Security
What the software does today — not marketing claims and not an independent audit.
Threat model
| Threat | Mitigation | Residual risk |
|---|---|---|
| Secrets at rest | libsodium secretbox (XSalsa20-Poly1305); vault holds ciphertext + nonce. | Anyone with the master key and vault file can decrypt. |
| Master key storage | OS keychain via keytar; optional Argon2id passphrase wrap. | Malware in the user session may access memory or keychain APIs. |
| Over-broad agent / tool access | .latchkey.toml allowlists; approve/deny per request; MCP needs LATCHKEY_MCP_APPROVE=1. Limits which secret names an agent can even request — not a substitute for vendor-side token scope hygiene. | A careless approve still injects plaintext into the child process; compromised tools can exfiltrate after approval. |
| Untrusted tool / MCP runtime | Planned: optional agent sandbox (isolated tool execution). Today: gate + audit only. | Same class of risk as agents calling third-party APIs with excessive tokens — mitigate with approvals now; sandbox later. |
| Logging leaks | Redaction helpers; audit log stores names and actions, not values. | External tracers can still observe child env. |
| Network exfiltration by CLI | CLI makes no outbound connections by default. | Commands you run may use the network. |
Crypto choices
- Vault values: libsodium crypto_secretbox
- Master key: OS keychain (keytar) preferred
- Passphrase wrap: Argon2id (crypto_pwhash)
- Licences: Ed25519 signatures verified offline in the CLI
What we never see
- Vault plaintext or master keys
- Passphrases or keychain material
- Secret values in audit sync (metadata only, if enabled)
- Your repository contents during a local leak scan
Enterprise trust pack
Sub-processors, DPA summary, and procurement index: Trust & legal · Agent sandbox (M22).
Report a vulnerability
Email Yusuf@yusuf-choudhury.com with reproduction steps. Do not include real API keys.
Also see docs and packages/cli/SECURITY.md.