▸ Core

Architecture Overview

System Architecture Summary

INCOG AI is a layered privacy infrastructure protocol. Its architecture decomposes into four distinct strata, each addressing a specific class of privacy degradation present in contemporary internet infrastructure:

  1. Browser Execution Layer — eliminates observable fingerprinting surfaces and enforces session-level compartmentalization at the client
  2. Network Routing Layer — fragments traffic attribution through distributed encrypted relay paths
  3. Incentive Coordination Layer — aligns node operator economic interests with network privacy capacity via token-based rewards
  4. Application Privacy Layer — extends privacy guarantees to wallet interactions and in-browser AI inference

These layers are designed to compose. A user operating the INCOG Browser connected to the INCOG Mesh Network with an INCOG Wallet receives compounding privacy guarantees that no single layer could provide alone.


Layer 1: Browser Execution

The browser is the highest-entropy privacy leakage surface in the modern internet stack. A contemporary browser session exposes:

  • Canvas fingerprinting vectors via 2D and WebGL rendering APIs
  • Audio context timing signatures
  • Font enumeration surfaces
  • Screen resolution, color depth, and DPI ratios
  • Navigator API attributes (platform, language, user agent)
  • Battery status and hardware concurrency
  • WebRTC local IP exposure
  • Timing attack vectors via performance.now() and related interfaces
  • Cookie and storage linkability across origins

The INCOG Browser addresses these vectors not through blocking alone — which creates its own detectable signature — but through systematic API surface normalization and spoofing that reduces fingerprint entropy to a level indistinguishable from a large population of legitimate browsers.

Beyond fingerprinting, the browser layer enforces session-level isolation: each browsing context operates with independent storage partitions, network state, and execution environments. Cross-origin state leakage is prevented at the architecture level rather than through content policies that can be circumvented.


Layer 2: Network Routing

Even a perfectly fingerprint-neutral browser exposes metadata at the network layer. DNS queries reveal intent. IP attribution enables geographic and identity correlation. SNI (Server Name Indication) in TLS handshakes exposes destination before encryption is established. Timing analysis can correlate encrypted flows to specific destinations even without decryption.

The INCOG Mesh Network addresses these vectors by routing browser traffic through a multi-hop encrypted relay architecture operated by independent node operators. Each relay hop observes only the immediately adjacent nodes — never both origin and destination simultaneously — which prevents any single node from constructing a complete traffic picture.

The relay topology is designed to maximize path diversity and minimize the probability that any adversarial observer controls a sufficient fraction of the network to perform end-to-end correlation.


Layer 3: Incentive Coordination

Decentralized relay networks fail when node operators lack economic motivation to participate honestly and continuously. INCOG AI solves this through a token-aligned incentive model: node operators receive monthly $INCOG issuance proportional to verified throughput, uptime, and geographic diversity contribution.

The incentive structure is designed so that honest relay operation is strictly more profitable than defection, and that geographic diversity is economically rewarded, preventing concentration of routing capacity in a small number of jurisdictions.


Layer 4: Application Privacy

The protocol extends privacy guarantees to application-layer interactions through two modules:

INCOG Wallet enforces transaction-level privacy through address rotation, client-side signing, and minimal metadata footprint. Wallet operations occur within the browser isolation layer, preventing wallet state from leaking across browsing contexts.

INCOG LLM provides a private inference runtime that executes language model operations either entirely client-side or through privacy-preserving relay routing, with zero persistent prompt storage and no behavioral inference extraction.


Data Flow Model

User Action
    │
    ▼
Browser Execution Context (isolated per session)
    │  Fingerprint normalization applied
    │  Telemetry blocked at request layer
    ▼
Local Privacy Processing
    │  DNS-over-HTTPS routing
    │  WebRTC isolation enforced
    ▼
Encrypted Relay Entry Node (operator-independent)
    │  Traffic encrypted end-to-end
    │  Entry node sees: client IP + encrypted payload only
    ▼
Relay Intermediate Node(s) (1–N hops)
    │  Intermediate nodes see: previous hop + encrypted payload only
    ▼
Relay Exit Node
    │  Exit node sees: destination + decrypted payload only
    │  Origin IP not observable
    ▼
Destination Server
    │  Sees: exit node IP + standard HTTP/S request
    │  No origin attribution possible
    ▼
Response routed back through relay path
    ▼
Browser renders response in isolated context

Composability and Defense-in-Depth

Each layer of the INCOG architecture provides independent privacy guarantees. The system is designed so that the failure of any single layer degrades but does not eliminate overall privacy. A user whose relay path is partially compromised still benefits from browser-level fingerprint resistance. A user without Mesh Network access still benefits from browser isolation and telemetry blocking.

This defense-in-depth property is a deliberate design choice. Privacy architectures that require all components to function perfectly provide weaker guarantees in practice than architectures that degrade gracefully.


Trust Assumptions

The INCOG architecture operates under the following explicit trust assumptions:

  • Browser client: Trusted. The client executes privacy-preserving code locally. Users who modify the client do so at their own risk.
  • Relay nodes: Untrusted individually. No single relay node is trusted with complete routing information. The protocol tolerates a fraction of malicious nodes.
  • INCOG AI operator: Untrusted for operational privacy. The system is designed so that INCOG AI cannot deanonymize users in normal operation.
  • Destination servers: Adversarial. Destination servers are assumed to attempt fingerprinting, behavioral tracking, and IP-based attribution.
  • Network adversaries: Adversarial. Passive observers at the network layer are assumed to log all observable traffic metadata.

These trust assumptions define the protocol's security boundary. Claims outside this boundary are not made.

Incog SwapIncog Swap

Incog Swap is a non-custodial aggregation platform. Users maintain full control of their assets at all times. Incog Swap does not hold funds, store private keys, or require seed phrases.

Product

  • Swap
  • Status
  • Architecture
  • Docs
  • Help Center

Privacy

  • No KYC
  • No Account
  • Zero Custody
  • No Seed Phrase

Providers

  • LetsExchange
  • FixedFloat
  • SideShift
  • + 4 more

© 2026 Incog Swap · incogswap.org · Private Routes. Better Rates.

support@incogswap.org · ▸ session encrypted