The crypto stack.

Standard, well-studied primitives. Audit-friendly. No in-house cipher suite.

Argon2id

Password stretching. Memory-hard. Resistant to GPU cracking.

XChaCha20-Poly1305

AEAD cipher. Seals every item and every operation log entry.

X25519

Device-to-device key wrapping. Elliptic-curve Diffie-Hellman.

Ed25519

Device approval signatures. Domain-separated bytes per approval.

Contributing.

All contributions are welcome — patches, bug reports, imports for new authenticators, translations, documentation, ideas. The contributing guide covers the conventions we follow so your first PR lands clean.

Read the contributing guide

Roadmap.

  1. V1 — current. Web, CLI, server, Docker, Postgres, imports, sync.
  2. Native iOS & Android. Same crypto core via UniFFI.
  3. SQLite backend. Optional, for single-operator deployments.
  4. Coffre Cloud launch. Managed, in France.