Start from your threats, not from the app's promises
Published: October 7, 2026 · Updated: October 8, 2026
A threat model is just an honest list: who are you worried about, what can they do, and does your app actually stop them? Signal is superb protection against some adversaries: your internet provider reading your messages, a hacker intercepting traffic, a company mining your chats for ads. It is honest-to-goodness inadequate against others, like someone with physical access to your unlocked phone or a government that can compel you to unlock it. Most privacy advice fails because it starts with the tool ("use Signal!") instead of the threat ("who am I actually worried about?"). This guide flips that: name your adversary first, then check what Signal does and does not cover at each level.
You do not need security training to do this. You need five minutes, a piece of paper or this page, and the willingness to be specific instead of vague. "I want to be private" is not a threat model. "I don't want my employer reading my chats" is. Let us build yours.
Why bother with a threat model
Because security is always a trade-off, and you cannot make a good trade-off without knowing what you are trading for. The person who wants to keep their chats away from an advertiser needs different protection than the person hiding from an abusive partner, who needs different protection than a journalist protecting a source from a state intelligence agency. All three might install Signal. For the first two, that is probably the whole answer. For the third, Signal is one layer in a much bigger plan.
Skipping this step produces two classic mistakes. The first is under-protection: assuming the app's reputation covers threats it was never designed for, like a stolen unlocked phone. The second is over-protection: burning hours on elaborate setups against adversaries that do not exist in your life, while ignoring the real weak point: usually the people you talk to, or your own unlocked screen. A threat model kills both mistakes at once.
Here is the framework security professionals use, stripped of jargon: (1) name the adversary, (2) describe what they can realistically do, (3) ask whether your tools stop that, (4) fill the gaps. The rest of this page walks you through it with Signal as the tool under examination.
The five levels of adversary
Not every "bad guy" is the same kind of bad guy. These five levels cover the realistic range, from the mundane to the extreme. Most readers live at levels 1–3; levels 4–5 are for people with genuinely dangerous adversaries.
| Level | Adversary | What they can do |
|---|---|---|
| 1 | Nosy people around you: friends, family, coworkers | Glance at your screen, pick up your unlocked phone, ask "who was that?" |
| 2 | Companies and data brokers: advertisers, analytics firms | Collect, profile, and sell behavioral data at scale; cannot read encrypted content |
| 3 | Your network observers: ISP, employer Wi-Fi admin, café network | See which domains you connect to and when; on work networks, sometimes much more |
| 4 | Determined individuals: abusive ex, stalker, targeted hacker | Social engineering, phishing, device theft, spyware, physical access |
| 5 | State actors: police, intelligence agencies | Legal compulsion, large-scale surveillance, targeted device hacking, network taps |
The key insight: each level up changes the game, not just the difficulty. Level 2 is defeated by encryption; level 4 is defeated by device security and human judgment; level 5 is defeated by operational discipline that no app can provide alone. Signal's strength is concentrated at levels 2–3, with real but limited help at 1 and 4, and honest limits at 5.
What Signal handles at each level
Level by level, here is where Signal genuinely earns its reputation:
- Level 1: nosy people. Signal helps through the basics: the app can require your phone's screen lock or biometrics to open, notifications can hide message content, and disappearing messages limit how much old content sits on the device. But this is the level where the app matters least and you matter most. An unlocked phone in someone else's hands defeats everything. Our screenshot guide covers the related "who can capture my chats" question.
- Level 2: companies and data brokers. This is Signal's home turf, and it is where the app is hardest to beat. Messages are end-to-end encrypted, so no company in the middle can read them. Signal's business model has no advertising, so there is no incentive to profile you. The service is designed to store as little as possible. It does not keep your messages, your contacts, or a social graph of who talks to whom. See our metadata breakdown for exactly what the service does retain (very little) and why that matters.
- Level 3: network observers. Your internet provider or the admin of the Wi-Fi you are on can see that you connect to Signal's servers and roughly when. They cannot see message contents, recipients, or anything inside the encrypted tunnel. For most people this is a complete win. The ISP goes from "reads everything" to "sees you use an encrypted messenger." If even that connection pattern is sensitive (some countries treat Signal usage itself as suspicious), Signal's built-in proxy support lets you route around blocks. Our proxy guide walks through it.
- Level 4: determined individuals. Partial help. Encryption still protects messages in transit, and features like registration lock make it harder for someone to hijack your number and take over your account. But a level-4 adversary attacks the endpoints, your phone, your judgment, not the encryption. Phishing you, stealing your unlocked phone, or installing spyware on it bypasses every protection Signal offers. At this level Signal is necessary but nowhere near sufficient; the device and the human are the battlefield.
- Level 5: state actors. Honest answer: Signal's encryption holds up, there is no known backdoor and the protocol is publicly audited, but states rarely attack the encryption. They attack the phone (targeted spyware), the person (compelled unlock, coercion of contacts), or the metadata around the edges (who uses Signal, when, from where). Against those, Signal reduces your exposure but cannot eliminate it. Anyone at this level needs professional operational-security guidance, not an app store download.
Where Signal's protection stops
This is the section most "why Signal is great" articles skip. Signal does not protect you against:
- Your own unlocked device. Whoever holds your unlocked phone reads everything: messages, photos, contacts. Screen lock, biometrics, and not handing your phone to people are the entire defense here.
- The recipient. The person you message can screenshot, forward, or read your words aloud. Encryption protects the journey, not the destination. (Our screenshot guide is blunt about this.)
