Home / MeshUnion / MeshUnion Specification
MeshUnion
Your Keys. Your Conversations. Your Node.
MeshUnion is a modular, federated communications and archival infrastructure specification designed for individuals, businesses, organizations, and independently operated network hosts.
MeshUnion enables participants to communicate across independently operated nodes while maintaining control over their identities, encryption keys, conversations, archives, storage relationships, and federation policies.
The system is designed around local operation, optional federation, complete end-to-end encryption, persistent searchable communication history, participant-controlled data, and independently provided infrastructure.
Specification Goals
MeshUnion is designed to provide:
- Self-hosted communications infrastructure
- Federated communication between independent nodes
- Business-to-business communication
- Peer-to-peer communication
- Participant-controlled identities
- Complete end-to-end encryption
- Participant-controlled encryption keys
- Persistent communication archives
- Keyword and date-based historical search
- Local and federated archive synchronization
- Modular AI assistance
- Independent storage hosting
- One-time and long-duration storage purchasing
- Perpetual storage arrangements
- Data portability and migration
- Host-controlled policies
- No mandatory recurring platform charges
- Vendor-independent infrastructure
- Long-term institutional communication history
Core Principles
Local Ownership
Each node operates independently and maintains control over its local users, policies, data, archives, and infrastructure.
Optional Federation
Federation is optional. A node can operate independently or establish controlled relationships with other nodes.
Participant-Controlled Encryption
Communication content is end-to-end encrypted. Authorized participants and their authorized devices control the cryptographic capability required to decrypt their conversations.
Persistent History
Authorized participation history can be retained locally and across independently selected storage providers for long-term retrieval.
Data Portability
Communication history, archives, identities, and related data should remain portable between compatible nodes and storage providers.
Modular Design
Core capabilities are separated into modules so that implementations can enable, disable, replace, or extend individual capabilities.
Host Autonomy
Each host establishes its own identity, privacy, federation, storage, retention, and participation policies.
Infrastructure Independence
Communication services, storage services, AI services, and federation relationships do not need to be operated by the same provider.
Core Modules
Identity Module
The Identity Module manages participant identities and identity policies.
Features include:
- Unique network identities
- Host-controlled naming conventions
- Organization-controlled naming conventions
- Verified identities
- Pseudonymous identities
- Anonymous identities where permitted
- Local identity namespaces
- Cross-federation identity resolution
- Identity verification
- Participant cryptographic identities
- Device identities
- Identity permissions
- Identity visibility controls
The module must allow each host to determine how identities are created, formatted, verified, exposed, and managed.
Authentication Module
The Authentication Module manages participant authentication and access to local services.
Features include:
- Local authentication
- Credential management
- Secure session management
- Account recovery mechanisms
- Device authorization
- Trusted-device management
- Device revocation
- Multi-factor authentication support
- Security key support where implemented
Authentication credentials must not be treated as plaintext encryption keys.
Key Management Module
The Key Management Module manages cryptographic material used to protect participant identities, devices, conversations, attachments, and archives.
Features include:
- Account encryption keys
- Identity keys
- Device keys
- Conversation keys
- Attachment encryption keys
- Archive encryption keys
- Secure key derivation
- Key rotation
- Device key authorization
- Device key revocation
- Conversation key rotation
- Membership-change key rotation
- Encrypted key backup
- Key recovery mechanisms
- Cryptographic identity verification
User credentials may be used to unlock protected cryptographic key material through appropriate key derivation mechanisms. Credentials must not be transmitted to federation or storage providers as a means of obtaining plaintext conversation keys.
Communication Module
The Communication Module provides the primary communication capabilities.
Features include:
- Direct messaging
- Group messaging
- Public conversations
- Private conversations
- Federated conversations
- Organization-to-organization conversations
- Peer-to-peer conversations
- Multi-organization conversations
- Replies
- Threads
- Mentions
- Reactions
- Message editing
- Configurable message deletion
- Message delivery status
- Message read status
- Notifications
- File attachments
Communication events must be represented in a form suitable for local storage, synchronization, archival, and federation.
