization-level AI permissions
  • Archive-level AI permissions
  • Federated AI permissions
  • Local AI processing
  • Optional remote AI processing
  • AI access auditing
  • AI data handling policies

AI services must not bypass existing communication or archive permissions.

Federated AI Module

The Federated AI Module enables controlled AI interactions across independent nodes.

Features include:

  • Permissioned AI-to-AI requests
  • Cross-organization AI queries
  • Federated knowledge requests
  • Remote information retrieval
  • Explicit AI federation permissions
  • Organization-level AI policies
  • User-level AI policies
  • Conversation-level AI policies
  • Federated AI audit records

Remote AI access must require explicit authorization and must not provide unrestricted access to a remote archive.

Administration Module

The Administration Module provides host-level management.

Features include:

  • User management
  • Organization management
  • Group management
  • Identity policies
  • Conversation management
  • Federation management
  • Storage management
  • Archive management
  • AI management
  • Security policies
  • Retention policies
  • Privacy policies
  • Host configuration
  • Service configuration

Permission Module

The Permission Module provides granular access control throughout the system.

Permission scopes may include:

  • Host
  • Organization
  • User
  • Group
  • Conversation
  • Message
  • Attachment
  • Archive
  • Storage
  • Federation
  • AI
  • Device

Permissions must be independently enforceable across local and federated environments.

Privacy Policy Module

The Privacy Policy Module allows each host to determine how information is exposed.

Features include:

  • User discoverability controls
  • Organization discoverability controls
  • Directory visibility
  • Anonymous participation policies
  • External messaging policies
  • Federation visibility
  • Contact visibility
  • Archive visibility
  • AI visibility
  • Metadata exposure controls

Audit Module

The Audit Module maintains records of security-sensitive and administrative events.

Features include:

  • Administrative actions
  • Permission changes
  • Federation changes
  • Device authorization
  • Device revocation
  • Archive operations
  • Storage migrations
  • Storage changes
  • AI access events
  • Security events
  • Policy changes
  • Audit integrity verification

Data Portability Module

The Data Portability Module allows participants to retain control of their data when changing infrastructure.

Features include:

  • Conversation export
  • Archive export
  • Contact export
  • Identity export
  • Configuration export
  • Storage migration
  • Node migration
  • Archive restoration
  • Backup and recovery
  • Compatible data interchange

Network Directory Module

The Network Directory Module provides controlled discovery of participating network resources.

Features include:

  • Host discovery
  • Organization discovery
  • User discovery
  • Service discovery
  • Storage provider discovery
  • Federation capability discovery
  • Host capability information
  • Privacy-controlled directory visibility

Optional Plugin Modules

Optional plugins extend the core system without making their capabilities mandatory for every implementation.

Calendar Plugin

Features may include:

  • Shared calendars
  • Federated calendars
  • Event invitations
  • Scheduling
  • Availability information
  • Calendar-based conversation references
  • Calendar search

Task Management Plugin

Features may include:

  • Tasks
  • Assignments
  • Deadlines
  • Status tracking
  • Conversation-linked tasks
  • Federated task collaboration
  • AI-generated task suggestions

Document Collaboration Plugin

Features may include:

  • Shared documents
  • Federated document access
  • Document versioning
  • Document permissions
  • Encrypted document storage
  • Conversation-linked documents

File Storage Plugin

Features may include:

  • Persistent file storage
  • Federated file sharing
  • File versioning
  • File permissions
  • Encrypted files
  • Archive integration
  • Storage-provider integration

Voice Communication Plugin

Features may include:

  • Encrypted voice communication
  • Peer-to-peer voice sessions
  • Federated voice sessions
  • Group voice sessions
  • Voice recording where permitted
  • Voice archive integration

Video Communication Plugin

Features may include:

  • End-to-end encrypted video communication
  • Peer-to-peer video sessions
  • Federated video sessions
  • Group video sessions
  • Screen sharing
  • Recording where permitted

Workflow Plugin

Features may include:

  • Automated workflows
  • Event-triggered actions
  • Federation-triggered workflows
  • Communication-triggered workflows
  • Archive-triggered workflows
  • Administrative workflows
  • Approval workflows

External Service Integration Plugin

Features may include:

  • Third-party service connectors
  • API integrations
  • Federated service connections
  • Controlled data exchange
  • Permission-aware integrations
  • Integration auditing

Storage Marketplace Plugin

Features may include:

  • Storage provider discovery
  • Storage offers
  • Storage comparison
  • Storage contract management
  • Capacity purchasing
  • Provider reputation information
  • Migration management

