gh0st

Security Architecture

Technical details on encryption, threat model, and security boundaries. The CLI provides the current encrypted workflow; native macOS vault and biometric integration remain pending.

Found a Security Issue?

We take security seriously. Please report vulnerabilities privately:

We acknowledge receipt within 48 hours and provide a timeline for fix.

Cryptographic Primitives

PrimitivePurposeImplementationStatus
AES-256-GCMContent encryptionWeb Crypto API (browser) / Ring (native)Implemented
HKDF-SHA-256Key derivationPurpose-separated subkeys from masterImplemented
Argon2idPassphrase KDF64MB memory, 3 iterations, 4 parallelImplemented
ChaCha20-Poly1305Alternative cipherAvailable via Ring for native buildsAvailable

Key Architecture

Master Key Derivation

User Passphrase │ ▼ Argon2id (64MB, 3 iter, 4 parallel) │ ▼ Master Key (256-bit) │ ├── HKDF → Conversations Key ├── HKDF → Attachments Key ├── HKDF → Agents Key ├── HKDF → Preferences Key ├── HKDF → MCP Credentials Key └── HKDF → Export Key

Encryption Properties

Algorithm
AES-256-GCM
Key derivation
HKDF-SHA-256
Passphrase KDF
Argon2id (64MB, 3i, 4p)
Nonce
12-byte random per encryption
Versioning
v1 in ciphertext header
Integrity
AEAD authentication tag
Tamper detection
AEAD tag verification
Key wipe
Zeroize on lock (native)

Vault Operations

OperationTrigger
LockCLI manual lock; native integration pending
UnlockCLI passphrase flow; native integration pending
Rotate keysCLI export/import workflow
WipeExplicit <code>gh0st wipe --force</code>

Threat Model — What We Protect Against (and What We Don't)

Honest threat modeling means being explicit about boundaries. This table shows the current threat model.

ThreatProtectedZoneNotes
Casual filesystem inspectionDevice—
Stolen app data directory (locked)Device—
Accidental plaintext backupsDevice—
Provider-side persistence (ZDR)xAIVerified via response header
Remote gh0st server compromiseNoneNo gh0st server exists
Fully compromised OS / malwareDevice—
xAI seeing plaintext during inferencexAIRequired for AI to work
Network metadata (ISP/VPN)Network—
Screenshots / shoulder surfingPhysical—
Deliberately shared MCP dataMCPOutside xAI ZDR

What gh0st Does NOT Protect Against

This honesty is important. These are outside gh0st's control regardless of encryption strength.

Fully compromised OS / malware (process memory readable when unlocked)

xAI seeing plaintext during inference (required for model to generate response)

Network metadata — ISP, VPN, DNS traffic analysis reveals usage patterns

Screenshots / shoulder surfing / physical observation

Keyboard / input compromise (keyloggers capture before encryption)

Deliberately shared MCP data (you chose to send it to that provider)

Hardware backdoors / firmware (below software trust boundary)

Rubber-hose cryptanalysis (coercion to reveal passphrase)

Side-channel attacks (timing, power, EM emanations)

Related Documents