Skip to content

Security

Keep less. Protect the rest.

What runs on your PC, what reaches the server, how it is protected there, and what is not finished yet. Written for people who want to check before they trust.

Overview

Kenveil is a Windows app with one server in Spain (EU) behind it. The sensitive work happens on your PC. The server keeps what the Ledger lists, most of it encrypted with a key unique to your account.

Your PC

Kenveil app

  • WebViewThe interface. No network of its own
  • Rust coreTokens, keys and every request

WireGuard for Windows

Uses the Relay file you saved

Never leaves this PC

  • Mailbox passwords and sign-ins
  • Mail subjects and contents
  • Raw hardware values
  • Relay private keys
  • Photos you check with Post

HTTPS: the Rust core connects to the Caddy edge.

WireGuard: WireGuard for Windows connects to the Relay.

Inbound mail: other mail servers deliver to Canary mail.

Kenveil server · Spain (EU)

Caddy edge

TLS, HSTS for two years

Relay

WireGuard. Sites see the server’s address, not yours

Canary mail

Receive-only. No mail is sent

API

Sign-in, licenses, scans and Canary inboxes, behind rate limits

Postgres + Redis

Internal-only network, no route to the internet

How the parts connect. Everything inside the dashed outline runs on your own PC.
  • App traffic

    The Rust core talks to the API over HTTPS through Caddy. The interface never opens a connection itself.

  • Relay traffic

    WireGuard for Windows connects straight to the Relay with the file you saved. The Kenveil app is not in that path.

  • Canary mail

    Other mail servers deliver to your Canary addresses, encrypted with STARTTLS when they support it. The server only receives: it sends no mail at all.

Accounts and sign-in

Passwords are hashed slowly, sessions run on short-lived tokens, and a refresh token that shows up twice ends the whole session.

Passwords
HashingArgon2id with 64 MiB of memory, 3 passes, 1 lane.m=65536, t=3, p=1
Length12 to 256 characters.
StrengthMust score at least 3 out of 4 on zxcvbn.
Breached passwordsRefused. Only the first 5 characters of the password’s SHA-1 hash go to Pwned Passwords.
Unknown emailsSign-in does the same work either way, so timing doesn’t reveal who has an account.
Sessions and tokens
Access tokenA JWT, valid for 10 minutes.
Refresh token256 random bits, stored only as a keyed hash.
RotationReplaced on every use. Reusing an old one ends the session.
Lifetime30 days in the app, 14 days on the web.
In the appTokens stay in the Rust core and Windows Credential Manager. The WebView never sees them.
Two-step sign-in
CodesTOTP: 6 digits every 30 seconds, one step of clock drift allowed.
ReuseEach code works once.
SecretEncrypted with your account key.
Backup codes10 single-use codes, stored only as keyed hashes.
Attempts10 tries per 15 minutes.
Rate limits
Sign-in30 per 15 minutes.
Sensitive actions10 per hour.
Signed in300 requests per minute.
Not signed in120 requests per minute.
Failed attemptsLimits per account, with a growing delay.

Encryption at rest

Personal data on the server is encrypted with a data key that belongs to your account alone. Delete the account and the key goes with it.

Master key

Kept outside the database

Wraps: the master key wraps each account’s data key.

Your data key

Random, one per account, stored only wrapped

AES-256-GCM: your data key encrypts your records.

Your encrypted records

Graph, scans, alerts, Canary mail, removals and more

HKDF-SHA256: the master key also derives the purpose keys.

Purpose keys

Blind indexes, rate-limit keys, one-time tokens

  • Bound to its place

    Every value is sealed with AES-256-GCM under a fresh random nonce and bound to its table, column and row. Moved anywhere else, it fails to decrypt.

  • Found without being read

    Where a lookup is needed, Kenveil uses a blind index: a keyed hash scoped to your account and the field, so the same value in two accounts never matches.

  • Deleted means unreadable

    Deleting your account deletes your wrapped data key. Every encrypted record becomes unreadable at once, and the rows are removed with it.

  • Readable on purpose

    Your email address (to sign you in), Canary addresses and their sites’ domains (to route mail), and Relay public keys and tunnel addresses (to route traffic). Passwords, license keys and PC fingerprints are kept only as hashes.

Devices and licenses

A license is tied to PCs through keys and hashes. Kenveil can recognise a PC again without ever learning its serial numbers.

Devices and licenses
Device keyEd25519, created on the PC. The private key stays in Windows Credential Manager.
ActivationThe PC signs a single-use challenge from the server that expires after 60 seconds, so a recorded request can’t be replayed.
Offline useA signed lease (EdDSA) valid for 72 hours, checked again every hour while the app runs.
PC fingerprintFour identifiers: Windows installation ID, motherboard UUID, motherboard serial number and system disk serial number. Each is hashed on the PC; the server hashes the results again with its own secret.
License keys100 random bits, stored only as a peppered hash and the last characters.KNVL-XXXXXX-XXXXXX-XXXXXX-XXXXXX

Raw hardware values never leave your PC. What reaches the server is a set of hashes that can only recognise the same PC again.

