KJA Holdings LLC

Company

Who we are, and how we are put together.

KJA Holdings LLC is a privately held limited liability company. It owns and operates Pully, and does not hold interests in anything else.

Overview

KJA Holdings LLC exists to build and operate one thing well. The company was formed as the corporate home for Pully — to hold its intellectual property, to enter the agreements a software product requires, and to carry the obligations that come with running a service people rely on for private communication.

“KJA Holdings” is the registered trade name under which the company does business, and it is how we appear on our published applications. “KJA Holdings LLC” is the legal entity behind it. Both refer to the same company.

We are small and intend to stay that way for as long as it serves the product. There are no outside investors, no board seats sold, and no revenue line that depends on knowing things about the people who use our software. That last one is a structural decision rather than a promise: a company that has never built the machinery to profile its users cannot be quietly pressured into switching it on.

Structure and governance

Legal nameKJA Holdings LLC
Registered trade nameKJA Holdings
Entity typeLimited liability company
OwnershipPrivately held, wholly owned
Subsidiaries and holdingsPully (operating product, wholly owned)
Business activityDevelopment and operation of software for digital identity, authentication and private communications

Leadership

Joseph deGrood — Managing Member

Joseph deGrood is the sole owner and managing member of KJA Holdings LLC, and is the authorized signer for the company. He leads product and engineering for Pully, and is the point of contact for partnership, press and legal correspondence.

contact@kjahllc.com

What we believe

Identification without intrusion

This is the whole thesis. A website should be able to learn that you are you. A person picking up the phone should be able to learn that the voice on the other end is who it claims to be. Neither of those should cost you your phone number, your contact list, your location, or a file somewhere with your name on it. The industry has treated proof of identity and surrender of privacy as the same transaction. They are not, and the cryptography to separate them has existed for years.

The safest data is the data we never had

Every company that has lost its customers' information first decided to collect it. We design in the other direction: we ask what we can avoid knowing and still deliver the product. Message contents, call audio and video, and the substance of what people share are end-to-end encrypted and unreadable to us as the operator.

Reliability should be invisible

Software that works announces itself as little as possible. We would rather recover silently from a bad network than show someone an error they can do nothing about, and we hold ourselves to the standard that a call either works or tells you plainly that it did not.

Cryptography has to be able to move

The algorithms that are sound today will not all be sound in twenty years. Our key derivation and message formats are versioned so they can be migrated in lockstep across clients and servers, which is what makes a future move to post-quantum algorithms a project rather than a rewrite.

Milestones

2026Pully published on the Apple App Store for iOS.
August 2026Pully 1.1 released, adding private events and a rebuilt notification path.
August 2026Pully 1.2 released, with encrypted voice and video calling between Pully identities.
2026“Sign in with Pully” made available to developers, letting a website authenticate a visitor with no password and no shared secret.
In developmentAndroid release; an authenticator that replaces one-time-code apps; expanded verified organization identity, so a business can prove to a customer that an inbound contact is genuinely from them.