Skip to content

Security model

Apex is built entirely on named, standard primitives. There is no proprietary cryptography and nothing in the security model depends on the source staying private.

PurposePrimitive
Master-key derivationArgon2id (m = 65536, t = 3, p = 1)
Symmetric encryptionAES-256-GCM
Key exchange between devicesP-256 ECDH
Message authentication / signingECDSA on P-256

Your master phrase never leaves your device. It is stretched with Argon2id into the vault key that seals your data with AES-256-GCM. Apex has nothing to leak because Apex never receives it — there is no account and no server-side copy of your vault.

When two devices pair, they exchange P-256 public keys (in person, by scanning a QR code — no server hand-off). From then on, every payload between them is encrypted with a fresh AES-256-GCM key derived from a P-256 ECDH shared secret.

  1. Derive the vault key. Your master phrase runs through Argon2id on-device. The key exists in memory only while the vault is unlocked.
  2. Establish a shared secret. The two paired devices derive a per-message key via P-256 ECDH.
  3. Encrypt, sign, relay. The sender seals the payload with AES-256-GCM and signs it with ECDSA. The relay forwards opaque bytes; it cannot read or forge them.
  4. Verify and use. The receiver checks the signature before decrypting. Tampered or replayed messages are rejected. The delivered credential is used once and wiped.
// Illustrative — derive, seal, sign, relay
const vaultKey = argon2id(phrase, salt, { m: 65536, t: 3, p: 1 });
const { publicKey, privateKey } = p256.generateKeyPair();
const shared = p256.getSharedSecret(privateKey, peerPublicKey);
const ct = aes256gcm.seal(shared, payload);
const sig = ecdsa.sign(deviceKey, ct);
await relay.forward({ ct, sig, pub: publicKey });
// the relay sees only opaque bytes

The relay is content-blind: it routes ciphertext and discards it on delivery. It cannot read your passwords or vault. It does observe metadata — which devices connect, when, and roughly how large each ciphertext is.

Apex never holds a recoverable copy of your vault. If we could recover it, so could anyone who compromised us. Recovery is your responsibility — your master phrase plus an optional, self-custodied encrypted backup. See the Cold Vault Protocol.