Conversation Module
The Conversation Module manages conversation membership, permissions, metadata, and history.
Features include:
- Conversation creation
- Conversation membership
- Conversation invitations
- Participant management
- Organization participation
- Host participation
- Conversation permissions
- Conversation-specific encryption
- Conversation history
- Conversation archival
- Conversation export
- Conversation migration
Conversation permissions must be independently configurable from broader host permissions.
Contact Module
The Contact Module manages persistent relationships between participants and organizations.
Features include:
- Personal contacts
- Organization contacts
- Federated contacts
- Peer contacts
- Customer contacts
- Vendor contacts
- Partner contacts
- Contact groups
- Relationship metadata
- Contact verification
- Shared conversation history
- Contact discovery controls
- Contact visibility controls
Contacts may retain references to communication history without granting access to conversations for which the participant is not authorized.
Federation Module
The Federation Module manages connections between independently operated nodes.
Features include:
- Host-to-host federation
- Business-to-business federation
- Peer federation
- Federation requests
- Federation approvals
- Federation rejection
- Federation revocation
- Trust relationships
- Federation permissions
- Capability-based federation
- Selective federation
- Cross-federation identity resolution
- Federated conversation participation
- Federated event synchronization
- Federated history synchronization
- Federation health monitoring
Federation must not require a node to surrender control of its local users, archives, encryption keys, or unrelated conversations.
Federation Contract Module
The Federation Contract Module defines the capabilities permitted between connected nodes.
Features include:
- Connection identity
- Connection status
- Trust designation
- Permitted communication types
- Permitted file exchange
- Permitted history synchronization
- Directory visibility
- Archive permissions
- AI permissions
- Storage permissions
- Data retention terms
- Connection expiration
- Connection revocation
A federation relationship should allow individual capabilities to be approved independently.
Synchronization Module
The Synchronization Module manages the exchange and reconciliation of authorized communication events between nodes.
Features include:
- Event synchronization
- Message synchronization
- Conversation synchronization
- Attachment synchronization
- Historical event retrieval
- Missing-event recovery
- Reconnection synchronization
- Conflict handling
- Synchronization status
- Synchronization integrity verification
- Selective synchronization
- Permission-aware synchronization
Synchronization must not transmit content to nodes that lack authorization to possess or decrypt that content.
End-to-End Encryption Module
The End-to-End Encryption Module protects communication content from unauthorized infrastructure access.
Features include:
- End-to-end encrypted messages
- End-to-end encrypted conversations
- End-to-end encrypted attachments
- End-to-end encrypted archives
- Participant-controlled decryption capability
- Device-specific cryptographic keys
- Conversation-specific encryption keys
- Key rotation
- Membership-change key rotation
- Device revocation
- Cryptographic integrity verification
- Forward secrecy capable architecture
Federation hosts, storage hosts, network operators, and other infrastructure providers must not receive usable plaintext conversation keys merely because they transport or store encrypted content.
Archive Module
The Archive Module maintains persistent historical records of authorized participation.
Features include:
- Local conversation archives
- Federated conversation archives
- Participant-local history
- Long-term retention
- Configurable retention policies
- Permanent archival options
- Archive integrity verification
- Archive replication
- Archive restoration
- Archive export
- Archive migration
- Historical conversation retrieval
- Encrypted archive storage
The archive must remain associated with the data owner’s permissions and encryption controls rather than becoming the property of the infrastructure provider.
Search Module
The Search Module provides retrieval of authorized communication history.
Features include:
- Keyword search
- Phrase search
- Participant search
- Organization search
- Conversation search
- Date search
- Date-range search
- Attachment search
- Message-type filtering
- Combined search criteria
- Historical archive search
- Federated history search where authorized
- Local encrypted search indexes
Search operations must respect conversation, participant, archive, and federation permissions.
