unlose docs · Concept

Security and key custody

Understand the local vault, client-side encryption, hosted metadata, and optional key custody modes.

Local vault

The local vault is plaintext because the agent must be able to resume it. Directories and files use owner-only permissions.

Hosted sync

Sync and export capsules are encrypted on your machine. By default, the server stores ciphertext and cannot read prompts, responses, or file paths. It can see routing facts required to operate the service: provider account, agent, random session ID, byte and file counts, and timestamps.

Key custody

ModeWhat changes
You hold the keyThe server has no recovery key and cannot decrypt session contents.
unlose key host onThe server stores the recovery code; the operator can decrypt that account.
unlose titles onA separate key reveals session titles only, not contents.

Sharing

Exports and share links are complete recovery copies, not redacted summaries. Anyone with the matching recovery code or complete share link can read that copy.