Sealed for local roots
Before broadcast, direct messages are Ed25519-signed and sealed with ephemeral X25519 + ChaCha20-Poly1305. The backend receives ciphertext without account names or a stable recipient-key ID. Direct delivery stays inside one operator’s local PKI. Panetière can mix envelopes from multiple OSCAR servers, but their trusted PKIs remain separate; this is not cross-server key federation or client-to-client end-to-end encryption.