Search functionality should allow queries such as:
- Messages containing a specified keyword
- Messages from a specific participant
- Messages involving a specific organization
- Messages within a specified date range
- Attachments associated with a conversation
- Historical conversations involving a particular contact
Storage Module
The Storage Module manages local and remote storage used by communication nodes.
Features include:
- Local storage
- Remote storage
- Federated storage
- Active storage
- Archive storage
- Deep archive storage
- Storage redundancy
- Geographic redundancy
- Storage capacity monitoring
- Storage health monitoring
- Encrypted storage
- Storage migration
- Storage replication
- Archive restoration
Storage providers must not require access to plaintext communication content in order to provide storage services.
Storage Hosting Module
The Storage Hosting Module allows participating hosts to offer storage capacity to other network participants.
Features include:
- Storage capacity offers
- Storage provider profiles
- Storage availability
- Storage duration
- Storage pricing
- Storage redundancy options
- Geographic storage options
- Encrypted archive hosting
- Storage contracts
- Storage migration
- Provider replacement
- Storage health reporting
Hosts may independently provide storage without becoming the owner of the stored communication data.
Storage Contract Module
The Storage Contract Module manages one-time, fixed-term, and perpetual storage arrangements.
Supported arrangements include:
- One-year storage
- Multi-year storage
- Five-year storage
- Ten-year storage
- Custom-duration storage
- Perpetual storage
Storage contracts may define:
- Capacity
- Duration
- Price
- Number of copies
- Geographic requirements
- Availability requirements
- Migration rights
- Data ownership
- Encryption requirements
- Provider responsibilities
Perpetual storage should represent an arrangement without a scheduled expiration while remaining subject to the continued operation of the storage provider and the network’s migration mechanisms.
Storage Replication Module
The Storage Replication Module maintains multiple copies of encrypted archives.
Features include:
- Multiple storage providers
- Configurable replica count
- Independent replica locations
- Replica health monitoring
- Replica integrity verification
- Automatic replacement of unavailable replicas where configured
- Archive recovery
- Geographic redundancy
- Provider redundancy
Storage Migration Module
The Storage Migration Module allows encrypted archives to move between storage providers.
Features include:
- Provider replacement
- Archive migration
- Provider failure recovery
- Contract expiration migration
- Storage expansion
- Storage reduction
- Replica relocation
- Integrity verification after migration
- Migration status reporting
Migration must preserve encryption controls and data ownership.
AI Assistant Module
The AI Assistant Module provides assistance using information the participant is authorized to access.
Features include:
- Communication Q&A
- Archive Q&A
- Conversation summarization
- Project summarization
- Historical information retrieval
- Search assistance
- Action-item extraction
- Decision extraction
- Commitment identification
- Question identification
- Topic identification
- Conversation classification
- Archive analysis
The AI assistant should operate against the participant’s authorized information rather than receiving unrestricted access to the node.
AI Permission Module
The AI Permission Module controls what information AI services can access.
Features include:
- User-level AI permissions
- Conversation-level AI permissions
- Organization-level AI permissions
- Archive-level AI permissions
- Federated AI permissions
- Local AI processing
- Optional remote AI processing
- AI access auditing
- AI data handling policies
AI services must not bypass existing communication or archive permissions.
Federated AI Module
The Federated AI Module enables controlled AI interactions across independent nodes.
Features include:
- Permissioned AI-to-AI requests
- Cross-organization AI queries
- Federated knowledge requests
- Remote information retrieval
- Explicit AI federation permissions
- Organization-level AI policies
- User-level AI policies
- Conversation-level AI policies
- Federated AI audit records
Remote AI access must require explicit authorization and must not provide unrestricted access to a remote archive.
Administration Module
The Administration Module provides host-level management.
