Security Architecture Whitepaper
The cryptographic design, the trust boundaries, the threat model, and — at equal length — what this design does not protect you from.
No email address required. It is the same document we ship with the application.
4d8f227422011dfd…Contents
- 01Executive summary
- 02Security principles
- 03System architecture
- 04Threat model
- 05Cryptography
- 06The master password
- 07Vault architecture
- 08Backup architecture
- 09Session security
- 10Offline architecture
- 11Privacy
- 12Platform security
- 13Security assumptions
- 14Security limitations
- 15Best practices
- 16Frequently asked questions
- 17Future security work
- 18Appendix A — Parameters at a glance
- 19Appendix B — Findings from this review
- 20Appendix C — Verifying these claims
Before you open it
Not an audit. No independent party has reviewed this design or this code, and the roadmap in §17 says when that is intended to change. It is a description of a design, its assumptions and its failure modes, written so you can judge whether those assumptions hold for you.
§14 lists what CofferShield cannot defend against — keyloggers, an unlocked machine, coercion, a weak master password. Appendix B publishes the defects this review found in the product and what was changed. Appendix C tells you how to verify each claim yourself.