unlose docs · Concept
Security and key custody
Understand the local vault, client-side encryption, hosted metadata, and optional key custody modes.
Local vault
The local vault is plaintext because the agent must be able to resume it. Directories and files use owner-only permissions.
Hosted sync
Sync and export capsules are encrypted on your machine. By default, the server stores ciphertext and cannot read prompts, responses, or file paths. It can see routing facts required to operate the service: provider account, agent, random session ID, byte and file counts, and timestamps.
Key custody
| Mode | What changes |
|---|---|
| You hold the key | The server has no recovery key and cannot decrypt session contents. |
unlose key host on | The server stores the recovery code; the operator can decrypt that account. |
unlose titles on | A separate key reveals session titles only, not contents. |
Sharing
Exports and share links are complete recovery copies, not redacted summaries. Anyone with the matching recovery code or complete share link can read that copy.