Never sees

  • plaintext TOTP secrets
  • your master key
  • your password
  • your recovery code
  • the contents of any item

Does see

  • sealed ciphertext (per-item and per-op)
  • device public keys (X25519, Ed25519)
  • operation ordering (Lamport counters)
  • your email address — for authentication only
  • push subscription tokens — for notifications

Audit status.

Coffre V1 has not been externally audited. The crypto primitives are standard and well-studied (XChaCha20-Poly1305, Argon2id, X25519, Ed25519). The integration — how they compose into a product — is what an audit would cover, and we'd welcome one.

Read the full threat model

Responsible disclosure.

Found a vulnerability? Email security@coffre.app. We'll respond within 72 hours. Details in our security.txt.