Encryption scope
| Area | Current behavior and limits |
|---|---|
| Standard chat | Transport security + Supabase authorization/RLS. Server-readable content; not end-to-end encrypted. |
| Secure Link | Optional pre-shared-key end-to-end encryption of supported message/file content. Requires manual key exchange and verification. |
| Local message cache | Encrypted local Hive data; its key uses device platform secure storage. |
| Server-side metadata | Participants, account identifiers, timestamps, delivery state, sizes and other operational metadata may remain available. |
| Push | Uses FCM/APNs transport; Secure Link notifications should avoid plaintext previews. |
| AI / HTTP / bots / SSH | These features intentionally interact with outside services; their network and data exposure is not automatically covered by Secure Link. |
| Live Morse | Timing/broadcast events are not Secure Link end-to-end encrypted. |
Secure Link is not Signal Protocol
The attached implementation notes describe a manually shared-secret scheme using Argon2id, XChaCha20-Poly1305 and HKDF, plus versioned key rotation and key fingerprints. They explicitly do not claim Double Ratchet forward secrecy or post-compromise security. The scheme has not been independently audited on the basis of the files provided.
Responsible security habits
- Exchange and verify Secure Link keys through an independent trusted channel.
- Avoid connecting bots, AI providers or third-party endpoints to confidential conversations without consent.
- Use limited-scope tokens and SSH users. Assume machine-generated output is untrusted.
- Keep COM1 and your operating system updated.
- Don't treat deleted/expiring messages as a guarantee against screenshots, forwarding or previously downloaded content.
Report a vulnerability
Email mail@najad.dev with subject COM1 Security Report. Include a non-destructive proof of concept, affected version/platform and reproducible steps. Do not send real users' data or exploit production accounts. This contact route is not an encrypted reporting channel; avoid including live secrets.
Verification boundary
These notes explain the COM1 security design; they are not a statement of independent audit or penetration-testing certification. Specific protections depend on the running app version, server configuration and deployment.