Security
No absolute guarantees, no theater. A precise description of what Cloak Dagger protects, how it is built, and where the honest limits sit.
Nearby communication
Cloak Dagger Nearby supports encrypted text in existing verified one-to-one chats and groups over a shared local Wi-Fi network or hotspot. The local network does not grant conversation access.
Text is encrypted with the existing conversation key before the peer transport receives it. Peer transport encryption is an additional layer, not a replacement for Cloak Dagger E2EE. Local Wi-Fi does not determine who is trusted or authorized.
Nearby supports verified one-to-one and group text; group messages are sent to connected members and may be partially delivered until internet synchronization. Reactions and attachments are not available over Nearby. Every participant must first connect on a shared local network, and a membership removal cannot reach a device while it is offline.
Principles
Message content is encrypted on your device and decrypted only by the intended recipients. The server relays ciphertext it cannot read.
AI memory, retrieval, and reasoning run on your device through a Web Worker. Conversations never become training material.
Cloud processing is off by default. If you ever allow it, Cloak Dagger asks first and labels the answer. There is no configuration in which Cloak Dagger uploads context quietly.
Every device that holds your conversations is listed and revocable. Linking a new device is an explicit, verifiable act.
Model artifacts are delivered from object storage via public or short-lived URLs. Access keys never exist in the app bundle.
No analytics SDKs, no ad networks, no session replay, no fingerprinting. Operational metrics, if any, exclude message and AI content.
Threat model
A threat model states exposures honestly — including the ones that remain.
Conversation content is end-to-end encrypted; the relay cannot read it.
AI retrieval and reasoning run locally; prompts are not sent to cloud models by default.
People reach you by Cloak Dagger ID — there is no public phone-number identity.
Cloak Mode reduces previews, sender details, and activity indicators.
Groups and Circles are invite-only with controlled membership and no open invitation links.
Every authorized device is visible and revocable in one step.
Ghost Chats are configured to disappear from Cloak Dagger on the timer you choose.
Encryption
Plain-language architecture — the detailed cryptographic review is part of the planned independent assessment.
Conversation content is encrypted on the sending device using keys derived per conversation, and decrypted only on the recipient's device. The server relays encrypted payloads and cannot read them.
Identity keys are generated on your device when your account is created. Your private key is wrapped with your passphrase for backup — Cloak Dagger cannot recover it for you.
Shared documents, images, and videos are transferred directly between the devices in a conversation. The server does not store your attachments.
Every authorized device is listed and revocable. New device linking is an explicit act; access requires your credentials.
Dagger
Dagger destroys local Cloak Dagger keys first, then removes application-controlled sensitive data and revokes the device.
Cloak Dagger's Dagger flow is designed to invalidate the cryptographic material required to use local encrypted data before slower storage cleanup runs. Keys go first — always.
Remote Dagger revokes a device immediately. If the target is offline, local data destruction cannot occur until the device reconnects.
Dagger removes Cloak Dagger-controlled local data and device authorization. It does not delete your account or membership, and it cannot remove operating-system or browser artifacts outside Cloak Dagger's control.
Groups & Circles
The Circle model is designed so trust stays controlled — and stays private.
Members are added deliberately by the people who own the group. There are no open invitation links, no discovery, and no follower graph.
A person can belong to a Circle without automatically seeing every group inside it. Membership and visibility are managed per group.
Group conversations use the same device-side encryption model as one-to-one chats, and local-first intelligence rules apply unchanged.
Status — private groups and Cloak Dagger Circles are live in member accounts: server-enforced membership and roles, least-privilege invite links that grant only the groups you select, circle security policies, archiving, and a private activity log. Capabilities ship further refinements over time on the same model described above.
Cloak Dagger AI
Memory, retrieval, and reasoning run on your device. The model does not search your entire message history — only the small context permitted for the request is selected. AI prompt context is not sent to a cloud model when Cloak Dagger is operating on the local path.
Cloud processing is off by default and never silent. You can choose local-only, ask-before-cloud, or allow-cloud — and every answer is labeled with where processing happened.
Metadata & infrastructure
Precision here matters more than comfort.
Audit status
Planned
An independent assessment of the cryptographic protocol layer and application security is planned before wide-scale marketing. Cloak Dagger does not claim independent verification until a report exists.
Responsible disclosure
Send responsible-disclosure reports to security@cloakdagger.app with the affected route, severity, impact, and safe reproduction notes. No vulnerability bounty program is offered at this time.
Privacy
The practices below are implemented today, not aspirations.
No advertising and no behavioral tracking anywhere in the product.
No analytics SDKs, session replay, or fingerprinting — including in the app.
Message content is end-to-end encrypted; attachments never touch the server.
AI prompts and local memory stay on your device unless you explicitly allow cloud processing.
Payment verification is separated from your Cloak Dagger identity.
Marketing analytics, if ever used, stay isolated from application telemetry and never capture messages, prompts, tokens, or payment details.
Account terms, privacy details, refund/payment questions, and institutional legal requests are handled through onboarding until the formal public policy pages are approved.
Request a private briefing with the Cloak Dagger team.