Security

Security you can read about in plain language.

No absolute guarantees, no theater. A precise description of what Cloak Dagger protects, how it is built, and where the honest limits sit.

Nearby communication

A local network is a transport, not a trust boundary.

Cloak Dagger Nearby supports encrypted text in existing verified one-to-one chats and groups over a shared local Wi-Fi network or hotspot. The local network does not grant conversation access.

What the design protects

Text is encrypted with the existing conversation key before the peer transport receives it. Peer transport encryption is an additional layer, not a replacement for Cloak Dagger E2EE. Local Wi-Fi does not determine who is trusted or authorized.

Local-network risks

  • A hostile hotspot owner or another user on the same LAN may observe or disrupt traffic.
  • Attackers may attempt replay or peer impersonation; identity and conversation authorization must remain authoritative.
  • Short-lived QR setup data can be copied before it expires; expired or mismatched codes must be rejected.
  • A lost or compromised device can still expose information already available to that device.
  • A device offline during a remote revocation cannot know about that revocation until it receives authenticated state.
  • Nearby requires everyone to share a local network and does not provide unlimited range or multi-hop routing.

Nearby supports verified one-to-one and group text; group messages are sent to connected members and may be partially delivered until internet synchronization. Reactions and attachments are not available over Nearby. Every participant must first connect on a shared local network, and a membership removal cannot reach a device while it is offline.

Principles

How Cloak Dagger is built.

End-to-end encryption

Message content is encrypted on your device and decrypted only by the intended recipients. The server relays ciphertext it cannot read.

Local-first intelligence

AI memory, retrieval, and reasoning run on your device through a Web Worker. Conversations never become training material.

No silent cloud

Cloud processing is off by default. If you ever allow it, Cloak Dagger asks first and labels the answer. There is no configuration in which Cloak Dagger uploads context quietly.

Trusted devices only

Every device that holds your conversations is listed and revocable. Linking a new device is an explicit, verifiable act.

No secrets in the client

Model artifacts are delivered from object storage via public or short-lived URLs. Access keys never exist in the app bundle.

No tracking by default

No analytics SDKs, no ad networks, no session replay, no fingerprinting. Operational metrics, if any, exclude message and AI content.

Threat model

What Cloak Dagger is designed to reduce.

A threat model states exposures honestly — including the ones that remain.

Service-provider message access

Conversation content is end-to-end encrypted; the relay cannot read it.

Cloud AI prompt retention

AI retrieval and reasoning run locally; prompts are not sent to cloud models by default.

Public phone-number identity

People reach you by Cloak Dagger ID — there is no public phone-number identity.

Casual device observation

Cloak Mode reduces previews, sender details, and activity indicators.

Uncontrolled group membership

Groups and Circles are invite-only with controlled membership and no open invitation links.

Stale trusted devices

Every authorized device is visible and revocable in one step.

Message retention beyond user intent

Ghost Chats are configured to disappear from Cloak Dagger on the timer you choose.

What Cloak Dagger cannot protect against

  • Cloak Dagger cannot protect a conversation if an authorized device is already compromised.
  • Cloak Dagger cannot prevent another participant from photographing their screen.
  • A PWA cannot guarantee every OS-level anti-capture control.
  • Blockchain settlement is public. Cloak Dagger does not claim payment anonymity.

Encryption

How message and device protection works.

Plain-language architecture — the detailed cryptographic review is part of the planned independent assessment.

Message content

Conversation content is encrypted on the sending device using keys derived per conversation, and decrypted only on the recipient's device. The server relays encrypted payloads and cannot read them.

Keys on your device

Identity keys are generated on your device when your account is created. Your private key is wrapped with your passphrase for backup — Cloak Dagger cannot recover it for you.

Media stays on devices

Shared documents, images, and videos are transferred directly between the devices in a conversation. The server does not store your attachments.

Devices and recovery

Every authorized device is listed and revocable. New device linking is an explicit act; access requires your credentials.

Dagger

Emergency device control.

Dagger destroys local Cloak Dagger keys first, then removes application-controlled sensitive data and revokes the device.

Keys first.

Cloak Dagger's Dagger flow is designed to invalidate the cryptographic material required to use local encrypted data before slower storage cleanup runs. Keys go first — always.

Remote Dagger

Remote Dagger revokes a device immediately. If the target is offline, local data destruction cannot occur until the device reconnects.

Dagger removes Cloak Dagger-controlled local data and device authorization. It does not delete your account or membership, and it cannot remove operating-system or browser artifacts outside Cloak Dagger's control.

Groups & Circles

Organizing trust without a public graph.

The Circle model is designed so trust stays controlled — and stays private.

Invite-only membership

Members are added deliberately by the people who own the group. There are no open invitation links, no discovery, and no follower graph.

Group-level visibility

A person can belong to a Circle without automatically seeing every group inside it. Membership and visibility are managed per group.

Same encryption model

Group conversations use the same device-side encryption model as one-to-one chats, and local-first intelligence rules apply unchanged.

Status — private groups and Cloak Dagger Circles are live in member accounts: server-enforced membership and roles, least-privilege invite links that grant only the groups you select, circle security policies, archiving, and a private activity log. Capabilities ship further refinements over time on the same model described above.

Cloak Dagger AI

What stays local, and when cloud can occur.

The local path

Memory, retrieval, and reasoning run on your device. The model does not search your entire message history — only the small context permitted for the request is selected. AI prompt context is not sent to a cloud model when Cloak Dagger is operating on the local path.

The cloud boundary

Cloud processing is off by default and never silent. You can choose local-only, ask-before-cloud, or allow-cloud — and every answer is labeled with where processing happened.

Metadata & infrastructure

What the server sees.

Precision here matters more than comfort.

Sees

  • Account identifiers and membership state.
  • Routing metadata required to deliver messages — which conversations exist and when traffic occurs.
  • Payment verification data for direct USDC settlement, kept separate from messaging identity.

Cannot read

  • Message content — end-to-end encrypted on devices.
  • Attachments — media moves device-to-device and is not stored server-side.
  • AI prompts and local memory — they never leave the local path.

Audit status

Independent security assessment

Planned

An independent assessment of the cryptographic protocol layer and application security is planned before wide-scale marketing. Cloak Dagger does not claim independent verification until a report exists.

Responsible disclosure

Report a vulnerability

  • Scope: the public website and the Cloak Dagger application.
  • Good-faith research within scope will not be met with legal action.
  • Prohibited: testing against real user accounts, denial of service, or data exfiltration.

Send responsible-disclosure reports to security@cloakdagger.app with the affected route, severity, impact, and safe reproduction notes. No vulnerability bounty program is offered at this time.

Privacy

What this product does not do.

The practices below are implemented today, not aspirations.

No advertising and no behavioral tracking anywhere in the product.

No analytics SDKs, session replay, or fingerprinting — including in the app.

Message content is end-to-end encrypted; attachments never touch the server.

AI prompts and local memory stay on your device unless you explicitly allow cloud processing.

Payment verification is separated from your Cloak Dagger identity.

Marketing analytics, if ever used, stay isolated from application telemetry and never capture messages, prompts, tokens, or payment details.

Account terms, privacy details, refund/payment questions, and institutional legal requests are handled through onboarding until the formal public policy pages are approved.

Evaluating Cloak Dagger for an organization?

Request a private briefing with the Cloak Dagger team.

For conversations that should remain under your control.