Home / Privacy / Server code

Signal publishes its server code, but can you verify what's actually running?

Published: October 7, 2026 · Updated: October 8, 2026

Yes, Signal publishes its server code publicly. Anyone can read it, copy it, and even run their own copy. That is genuinely unusual among major messaging apps. But there is an honest limit: nobody outside Signal can verify that the servers currently handling your messages were built from that published code. This guide gives the balanced picture: what is actually open, what the publication proves, where verification stops, and why the limit is not a reason to panic.

Download the official Signal APK

from Signal's official site — file hosted by Signal, not by us

A server rack beside an open book, representing published server code that cannot be independently verified as deployed

What Signal actually publishes

Signal's server software is published in its public code repositories, under an open-source license, where anyone can read it. This is not a partial dump or a marketing gesture: the publication includes the code that routes messages, manages accounts, and handles the parts of the system users never see. You can clone it, study it, and run your own instance of it on your own hardware.

For context on how unusual this is: most major messaging apps publish no server code at all. Their servers are pure black boxes. Signal sits at the opposite end of the industry spectrum. Our open-source explainer walks through the client-side code, which is even more transparent thanks to reproducible builds; this page is about the server side specifically.

Publishing the server code does two concrete things:

Flow of published repositories: client apps and server code published openly
Clients, servers, and protocol code are all public. The transparency is real.

What publishing the server code proves

The published code answers a specific question: what is this software designed to do? And the answer, readable by anyone, is reassuring on the points that matter most:

These are not promises. They are inspectable facts about published code. That distinction is the whole point of publishing it.

The honest limit: verifying the deployment

Here is the caveat, stated plainly: reading the code tells you what the software does. It does not tell you which software is running on Signal's servers right now. There is no technical mechanism that lets an outsider confirm that the servers currently handling your messages were built from the published code, unmodified.

This is not a Signal-specific failure. It is a property of all centralized services:

Keep this in proportion. The deployment-verification gap is real, and honest writing should name it. But it is the same gap every centralized service on earth has, and Signal narrows it further than anyone else by publishing the code and designing the crypto to distrust the server.

Frequently asked questions

Is Signal's server code open source?

Yes. Signal publishes its server code publicly under an open-source license. Anyone can read it, copy it, and run their own instance of it.

Can I verify that Signal's servers run the published code?

No. Nobody outside Signal can confirm what software the live servers currently run. This is an inherent limit of all centralized services. A remote machine's software is unobservable by design.

Does the verification gap mean Signal could be reading my messages?

No. Message content is encrypted on your device with keys the server never holds, so even a dishonest server could not open the messages. The worst a rogue server could do is metadata-level misbehavior, like logging connection patterns.

Why publish server code if the deployment can't be verified?

Because the published code lets experts inspect the design and confirm there is no message storage or key escrow built in, and it lets anyone run their own instance to study its behavior. It is the maximum transparency the architecture allows.

Do other messaging apps publish their server code?

Almost none do. Most major messaging apps publish no server code at all, making their servers pure black boxes. Signal is at the opposite end of the industry spectrum.

What is reproducible builds and does it cover the server?

Reproducible builds let outsiders verify that a compiled app matches its published source code. They cover Signal's clients (including Android), not the servers. Servers cannot be verified that way because you never download a server binary.

Client code vs server code: the transparency gap

QuestionClient (the app on your phone)Server (Signal's machines)
Is the code public?YesYes
Can outsiders audit it?Yes. commissioned audits existYes. Anyone can read it
Can you verify the build you use?Yes, via reproducible buildsNo. Remote machines are unverifiable by design
Can it read your messages?It holds your keys by necessityNo. It never holds the keys
Worst realistic misbehaviorMalicious update exfiltrating keysMetadata logging, traffic analysis
Who watches itYou, auditors, researchersResearchers reading the published code

The table's bottom line: the client side is where verification is strongest and where the keys live, so that is where scrutiny matters most. The server side is less verifiable but also less powerful, because the encryption was built on the assumption that the server might be hostile.

Comparison of client code transparency versus server deployment verifiability
You can verify the app on your phone; you cannot verify what runs on the server.

Why the limit exists (and why it is not a scandal)

It helps to understand why nobody has solved deployment verification, so the caveat reads as engineering reality rather than suspicion:

Be skeptical of anyone who presents the deployment gap as a Signal scandal while recommending an app that publishes nothing at all. That is not analysis; it is marketing wearing a trench coat.

What you can still check for yourself

The verification story is not "trust us." There are concrete things you, or experts you trust, can actually do:

Checklist of what you can verify yourself: reproducible builds, published source, third-party audits
You cannot audit the servers, but you can verify the app in your hand.

The bottom line

Signal's server transparency is the best in the industry and still incomplete, and both halves of that sentence are true at once. The code is public, the design is inspectable, the cryptography distrusts the server by default, and the deployment cannot be independently verified, which is true of every centralized service ever built. If someone tells you the published code means the servers are proven safe, they are overselling. If someone tells you the verification gap means Signal is untrustworthy, ask them what their preferred app publishes. Then watch the conversation end.

Keep reading

Download the official Signal APK

from Signal's official site — file hosted by Signal, not by us