Security model
Apex is built entirely on named, standard primitives. There is no proprietary cryptography and nothing in the security model depends on the source staying private.
Primitives
Section titled “Primitives”| Purpose | Primitive |
|---|---|
| Master-key derivation | Argon2id (m = 65536, t = 3, p = 1) |
| Symmetric encryption | AES-256-GCM |
| Key exchange between devices | P-256 ECDH |
| Message authentication / signing | ECDSA on P-256 |
Where keys live
Section titled “Where keys live”Your master phrase never leaves your device. It is stretched with Argon2id into the vault key that seals your data with AES-256-GCM. Apex has nothing to leak because Apex never receives it — there is no account and no server-side copy of your vault.
When two devices pair, they exchange P-256 public keys (in person, by scanning a QR code — no server hand-off). From then on, every payload between them is encrypted with a fresh AES-256-GCM key derived from a P-256 ECDH shared secret.
A request, end to end
Section titled “A request, end to end”- Derive the vault key. Your master phrase runs through Argon2id on-device. The key exists in memory only while the vault is unlocked.
- Establish a shared secret. The two paired devices derive a per-message key via P-256 ECDH.
- Encrypt, sign, relay. The sender seals the payload with AES-256-GCM and signs it with ECDSA. The relay forwards opaque bytes; it cannot read or forge them.
- Verify and use. The receiver checks the signature before decrypting. Tampered or replayed messages are rejected. The delivered credential is used once and wiped.
// Illustrative — derive, seal, sign, relayconst vaultKey = argon2id(phrase, salt, { m: 65536, t: 3, p: 1 });
const { publicKey, privateKey } = p256.generateKeyPair();const shared = p256.getSharedSecret(privateKey, peerPublicKey);
const ct = aes256gcm.seal(shared, payload);const sig = ecdsa.sign(deviceKey, ct);await relay.forward({ ct, sig, pub: publicKey });// the relay sees only opaque bytesWhat the relay can and cannot see
Section titled “What the relay can and cannot see”The relay is content-blind: it routes ciphertext and discards it on delivery. It cannot read your passwords or vault. It does observe metadata — which devices connect, when, and roughly how large each ciphertext is.
No escrow, no backdoor
Section titled “No escrow, no backdoor”Apex never holds a recoverable copy of your vault. If we could recover it, so could anyone who compromised us. Recovery is your responsibility — your master phrase plus an optional, self-custodied encrypted backup. See the Cold Vault Protocol.