SecChat — auditable team + agentic chat¶
SecChat is auditable team chat and agentic chat in one app, for CUI / air-gapped enclaves — people talk to each other, spawn governed coding/assistant agents, hold voice and video calls, and every message is tamper-evidently logged.
What it does¶
Auditable by construction — every message links into a per-channel SHA-256 hash chain bound to the content hash (not the plaintext), plus a metadata-only audit chain; tampering is detectable and CUI spillage stays purgeable.
Agents are first-class and governed — spawn a SecAgent tied to you; it runs in plan mode by default, and only you can authorize code-executing work. Its model calls run through SecRouter, attributed and budgeted to you.
SSO from the ground up — every session is a SecSSO (Authentik) session, validated via JWKS. No local passwords.
Native voice & video calling — 1:1 and group calls ride the same WebRTC signaling as the chat WebSocket hub. Video is live-only: camera and screen share work during a call but are never recorded. A consented call is recorded audio-only by the
secchat-mediadrelay, then transcribed via SecRecorder into a speaker-exact transcript and posted to the channel with a best-effort LLM summary — either can be corrected afterward as a normal, chain-bound message revision.Optional Kubernetes agent pool — runs a coding agent in a server-launched, ephemeral pod instead of the user’s desktop; the execute-gate stays on the server either way.
Light/dark theme — a top-bar toggle switches the whole app, remembered across launches.
Quickstart¶
cp .env.example .env
# set SECCHAT_OIDC_ISSUER / SECCHAT_OIDC_AUDIENCE (SecSSO) and PG_PASSWORD
./bootstrap/secchat.sh up # build + start, wait for /healthz, print the wiring readout
Learn more¶
SecChat on GitHub — source, issues, releases.
SecChat docs — configuration, a user-facing usage tour, the auth/marking/audit security model, and the CMMC control mapping.