Privacy by design

Kenveil trims what it has to see and drops the rest before anything is stored.

  • Truncated addresses

    IP addresses are cut to the network before they are stored: /24 for IPv4, /48 for IPv6. Rate-limit keys are hashed.

  • A summary, not a fingerprint

    Your browser string becomes a short summary such as “Chrome 131 on Windows”.

  • Logs that redact

    Server logs strip passwords, tokens, emails, handles, labels, fingerprints and request bodies.

  • Relay keeps counts

    The Relay agent logs event names and counts only, such as how many connections were added.

  • About you only

    Scans start from accounts you verified and your account email, and the server reads official public endpoints only. There is no field for anyone else.

  • A quiet website

    No trackers, no analytics and no third-party requests. Fonts, images and scripts all come from this site.

On your PC

Kenveil installs for your Windows user only and asks for no special powers.

  • No drivers, no service

    Kenveil installs no kernel drivers and no Windows service.

  • No admin rights

    A per-user install. The installer never asks for administrator rights.

  • A sealed interface

    The interface runs in a WebView under a strict Content Security Policy: no remote code, and no network access of its own.

  • Allow-listed requests

    Every call to the Kenveil API goes through the Rust core, which only uses routes from a fixed list. The interface may use only the routes marked for it.

  • Secrets in Credential Manager

    Your sign-in, device key, license lease and mailbox passwords are kept in Windows Credential Manager, protected by your Windows account.

  • Mail read, not taken

    Connected mailboxes are read over IMAP with TLS, read-only and headers only.

  • In your browser

    The extension asks only for storage, alarms and notifications, and talks only to the Kenveil server. Web pages can’t see your names or groups, and password fields are ignored.

  • Leaves cleanly

    The uninstaller offers to remove your sign-in and saved data.

Infrastructure

The server runs as a set of locked-down containers, and only three of them take connections from the internet.

Server and website
Entry pointsHTTPS through Caddy, WireGuard to the Relay, and inbound mail for Canary. Readiness, admin and internal endpoints answer 404 from outside.
ContainersEvery container runs with no-new-privileges. The API, this website and the Discord bot run read-only with all Linux capabilities dropped; Caddy keeps only the right to bind its ports.
DatabasesPostgres and Redis sit on an internal-only network with no route to the internet, and both require a password.
TLSCertificates are issued and renewed automatically by Caddy.
HSTSTwo years, including subdomains.max-age=63072000; includeSubDomains
Headersnosniff, no referrer, no server banner. The API sends a Content Security Policy that allows nothing.default-src 'none'
This websiteA strict Content Security Policy: only scripts and styles with listed hashes run, and nothing loads from other hosts.

Known limitations

What is not finished yet, stated plainly.

  • The installer is not code-signed yet

    Windows SmartScreen warns the first time you run it. Before you install, compare the file’s SHA-256 checksum with the one published on the download page.

    Download page and checksum
  • No automatic updates yet

    The app does not update itself. New versions are published on the download page, and you install them the same way as the first one.

  • Relay needs WireGuard for Windows

    Relay gives you a connection file for the official WireGuard app. It hides your IP address from the sites you visit, but it does not make you anonymous.

  • Canary mail stays in Kenveil

    Kenveil does not forward Canary mail to your real inbox. You read a plain-text copy in the app for 7 days; on the server it is encrypted with your account key.

Responsible disclosure

Found a weakness? Tell us privately first. A person reads every report.

How to report

  1. Join the Kenveil Discord and open a private ticket.
  2. Choose the category Something else and start the title with SECURITY.
  3. Describe what you found. Keep the details out of public channels until it is fixed.
Open the Kenveil Discord(opens in a new tab)

What to include

  • What is affected: a page, an API route or the app version
  • Steps to reproduce it, with a minimal proof of concept
  • What someone could do with it

Please don’t

  • Access, change or delete data that isn’t yours. Test with your own account.
  • Degrade the service: no denial of service, spam or high-volume scanning.
  • Use social engineering, or target staff or other users.
  • Publish details before we have had a fair chance to fix the issue.

Safe harbour for good-faith research

If you research in good faith and follow this page, we will not take legal action against you, and we will work with you to understand and fix what you found.

Contact details for researchers are also published in machine-readable form at/.well-known/security.txt.

Transparency report

A monthly report, generated from the server’s own numbers and published after staff review.

Each month the server will compile these numbers itself, and staff will review the draft before it is published here.

Monthly transparency report

Not published yet
Active licenses
How many licenses were active during the month.
Data requests received
Requests for user data that Kenveil received.
Retention jobs run
The automatic clean-ups that delete data when its time is up.
Canary mail deleted
Canary messages deleted when their seven days ran out.
Security events
Security events the server recorded.

The first report will cover the first full month after launch. Until then this section shows no figures rather than estimates.

The Ledger

Everything Kenveil keeps, row by row.

Where each piece of data lives, how it is protected, why it is needed and how long it stays. The same map is inside the app.