Know the four security layers

NOID address
The stable network address other NOID users enter. It is not a password.
Installation credential
A protected secret used by one authorised client installation when connecting to the relay.
Account PIN
A four-digit account control. It should be changed from a default and kept private.
Device access
The operating-system login, screen lock and browser profile protecting everything stored locally.

These layers solve different problems. Hiding a NOID address does not replace a secure credential; a strong device lock does not make it safe to share a PIN; and encrypted transport does not protect content already visible on an unlocked screen.

Credentials and account access

NOID for Web creates an installation credential in protected browser storage. That credential allows the relay to distinguish the authorised installation from a browser that merely knows the public NOID address. Native clients maintain their own supported installation identity.

Do not copy browser storage between people, export unknown credential files, reuse a shared browser profile or enter NOID account details on a domain other than aieng.co.za. Private-browsing windows and storage-cleaning utilities can remove local installation state and cause a browser to be treated as new.

The account PIN protects account functions but has only four digits. It must be protected by rate limiting and should not be reused as a phone unlock code, bank PIN or password for another service. Change it if another person has seen it or if unexpected account activity appears.

Encrypted content and visible endpoints

Supported clients protect call and message content while it travels through the NOID transport. The relay still handles routing and delivery operations. Administrative registers are designed to show operational measurements rather than encrypted message text or attachment contents.

Encryption does not protect a message after a legitimate recipient opens it, prevent a recipient from copying information, or secure a device already controlled by malware. It also cannot verify that a person is trustworthy simply because they have a valid NOID address.

Before sharing sensitive information, confirm the recipient through an appropriate independent method. Never send a private key, installation credential or account PIN in a message or support request.

Why operational metadata exists

Communication systems need enough information to locate recipients, manage authentication and determine whether delivery succeeded. NOID may therefore process participating NOID addresses, times, direction, connection state, message type, attachment size, call duration, delivery result, client version and security events.

This data supports reliability, account history, compatibility diagnosis, anti-abuse controls and verified rewards. It can still be sensitive even when it is not the conversation text. Access to administrative records should be limited, actions should be logged where practical, and information should not be retained longer than reasonably necessary for its operational or legal purpose.

The Privacy Notice describes the categories and purposes in more detail.

Microphone, files and location permissions

A call needs microphone access. An attachment feature needs access to the file the user chooses. Location-based tools need a position when the user actively opens them. The browser or operating system remains responsible for showing the protected permission prompt.

  • Grant a permission only when using the feature that needs it.
  • Check the site name and HTTPS indicator before accepting a browser prompt.
  • Review permissions later in browser or Android settings and withdraw access that is no longer needed.
  • Do not upload a file merely because an unknown recipient requests it.
  • Remember that intentionally shared location data is visible to the selected recipient.

Practical security checklist

  1. Keep the browser, Android operating system and NOID client current.
  2. Install Android packages only from the official NOID Downloads page and compare the published version or checksum.
  3. Use an operating-system screen lock and a private browser profile.
  4. Change the NOID PIN from its default and never disclose it to support.
  5. Review unexpected device or activity records from the account area.
  6. Complete hotel Wi-Fi sign-in before opening NOID; do not bypass venue controls.
  7. Close private conversations before handing an unlocked device to another person.
  8. Report reproducible security concerns with dates, versions and steps, but omit credentials and private message content.

Security and availability limits

No connected service can promise absolute security or continuous availability. A malicious extension, rooted phone, compromised operating system, shared unlocked computer, deceptive link, weak internet connection or relay outage can undermine protections outside the intended protocol boundary.

NOID should not be used as an emergency service or as the only copy of critical information. Maintain an appropriate emergency calling method and keep independent backups of information that must not be lost.

Report safely: registered users can sign in to the account area and use Contact AIEng. Include the time, client version and reproducible steps. Never include a PIN, credential, private key or another person’s message content.

Advertising boundary: Google advertising may appear on this public guide, but is excluded from NOID login, account, administration, call and private messaging screens. Advertising systems do not receive private NOID message text from this page. See Advertising Standards.