Features include:
- User management
- Organization management
- Group management
- Identity policies
- Conversation management
- Federation management
- Storage management
- Archive management
- AI management
- Security policies
- Retention policies
- Privacy policies
- Host configuration
- Service configuration
Permission Module
The Permission Module provides granular access control throughout the system.
Permission scopes may include:
- Host
- Organization
- User
- Group
- Conversation
- Message
- Attachment
- Archive
- Storage
- Federation
- AI
- Device
Permissions must be independently enforceable across local and federated environments.
Privacy Policy Module
The Privacy Policy Module allows each host to determine how information is exposed.
Features include:
- User discoverability controls
- Organization discoverability controls
- Directory visibility
- Anonymous participation policies
- External messaging policies
- Federation visibility
- Contact visibility
- Archive visibility
- AI visibility
- Metadata exposure controls
Audit Module
The Audit Module maintains records of security-sensitive and administrative events.
Features include:
- Administrative actions
- Permission changes
- Federation changes
- Device authorization
- Device revocation
- Archive operations
- Storage migrations
- Storage changes
- AI access events
- Security events
- Policy changes
- Audit integrity verification
Data Portability Module
The Data Portability Module allows participants to retain control of their data when changing infrastructure.
Features include:
- Conversation export
- Archive export
- Contact export
- Identity export
- Configuration export
- Storage migration
- Node migration
- Archive restoration
- Backup and recovery
- Compatible data interchange
Network Directory Module
The Network Directory Module provides controlled discovery of participating network resources.
Features include:
- Host discovery
- Organization discovery
- User discovery
- Service discovery
- Storage provider discovery
- Federation capability discovery
- Host capability information
- Privacy-controlled directory visibility
Optional Plugin Modules
Optional plugins extend the core system without making their capabilities mandatory for every implementation.
Calendar Plugin
Features may include:
- Shared calendars
- Federated calendars
- Event invitations
- Scheduling
- Availability information
- Calendar-based conversation references
- Calendar search
Task Management Plugin
Features may include:
- Tasks
- Assignments
- Deadlines
- Status tracking
- Conversation-linked tasks
- Federated task collaboration
- AI-generated task suggestions
Document Collaboration Plugin
Features may include:
- Shared documents
- Federated document access
- Document versioning
- Document permissions
- Encrypted document storage
- Conversation-linked documents
File Storage Plugin
Features may include:
- Persistent file storage
- Federated file sharing
- File versioning
- File permissions
- Encrypted files
- Archive integration
- Storage-provider integration
Voice Communication Plugin
Features may include:
- Encrypted voice communication
- Peer-to-peer voice sessions
- Federated voice sessions
- Group voice sessions
- Voice recording where permitted
- Voice archive integration
Video Communication Plugin
Features may include:
- End-to-end encrypted video communication
- Peer-to-peer video sessions
- Federated video sessions
- Group video sessions
- Screen sharing
- Recording where permitted
Workflow Plugin
Features may include:
- Automated workflows
- Event-triggered actions
- Federation-triggered workflows
- Communication-triggered workflows
- Archive-triggered workflows
- Administrative workflows
- Approval workflows
External Service Integration Plugin
Features may include:
- Third-party service connectors
- API integrations
- Federated service connections
- Controlled data exchange
- Permission-aware integrations
- Integration auditing
Storage Marketplace Plugin
Features may include:
- Storage provider discovery
- Storage offers
- Storage comparison
- Storage contract management
- Capacity purchasing
- Provider reputation information
- Migration management
AI Model Plugin
Features may include:
- Local AI model integration
- Alternative AI model providers
- Model selection
- Model-specific permissions
- Local inference
- Remote inference
- AI model management
Analytics Plugin
Features may include:
- Communication analytics
- Organizational analytics
- Storage analytics
- Network analytics
- Federation analytics
- Archive analytics
- Configurable privacy controls
Translation Plugin
Features may include:
- Message translation
- Conversation translation
- Federated translation
- Local translation models
- Permission-aware translation
Notification Plugin
Features may include:
- Advanced notifications
- External notifications
- Custom notification rules
- Event-based notifications
- Federation notifications
- Storage notifications
- Security notifications
Display and Interface
The interface should provide a unified view of local and authorized federated activity.
