COM1_
TERMINAL MODEGET STARTED →
SECURE LINK // READ BEFORE ENABLE

Secure Link.

Privacy with a shared secret — and a threat model you can actually read.

Standard chat vs Secure Link

Standard chats are not end-to-end encrypted. They rely on encrypted network transport and Supabase access controls, but the service can process server-readable message and attachment content. This distinction is important.

Secure Link is an optional manually shared-key mode for selected conversations where the feature is enabled for your account. It derives encryption keys on participant devices from a manually exchanged channel key and secret.

Using Secure Link

  1. Open the intended conversation.
  2. Run /secure on.
  3. Agree on the channel key and secret out of band with your intended recipient; do not share the secret in the same chat.
  4. Compare the displayed fingerprint using another trusted method before trusting the channel.
  5. Use /secure rotate if a secret may be compromised. /forgetkey removes a locally remembered key.
/secure on
/secure rotate
/forgetkey

What Secure Link does and doesn't do

Protected Not protected / limited
Message content encrypted locally before it is stored/sent Conversation participants, timestamps, sizes and some delivery/typing metadata are still visible to infrastructure
Secure Link file content encrypted before upload The server and platforms can observe network/account activity
Manually derived, versioned shared-secret encryption Not Signal Protocol: no automatic Double Ratchet forward secrecy or post-compromise security
Generic push body for encrypted packets Live Morse timing is not covered by Secure Link content E2EE

COM1's implementation notes identify Argon2id, XChaCha20-Poly1305 and HKDF subkeys. Those details are implementation descriptions, not an independent security certification.

AI, bots and external network requests

Sending text or explicitly tagged media to an AI provider shares that selected content with a third party. Ordinary outgoing HTTP requests contact the destination API. Bot destinations and SSH servers likewise have separate trust boundaries. Secure Link encryption of the chat packet does not mean outside services cannot see content deliberately sent to them.

Losing the secret

If nobody retains the correct shared secret, old Secure Link content may be impossible to decrypt. Keep a secure backup of secrets you need. Also read the full security notes.