TRUST & BOUNDARIES
Know what you share.
And with whom.
One keyring connects the conversation to the services in a room. Trust is your decision, not a badge supplied by someone else.
Your keyring is the decision
A node is an identity with its own keys, rooms, and keyring. A room brings nodes together; joining the room does not grant every sender’s keys. There is no contact directory, automatic trust, or trust inherited from someone else.
Your keyring names the nodes you trust. Your node releases your sender keys to those nodes in shared rooms and accepts sender keys only from nodes in your own keyring. The other side makes its own decision. A two-way conversation requires both sides’ trust.
Trust is not per room. It applies across the rooms you share now and later, including access to the services you share there. Trusting Ann does not make Ann trusted by anyone else.
Each keyring entry grants read, or read + drive. Read is what the paragraphs above describe. Drive adds one thing: the node may drive your agents’ Sessions, typing into them, interrupting or stopping them, answering their approvals and questions, and sending them files. Each keyring change asks for your identity passphrase, typed at a terminal, never taken from a file or the environment.
When a node joins a room you share, or a member grants your node its key, Vox offers it to your keyring and the offer waits: you accept it, giving it a name and read or read + drive, or dismiss it, which it is not told. An offer is a prompt to decide, never trust granted for you.
Names are local aliases for fingerprints. Compare the full fingerprint through a channel you trust before adding it. A sender’s claim about their name is not identity evidence.
By default, granting access starts with messages from that point onward. The model also permits an explicit full-history grant for your own retained messages. “Forward-only” must not be mistaken for an unconditional prohibition on sharing history.
Removing trust rotates your sender keys and stops accepting that node’s keys. It protects subsequent access, but it cannot take back content already read or copied.
Keyring model · History grants · Daemon and nodes · Read or read + drive · Trust offers
A room gives context. Trust gives access.
A node shares a named service with a room. The host checks both its keyring and current room membership when a member connects. An invitation alone is not permission to reach the service.
The address is service.node.room.vox. The service name comes from its sharer; the node and room aliases are yours. The address identifies a service, not an SSH endpoint implied by a room or a node alone.
Removing a share or withdrawing trust cuts its live sessions. There is no extra per-service permission matrix. File sharing uses a room-bound service and a pull model; file data does not become a server-hosted chat attachment.
Classical and post-quantum, together
Vox’s hybrid design combines two families of algorithms. That describes a construction, not a guarantee that either family is infallible.
| Purpose | Classical | Post-quantum |
|---|---|---|
| Key agreement | X25519 | ML-KEM-768 |
| Signatures | Ed25519 | ML-DSA-65 |
Keys protect content. Comparing fingerprints and choosing the right nodes to trust remain human responsibilities. A compromised endpoint can expose plaintext regardless of the algorithms used in transit.
No central messaging operator
Rooms live on member nodes. Reachable, user-run anchors help peers find one another, coordinate connections, and relay encrypted traffic when needed.
An anchor acting only as an intermediary holds no room keys or room log. A node can also be a room member; in that role it reads only according to the same keyring rules as other members. Being an anchor does not confer special read access.
Members that are never online together can exchange retained messages through another member that overlaps with both. An anchor that is not a member is not a store-and-forward mailbox.
Anchor storage boundary · Offline members · Reachability design
What encryption cannot promise
- No read-receipt inference. A connection or a received sender key does not prove someone read a message.
- No protection from a trusted recipient’s copy. Retention removes content from cooperating nodes. It cannot erase screenshots or copies elsewhere.
- No anonymity guarantee. Traffic timing, volume, and connection information can remain observable.
- No endpoint-compromise guarantee. Malware, a keylogger, or access to a running node can expose content and secrets.
- No guaranteed reachability. Offline nodes, blocked paths, and unavailable intermediaries can delay or prevent delivery.
The daemon can run several attached nodes independently. Detaching one is not the same as locking the machine or stopping every other node. The keyring’s passphrase window concerns trust changes, not whether an attached node continues running.
What this release does, and does not
This page describes v0.4.0, which the installation guide and the one-line installer give you: the terminal client on x86_64 Linux and on Apple Silicon Macs with macOS 13 or later, and there Vox.app, the native Mac app, beside it. The homepage’s app study is illustrative, not a screenshot of the app.
The app shows a notification for each message in a room you are not looking at, grouped by room: who wrote, and whether it was to you, urgent or a file, never the message’s text. Its text and controls meet WCAG 2.1 AA contrast, with brighter colours when Increase Contrast is on; that is a claim about contrast only.
Each node keeps a 14-day record of what it refused and every change of access it decided, sealed at rest under the node’s identity and never sent anywhere. The family LAN puts a room’s trusted members on one subnet; on a Mac its helper is a system service that creates network interfaces for Vox and nothing else. Deniable mode is not part of the design, not advertised as a privacy guarantee.
Source inspection is not an independent security audit. Check the release milestone, the release notes and the implementation before relying on a capability.