Primary interface areas should include:
- Network
- Contacts
- Conversations
- Organizations
- Channels or groups
- Archive
- Search
- AI Assistant
- Storage
- Federation
- Notifications
- Administration
- Security
- Devices
The interface should clearly distinguish:
- Local participants
- Federated participants
- Local conversations
- Federated conversations
- Encrypted content
- Archive content
- Storage providers
- AI access
- Administrative information
- Connection status
- Permission status
Security and federation status should be visible without exposing sensitive cryptographic material.
Intended Network Model
A MeshUnion network consists of independently operated nodes.
A node may contain:
- Users
- Organizations
- Conversations
- Contacts
- Archives
- Storage
- AI services
- Federation relationships
- Local policies
Nodes may communicate directly when permitted.
Nodes may also use independent storage providers while retaining ownership and encryption control over their archives.
A network does not require a central authority to operate communication between participating nodes.
Intended Economic Model
The core system is designed to operate without mandatory recurring platform charges.
Network participants may independently purchase infrastructure services from participating hosts.
Possible transactions include:
- One-time storage purchases
- Fixed-duration storage
- Perpetual storage
- Storage redundancy
- Managed hosting
- Infrastructure services
- AI processing
- Migration services
- Backup services
- Professional support
Infrastructure providers may establish their own pricing and service terms.
The communication network should not require users to purchase recurring access from a central platform provider.
Security Requirements
Implementations must prioritize:
- End-to-end encryption
- Participant-controlled keys
- Secure authentication
- Secure key management
- Cryptographic identity verification
- Permission enforcement
- Encrypted storage
- Secure federation
- Secure synchronization
- Archive integrity
- Device authorization
- Device revocation
- Secure migration
- Auditability
Implementations should use established cryptographic algorithms, protocols, and libraries rather than implementing cryptographic primitives independently.
Data Ownership Requirements
Implementations should ensure that:
- Participants retain ownership of their communication data.
- Storage providers do not become owners of stored archives.
- Federation providers do not automatically gain access to unrelated communications.
- Encryption keys remain under participant or authorized organizational control.
- Archives remain portable.
- Storage providers can be replaced.
- Nodes can be migrated.
- Communication history can be exported.
- Authorized users can retrieve historical participation records.
Specification Branding License (SBL)
Standard
- Fully AGPL-3.0+ compliant system
- Copyleft enforced for network deployments
- Required attribution:
- Roxanne Ardary
- roxanneardary.com
Optional
- Specification Branding License (SBL)
- Attribution-free commercial deployment
- Pricing based on scale, usage, and deployment scope
- https://roxanneardary.com/meshunion/
License & Notice Requirements
MeshUnion is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
By contributing to any Open Arsenal project, you agree that your contributions will also be released under this license.
Please note the following:
- All contributions must comply with the AGPL-3.0+ terms.
- Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to Roxanne Ardary and roxanneardary.com.
- MeshUnion specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
- The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update
notice.md. - When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
- Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.
For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.
Notice – MeshUnion
Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.
Contributors
This file tracks contributors and their specific contributions to the project.
- Roxanne Ardary, roxanneardary.com – August 18, 2026
Created the repository for MeshUnion. Designed the federated, self-hosted communications architecture supporting end-to-end encryption, participant-controlled keys, persistent searchable archives, cross-federation connections, modular AI assistance, and independently provided one-time or perpetual storage. - [Add other contributors here] – [Date]
[Describe contribution in one sentence]
License – MeshUnion
This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
Key Points
- You are free to use, modify, and distribute the code.
- All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
- The software is provided “as is,” without warranty of any kind.
For the full license text, see GNU AGPL-3.0 License.
