What is Messaging Layer Security (MLS)?
The IETF open standard (RFC 9420) for end-to-end encrypted group messaging — efficient, forward-secret key agreement for groups from two members to many thousands.
Also known as
Messaging Layer Security (MLS) — explained.
Messaging Layer Security (MLS) is the IETF's open standard — published as RFC 9420 — for end-to-end encrypted group communication. Classic E2EE protocols were designed around pairwise conversations; extending them to groups historically meant either encrypting every message separately to every member (which scales poorly) or sharing a single static group key (which weakens forward secrecy and complicates membership changes). MLS solves the group problem directly: members share a cryptographic tree structure that lets the group agree keys efficiently, add and remove members with fresh keys per change (so a removed member cannot read future messages, and a new member cannot read past ones), and heal from device compromise through continuous key updates. The properties that matter to an enterprise evaluator: it is an open standard with public specification and academic scrutiny rather than a proprietary design; it scales group [end-to-end encryption](/glossary/end-to-end-encryption) to organisational sizes — departments, sites, whole-company announcement structures; and its membership-change semantics map naturally onto organisational lifecycle, where joiners, movers, and leavers are directory events that should have cryptographic consequences. For buyers of [secure enterprise messaging](/glossary/secure-enterprise-messaging), MLS alignment is a reasonable line item on the requirements list: it signals the vendor builds on scrutinised standards, and it future-proofs the platform as the standard's ecosystem matures. Zeour's NOVARYX platform aligns its group encryption design with MLS, combined with per-sender message signing so that even inside an encrypted group, one member cannot impersonate another.
Why operators care about messaging layer security (mls).
Group chat is where enterprise messaging actually happens — departments, sites, incident rooms, announcement channels. MLS is the standards answer to encrypting those at scale with membership changes handled cryptographically, not just cosmetically: a leaver loses access in the mathematics, not merely in the UI.
Buyer's checklist
- Group encryption aligned with an open standard (MLS, RFC 9420) rather than proprietary schemes
- Fresh keys on membership change — removal is cryptographic, not cosmetic
- Per-sender authentication inside groups (signing), not just a shared secret
- Published details of the cryptographic design available for review
- A credible story for very large groups and broadcast structures
Zeour solutions that operate on this layer.
Verticals where messaging layer security (mls) is operationally critical.
Adjacent definitions to read next.
End-to-End Encryption (E2EE)
Secure CommunicationsAn encryption model where content is encrypted on the sender's device and decrypted only on the recipient's — every system in between, including the server, handles ciphertext only.
Secure Enterprise Messaging
Secure CommunicationsOrganisation-governed instant messaging for official business — encrypted, directory-controlled, policy-managed, and archived to the organisation's regulatory obligations.
Off-Grid Mesh Messaging
Secure CommunicationsDevice-to-device messaging over short-range radio that relays encrypted messages across multiple hops — keeping teams communicating where there is no network at all.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where messaging layer security (mls) actually sits in your stack, then a fixed-fee Discovery price by the end of the call.