Security
Keep less. Protect the rest.
What runs on your PC, what reaches the server, how it is protected there, and what is not finished yet. Written for people who want to check before they trust.
Overview
Kenveil is a Windows app with one server in Spain (EU) behind it. The sensitive work happens on your PC. The server keeps what the Ledger lists, most of it encrypted with a key unique to your account.
Your PC
Kenveil app
- WebView
- Rust core
WireGuard for Windows
Never leaves this PC
- Mailbox passwords and sign-ins
- Mail subjects and contents
- Raw hardware values
- Relay private keys
- Photos you check with Post
HTTPS: the Rust core connects to the Caddy edge.
WireGuard: WireGuard for Windows connects to the Relay.
Inbound mail: other mail servers deliver to Canary mail.
Kenveil server · Spain (EU)
Caddy edge
Relay
Canary mail
API
Postgres + Redis
App traffic
The Rust core talks to the API over HTTPS through Caddy. The interface never opens a connection itself.
Relay traffic
WireGuard for Windows connects straight to the Relay with the file you saved. The Kenveil app is not in that path.
Canary mail
Other mail servers deliver to your Canary addresses, encrypted with STARTTLS when they support it. The server only receives: it sends no mail at all.
Accounts and sign-in
Passwords are hashed slowly, sessions run on short-lived tokens, and a refresh token that shows up twice ends the whole session.
| Hashing | Argon2id with 64 MiB of memory, 3 passes, 1 lane.m=65536, t=3, p=1 |
|---|---|
| Length | 12 to 256 characters. |
| Strength | Must score at least 3 out of 4 on zxcvbn. |
| Breached passwords | Refused. Only the first 5 characters of the password’s SHA-1 hash go to Pwned Passwords. |
| Unknown emails | Sign-in does the same work either way, so timing doesn’t reveal who has an account. |
| Access token | A JWT, valid for 10 minutes. |
|---|---|
| Refresh token | 256 random bits, stored only as a keyed hash. |
| Rotation | Replaced on every use. Reusing an old one ends the session. |
| Lifetime | 30 days in the app, 14 days on the web. |
| In the app | Tokens stay in the Rust core and Windows Credential Manager. The WebView never sees them. |
| Codes | TOTP: 6 digits every 30 seconds, one step of clock drift allowed. |
|---|---|
| Reuse | Each code works once. |
| Secret | Encrypted with your account key. |
| Backup codes | 10 single-use codes, stored only as keyed hashes. |
| Attempts | 10 tries per 15 minutes. |
| Sign-in | 30 per 15 minutes. |
|---|---|
| Sensitive actions | 10 per hour. |
| Signed in | 300 requests per minute. |
| Not signed in | 120 requests per minute. |
| Failed attempts | Limits per account, with a growing delay. |
Encryption at rest
Personal data on the server is encrypted with a data key that belongs to your account alone. Delete the account and the key goes with it.
Master key
Wraps: the master key wraps each account’s data key.
Your data key
AES-256-GCM: your data key encrypts your records.
Your encrypted records
HKDF-SHA256: the master key also derives the purpose keys.
Purpose keys
Bound to its place
Every value is sealed with AES-256-GCM under a fresh random nonce and bound to its table, column and row. Moved anywhere else, it fails to decrypt.
Found without being read
Where a lookup is needed, Kenveil uses a blind index: a keyed hash scoped to your account and the field, so the same value in two accounts never matches.
Deleted means unreadable
Deleting your account deletes your wrapped data key. Every encrypted record becomes unreadable at once, and the rows are removed with it.
Readable on purpose
Your email address (to sign you in), Canary addresses and their sites’ domains (to route mail), and Relay public keys and tunnel addresses (to route traffic). Passwords, license keys and PC fingerprints are kept only as hashes.
Devices and licenses
A license is tied to PCs through keys and hashes. Kenveil can recognise a PC again without ever learning its serial numbers.
| Device key | Ed25519, created on the PC. The private key stays in Windows Credential Manager. |
|---|---|
| Activation | The PC signs a single-use challenge from the server that expires after 60 seconds, so a recorded request can’t be replayed. |
| Offline use | A signed lease (EdDSA) valid for 72 hours, checked again every hour while the app runs. |
| PC fingerprint | Four identifiers: Windows installation ID, motherboard UUID, motherboard serial number and system disk serial number. Each is hashed on the PC; the server hashes the results again with its own secret. |
| License keys | 100 random bits, stored only as a peppered hash and the last characters.KNVL-XXXXXX-XXXXXX-XXXXXX-XXXXXX |
Raw hardware values never leave your PC. What reaches the server is a set of hashes that can only recognise the same PC again.
Privacy by design
Kenveil trims what it has to see and drops the rest before anything is stored.