AI Model Plugin

Features may include:

  • Local AI model integration
  • Alternative AI model providers
  • Model selection
  • Model-specific permissions
  • Local inference
  • Remote inference
  • AI model management

Analytics Plugin

Features may include:

  • Communication analytics
  • Organizational analytics
  • Storage analytics
  • Network analytics
  • Federation analytics
  • Archive analytics
  • Configurable privacy controls

Translation Plugin

Features may include:

  • Message translation
  • Conversation translation
  • Federated translation
  • Local translation models
  • Permission-aware translation

Notification Plugin

Features may include:

  • Advanced notifications
  • External notifications
  • Custom notification rules
  • Event-based notifications
  • Federation notifications
  • Storage notifications
  • Security notifications

Display and Interface

The interface should provide a unified view of local and authorized federated activity.

Primary interface areas should include:

  • Network
  • Contacts
  • Conversations
  • Organizations
  • Channels or groups
  • Archive
  • Search
  • AI Assistant
  • Storage
  • Federation
  • Notifications
  • Administration
  • Security
  • Devices

The interface should clearly distinguish:

  • Local participants
  • Federated participants
  • Local conversations
  • Federated conversations
  • Encrypted content
  • Archive content
  • Storage providers
  • AI access
  • Administrative information
  • Connection status
  • Permission status

Security and federation status should be visible without exposing sensitive cryptographic material.

Intended Network Model

A MeshUnion network consists of independently operated nodes.

A node may contain:

  • Users
  • Organizations
  • Conversations
  • Contacts
  • Archives
  • Storage
  • AI services
  • Federation relationships
  • Local policies

Nodes may communicate directly when permitted.

Nodes may also use independent storage providers while retaining ownership and encryption control over their archives.

A network does not require a central authority to operate communication between participating nodes.

Intended Economic Model

The core system is designed to operate without mandatory recurring platform charges.

Network participants may independently purchase infrastructure services from participating hosts.

Possible transactions include:

  • One-time storage purchases
  • Fixed-duration storage
  • Perpetual storage
  • Storage redundancy
  • Managed hosting
  • Infrastructure services
  • AI processing
  • Migration services
  • Backup services
  • Professional support

Infrastructure providers may establish their own pricing and service terms.

The communication network should not require users to purchase recurring access from a central platform provider.

Security Requirements

Implementations must prioritize:

  • End-to-end encryption
  • Participant-controlled keys
  • Secure authentication
  • Secure key management
  • Cryptographic identity verification
  • Permission enforcement
  • Encrypted storage
  • Secure federation
  • Secure synchronization
  • Archive integrity
  • Device authorization
  • Device revocation
  • Secure migration
  • Auditability

Implementations should use established cryptographic algorithms, protocols, and libraries rather than implementing cryptographic primitives independently.

Data Ownership Requirements

Implementations should ensure that:

  • Participants retain ownership of their communication data.
  • Storage providers do not become owners of stored archives.
  • Federation providers do not automatically gain access to unrelated communications.
  • Encryption keys remain under participant or authorized organizational control.
  • Archives remain portable.
  • Storage providers can be replaced.
  • Nodes can be migrated.
  • Communication history can be exported.
  • Authorized users can retrieve historical participation records.

Specification Branding License (SBL)

Standard

  • Fully AGPL-3.0+ compliant system
  • Copyleft enforced for network deployments
  • Required attribution:

Optional


License & Notice Requirements

MeshUnion is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

By contributing to any Open Arsenal project, you agree that your contributions will also be released under this license.

Please note the following:

  • All contributions must comply with the AGPL-3.0+ terms.
  • Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to Roxanne Ardary and roxanneardary.com.
  • MeshUnion specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
  • The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update notice.md.
  • When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
  • Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.

For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.


Notice – MeshUnion

Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.

Contributors

This file tracks contributors and their specific contributions to the project.

  • Roxanne Ardary, roxanneardary.com – August 18, 2026
    Created the repository for MeshUnion. Designed the federated, self-hosted communications architecture supporting end-to-end encryption, participant-controlled keys, persistent searchable archives, cross-federation connections, modular AI assistance, and independently provided one-time or perpetual storage.
  • [Add other contributors here] – [Date]
    [Describe contribution in one sentence]

License – MeshUnion

This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

Key Points

  • You are free to use, modify, and distribute the code.
  • All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
  • The software is provided “as is,” without warranty of any kind.

For the full license text, see GNU AGPL-3.0 License.