- Malware on your phone. Spyware sees your screen and your keystrokes before Signal ever encrypts anything. No messenger survives a compromised operating system.
- Being compelled to unlock. In many places, authorities can legally require you to unlock your phone, or coerce the people around you. Encryption you can be forced to undo is encryption in name only.
- Network-level observation of usage. Observers see that you use Signal and when. Sealed sender reduces some of this, but the fact of connection remains visible.
- Backups you make yourself. If you back up your phone to a cloud account, your Signal data may ride along into a backup protected by weaker security than Signal itself. Your threat model has to include everywhere your data copies itself.
- Your contacts' security. Your messages are only as safe as the least careful person in the chat. A group of five where one member has a compromised phone is a compromised group.
None of these are flaws in Signal. They are the boundaries of what any messenger can do. The app secures the channel; everything at the ends of the channel is yours to secure.
from Signal's official site — file hosted by Signal, not by us
When Signal is not enough
Concrete cases where "just use Signal" is the wrong answer on its own:
- An abusive partner with access to your phone. The threat is physical access and coercion, not interception. What matters: a device they cannot open, accounts they do not know about, and, most importantly, real-world safety planning with people who do this work. An app cannot fix a threat that lives in your house.
- A journalist protecting a source from a state. Signal is likely part of the answer, but the plan also needs secure devices, careful meeting practices, and source-handling tradecraft. One encrypted app among sloppy habits protects nothing.
- A workplace organizer on a company-managed phone. Company device-management software can see everything on the phone, including Signal. The fix is a separate personal device, not a better app on the monitored one.
- Someone under targeted spyware attack. If your phone is compromised, switching messengers is rearranging deck chairs. The fix is a clean device and expert help.
- Illegal activity. Let us be direct: Signal is a privacy tool, not a crime tool, and we do not advise on evading law enforcement. If your "threat model" is the police investigating a crime, no app is the answer and this guide is not for you.
The pattern: whenever the adversary can reach your device or your person, the messenger is downstream of the real problem. Fix the device and the human situation first; the app choice is secondary.
Complements, not replacements
No product endorsements here. Just the categories of protection that sit alongside a messenger in a serious setup:
- Device security. Current OS, automatic updates, strong screen lock, full-disk encryption (standard on modern phones). This is the foundation everything else stands on.
- Account hygiene. Registration lock on Signal (stops number-hijack account takeovers), two-factor authentication on your email and other accounts, unique passwords. Our registration lock guide covers Signal's side.
- Network privacy tools. A trustworthy VPN or Tor for hiding which services you use from local observers, relevant at level 3 when even "uses Signal" is sensitive.
- Disappearing messages as hygiene. Short timers shrink the archive sitting on every device in the chat. Not a security boundary, a recipient can capture anything before it vanishes, but good housekeeping.
- Separate identities where justified. A separate device or number for sensitive contacts, so a compromise of your everyday phone does not touch them. Signal's username feature helps here: you can connect without handing out your phone number (see our usernames guide).
- Human practices. Verifying safety numbers with important contacts, agreeing on what never goes in writing, knowing how to spot phishing. Unsexy, and more protective than any feature.
Build yours in five minutes
Grab this checklist and answer honestly. Your threat model is the set of boxes you tick:
- Who specifically worries you? Name them: "my boss," "my ex," "advertisers," "the government of X." Vague answers ("hackers") produce vague protection.
- What can they actually do? Glance at your screen? Read your email? Seize your phone? Buy data about you? Be realistic. Most adversaries are far less capable than movies suggest.
- What would losing look like? Embarrassment? Job loss? Physical danger? The stakes set the budget: five minutes of settings, or a serious operational plan.
- Where are your devices and accounts weakest? Unlocked phone? Reused passwords? Cloud backups? Fix the weakest link before polishing the strongest.
- Who else is in your chats? Your security includes every contact's phone habits. The careless friend is part of your threat model whether you like it or not.
- What does Signal cover for you? Match your answers to the levels above. Levels 1–3 with Signal plus good device habits: you are in great shape. Level 4–5: Signal is one layer; get expert help for the rest.
Revisit this once a year or whenever your situation changes. New job, new country, new relationship, new phone. Threats move; your model should move with them.
Frequently asked questions
What is a threat model?
A clear statement of who you are worried about, what they can realistically do, and whether your tools actually stop them. It is how you avoid both under-protecting and over-protecting yourself.
Does Signal protect against hackers?
Against network interception, yes. Encryption defeats eavesdropping completely. Against hackers targeting your phone itself with spyware or phishing, no messenger can help; the device is the battlefield.
Can the government read my Signal messages?
Signal's encryption has no known backdoor and the protocol is publicly audited, so message contents resist interception. States typically attack the phone, the person, or the metadata instead. Areas where no app alone is sufficient.
Is Signal enough for journalists or activists?
It is usually part of the answer, not the whole answer. High-risk work needs device security, careful practices, and often expert operational-security guidance alongside the app.
What is the weakest link in Signal security?
The endpoints: your unlocked phone, malware on the device, and the people you chat with. Encryption secures the channel; everything at either end is yours to secure.
Keep reading
- What metadata Signal keeps: the honest breakdown of what the service knows
- Registration lock: stopping number-hijack account takeovers
- Usernames without phone numbers: connecting without exposing your number
- Privacy guides hub: every Signal privacy guide in one place
- is Signal safe for activists: the honest answer for high-risk users