Truncated addresses
IP addresses are cut to the network before they are stored: /24 for IPv4, /48 for IPv6. Rate-limit keys are hashed.
A summary, not a fingerprint
Your browser string becomes a short summary such as “Chrome 131 on Windows”.
Logs that redact
Server logs strip passwords, tokens, emails, handles, labels, fingerprints and request bodies.
Relay keeps counts
The Relay agent logs event names and counts only, such as how many connections were added.
About you only
Scans start from accounts you verified and your account email, and the server reads official public endpoints only. There is no field for anyone else.
A quiet website
No trackers, no analytics and no third-party requests. Fonts, images and scripts all come from this site.
On your PC
Kenveil installs for your Windows user only and asks for no special powers.
No drivers, no service
Kenveil installs no kernel drivers and no Windows service.
No admin rights
A per-user install. The installer never asks for administrator rights.
A sealed interface
The interface runs in a WebView under a strict Content Security Policy: no remote code, and no network access of its own.
Allow-listed requests
Every call to the Kenveil API goes through the Rust core, which only uses routes from a fixed list. The interface may use only the routes marked for it.
Secrets in Credential Manager
Your sign-in, device key, license lease and mailbox passwords are kept in Windows Credential Manager, protected by your Windows account.
Mail read, not taken
Connected mailboxes are read over IMAP with TLS, read-only and headers only.
In your browser
The extension asks only for storage, alarms and notifications, and talks only to the Kenveil server. Web pages can’t see your names or groups, and password fields are ignored.
Leaves cleanly
The uninstaller offers to remove your sign-in and saved data.
Infrastructure
The server runs as a set of locked-down containers, and only three of them take connections from the internet.
| Entry points | HTTPS through Caddy, WireGuard to the Relay, and inbound mail for Canary. Readiness, admin and internal endpoints answer 404 from outside. |
|---|---|
| Containers | Every container runs with no-new-privileges. The API, this website and the Discord bot run read-only with all Linux capabilities dropped; Caddy keeps only the right to bind its ports. |
| Databases | Postgres and Redis sit on an internal-only network with no route to the internet, and both require a password. |
| TLS | Certificates are issued and renewed automatically by Caddy. |
| HSTS | Two years, including subdomains.max-age=63072000; includeSubDomains |
| Headers | nosniff, no referrer, no server banner. The API sends a Content Security Policy that allows nothing.default-src 'none' |
| This website | A strict Content Security Policy: only scripts and styles with listed hashes run, and nothing loads from other hosts. |
Known limitations
What is not finished yet, stated plainly.
The installer is not code-signed yet
Windows SmartScreen warns the first time you run it. Before you install, compare the file’s SHA-256 checksum with the one published on the download page.
Download page and checksumNo automatic updates yet
The app does not update itself. New versions are published on the download page, and you install them the same way as the first one.
Relay needs WireGuard for Windows
Relay gives you a connection file for the official WireGuard app. It hides your IP address from the sites you visit, but it does not make you anonymous.
Canary mail stays in Kenveil
Kenveil does not forward Canary mail to your real inbox. You read a plain-text copy in the app for 7 days; on the server it is encrypted with your account key.
Responsible disclosure
Found a weakness? Tell us privately first. A person reads every report.
How to report
- Join the Kenveil Discord and open a private ticket.
- Choose the category Something else and start the title with
SECURITY. - Describe what you found. Keep the details out of public channels until it is fixed.
What to include
- What is affected: a page, an API route or the app version
- Steps to reproduce it, with a minimal proof of concept
- What someone could do with it
Please don’t
- Access, change or delete data that isn’t yours. Test with your own account.
- Degrade the service: no denial of service, spam or high-volume scanning.
- Use social engineering, or target staff or other users.
- Publish details before we have had a fair chance to fix the issue.
Safe harbour for good-faith research
If you research in good faith and follow this page, we will not take legal action against you, and we will work with you to understand and fix what you found.
Contact details for researchers are also published in machine-readable form at/.well-known/security.txt.
Transparency report
A monthly report, generated from the server’s own numbers and published after staff review.
Each month the server will compile these numbers itself, and staff will review the draft before it is published here.
Monthly transparency report
Not published yet- Active licenses
- How many licenses were active during the month.
- Data requests received
- Requests for user data that Kenveil received.
- Retention jobs run
- The automatic clean-ups that delete data when its time is up.
- Canary mail deleted
- Canary messages deleted when their seven days ran out.
- Security events
- Security events the server recorded.
The first report will cover the first full month after launch. Until then this section shows no figures rather than estimates.
The Ledger
Everything Kenveil keeps, row by row.
Where each piece of data lives, how it is protected, why it is needed and how long it stays. The same map is inside the app.