Evidence and risk■Verified evidence/△CautionMaterial claims checked against current sources.; those sources show trade-offs worth reading.
Last reviewedReviewed 27 Aug 2026KYC checked 27 Aug 2026 · unknown jurisdiction · Source → official siteHow to cite this pageSource coverageVerified evidenceRecorded riskCaution
CAUTIONLoRa traffic and node/location metadata can be observable. Channel AES-CTR uses a shared PSK without authentication, so anyone with the PSK can read traffic and impersonate a channel member. Direct messages on 2.5+ use x25519/AES-CCM when keys are known, but may fall back to less-secure channel encryption.
AUDITED BYNo audit listed
OPERATOR DATANo hosted operator data recorded
SOURCE COVERAGE
■Verified evidenceSELF-REPORTED2/2Reviewed 27 Aug 2026 · Source → official site
LAST CHECKED2026-08-27
LAST UPDATED2026-08-27
Specs
DOCUMENT CHECKNone recorded
IDENTITY EXPOSURELevel 0/4
KYC TRIGGERSNo account or identity KYC to use the open-source mesh protocol; hardware purchases, donations, app stores or business programs can identify the buyer/user.
FEEFree
NETWORKSHardware, LoRa, FOSS
CATEGORIESMessaging, Offline, Hardware
TORNot listed
REGIONSGlobal availability
Review analysis, source material, related services, and history
Analysis
OVERVIEW
Meshtastic is open-source LoRa mesh firmware for encrypted text messaging without cellular service or internet, built by a volunteer community alongside a separate Meshtastic Solutions business arm noted in its own documentation.
LIMITS
Radio transmissions are local and observable by design, and the record flags device IDs, Bluetooth and companion-app metadata, and regional radio-law compliance as OPSEC concerns that the open-source firmware does not remove.
USEFUL FOR
Off-grid, internet-independent text communication for users prepared to manage radio-level and app-level metadata themselves.
No identity verification is recorded for typical use. No account or identity KYC to use the open-source mesh protocol; hardware purchases, donations, app stores or business programs can identify the buyer/user.
Which payment methods are accepted?
Accepted payment methods: Hardware, LoRa, FOSS.
Where is it available?
Recorded availability: GLOBAL.
Is the operator based in a Five Eyes country?
Yes. The recorded jurisdiction is US, a Five Eyes country (US, UK, CA, AU, NZ). This is jurisdiction context and does not by itself establish that a service is safer or less safe.
How are identity, operator, and evidence fields reported?
Identity exposure is level 0 of 4. No hosted operator data is recorded. Jurisdiction is shown as context, not a safety verdict. Source coverage is verified evidence, last reviewed 2026-08-27, and recorded risk is caution.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.
Service history
Latest meaningful changes to the facts shown on this provider page.
Apply full-service rereview and score 4.0
Privacy warning, Recorded risk, Score assessment
Corporate registry information updated
Corporate / Entity type
Corporate registry information updated
Corporate
Full service history
updated
Reconcile score 4.0 evidence
Audited by
not set → none
Changed at
not set → 2026-08-27
Checked at
2026-06-23 → 2026-08-27
KYC last checked
2026-06-22 → 2026-08-27
Last reviewed
2026-06-22 → 2026-08-27
Source reviewed
official site → Primary-source review 2026-08-27
Score assessment / Control model
local-self-custody → decentralized
Score review
not set → Outcome: PASS; Checked at: 2026-08-27; Inputs: Operator data exposure: none; Control model: decentralized; Source model: open; Audit: Score eligible: no; Reason: No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family.
Radio use is local and observable; device IDs, Bluetooth/app metadata and regional radio-law compliance remain OPSEC concerns. → LoRa traffic and node/location metadata can be observable. Channel AES-CTR uses a shared PSK without authentication, so anyone with the PSK can read traffic and impersonate a channel member. Direct messages on 2.5+ use x25519/AES-CCM when keys are known, but may fall back to less-secure channel encryption.
Recorded risk
standard → caution
Score assessment
not set → Operator data exposure: none; Control model: local-self-custody; Source model: open
Open-source LoRa mesh networking for off-grid encrypted text communication without cellular service or internet. Official docs identify Meshtastic as an open-source project with a separate Meshtastic Solutions business arm. → Open-source LoRa mesh networking for off-grid encrypted text without cellular service or internet.
Open-source, decentralized mesh networking using inexpensive LoRa hardware devices. Enables long-range, off-grid encrypted text communication without cell service or internet. → Open-source LoRa mesh networking for off-grid encrypted text communication without cellular service or internet. Official docs identify Meshtastic as an open-source project with a separate Meshtastic Solutions business arm.
Jurisdiction
not set → ??
KYC last checked
2026-03-13 → 2026-06-22
Kyc note
Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR. → No account or identity KYC to use the open-source mesh protocol; hardware purchases, donations, app stores or business programs can identify the buyer/user.
Last reviewed
2026-03-13 → 2026-06-22
Privacy warning
not set → Radio use is local and observable; device IDs, Bluetooth/app metadata and regional radio-law compliance remain OPSEC concerns.
Source reviewed
older source, not independently verified → official site