Security model

What is proven today—and what is still only a design.

The repository is ready for architecture and protocol review. It is not ready to protect real conversations: durable authorization exists only in the SQLCipher laboratory, connected FastV1 delivery is experimental, and there is no production client, offline mailbox, or hosted realm.

Read every security claim with its evidence status.

“Implemented and tested” describes a bounded laboratory result. It does not mean the complete product or deployment is secure.

Invitation and join formats
Versioned, size-bounded formats reject malformed, expired, unknown, and context-mismatched input before state changes.
Implemented + tested
Private invitation proof bound to one device
A one-shot HPKE check ties the exact signed invitation to one exact MLS KeyPackage, reserves replay values, and records a simulated approval decision.
Implemented + tested
Two-device MLS lifecycle
The in-memory adapter adds a device, exchanges protected messages in both directions, updates the group, removes the device, and tests replay and reordering.
Implemented + tested
Local delivery under faults
Separate deposit, receive, and acknowledgement rights are tested under deterministic loss, duplication, delay, reordering, retry, expiry, and bounds.
Implemented + tested
Durable authorization transaction
The SQLCipher laboratory atomically commits and reloads approval, replay, invitation consumption, MLS state, and the Welcome outbox. Platform key custody, stale-snapshot resistance, secure deletion, and production integration remain open.
Implemented laboratory
Production vault and desktop client
The common macOS, Windows, and Linux baseline needs reviewed key protection, a selected shell, safe deep links, updates, and packaging.
Required, unimplemented
Connected FastV1 delivery
The authenticated Iroh adapter implements experimental connected delivery. Offline delivery, a durable mailbox, anonymity, egress isolation, and production operations remain open.
Experimental
GitHub and portable credential admission
Designed behind the same exact KeyPackage binding, but intentionally kept out of the Phase 1 capability-only laboratory.
Later roadmap phases

Assume every input and supporting service can be hostile.

Invitations, links, envelopes, provider responses, mailbox objects, storage, and network input remain untrusted until the component responsible for them validates them.

Threats included in the design

  • A malicious or compromised participant before and after admission.
  • A curious or compromised realm, mailbox, relay, or transport operator.
  • A network adversary that delays, drops, reorders, duplicates, injects, or observes.
  • A supply-chain attacker targeting dependencies, builds, updates, or signing credentials.
  • A deceptive identity or credential ecosystem that produces technically valid but misleading evidence.

Required behavior

  • Reject ambiguity, expiry, replay, substitution, and unknown suites before mutation.
  • Bound storage, parsing, retries, queues, and unauthenticated work.
  • Keep plaintext, keys, capabilities, raw tokens, and stable identity out of transport and logs.
  • Fail closed when a private transport is unavailable.
  • Make every visible guarantee match retained evidence.

Encryption protects message content, not every trace of a conversation.

Identity, network metadata, device security, and message retention each have different observers and failure modes.

A private message can still leave metadata.

A direct peer may learn the other peer’s IP address. A relay may observe endpoints, timing, and volume. A mixnet can reduce correlation but adds latency, loss, and deployment assumptions. None of those layers may read MLS content, but they do not provide the same privacy.

The device can still expose the message.

Session Chat cannot stop a participant from saving plaintext or protect an unlocked device controlled by malware. Ephemeral deletion can remove only Session Chat’s own retained copies and cryptographic access, not copies on another person’s device.

See the release gates →
Use source-backed evidence for real decisions.

The independent-audit brief is the canonical index for code-backed evidence, required but unimplemented contracts, proposed experiments, deferred work, and explicit non-goals.

Open audit brief ↗