Skip to content

What we can and can't see

What we (the roamd service) can see

Yes, we can see No, we can't see
Your email address Your master password
That you have an account, and when you log in What's inside your vault
The names of your computers, and whether they're online Your browser key
When you connect to a computer, and for how long Anything you type or see in a terminal
Your internet address (as any website does) Your recovery key
What Voice says or hears (it all happens in your browser)
 what travels through us:

   your typing  --> [ LOCKED ] --> passes through us --> [ LOCKED ] --> your computer
                       ^                                    ^
                 locked by your                     unlocked only by
                 browser                            your computer

Cloudflare, the network company in front of our website, handles the same traffic we do, so it can see the same things we can (the left column), and nothing in the right column.

If our servers were broken into

Someone who stole our database would get emails and locked vaults. To open a vault they'd have to guess your master password, and every guess is deliberately slow. A long, unique master password keeps you safe even then.

Limits

We'd rather you hear these from us.

  • roamd is a website. Your browser runs code our server sends it. If someone took over our server, they could send changed code that captures your password as you type it. We block code from anywhere else, but the real fix is the downloadable apps we plan to make, whose code is signed and doesn't change behind your back.
  • Emails aren't verified yet, and there's no check yet when you log in from a new device (coming: an emailed code, or Face ID / fingerprint).
  • An open terminal stays open if you revoke a browser's access or remove the computer, until it's closed.
  • Mac and Windows versions haven't yet been tested on real computers.
  • This is a preview: don't rely on it for anything critical yet.

Data inventory (hub)

Data Stored as Purpose
Email Plain, normalised Account lookup
Salt, Argon2 settings Plain Client key derivation
Login and recovery proofs Hashed Authentication
Vault key Sealed twice (password key, recovery key) Unlocked client-side only
Vault items XChaCha20-Poly1305 ciphertext + revision Sync (browser key, host pins, Voice settings)
Sessions and device tokens Hashed Web sessions, machine connections
Devices Owner, name, host public key Routing
Transient (memory only) Login challenges, pending approvals, online tunnels, rate-limit counters —
Logs Startup and errors only: no request log, no bodies, no shell data Operations

The database is owner-only on the hub host. It contains no key that decrypts user data or logs in to a machine (tested: no raw proofs or tokens on disk).

Threat model

Adversary Protected Not protected
Network attacker TLS to the hub; SSH end to end; pinned host keys Traffic analysis (timing, sizes)
Cloudflare (in front of the hub) Shell traffic, vault contents, keys The same metadata the hub sees
Hub database leak Vault contents (Argon2id-bound); tokens and sessions (hashed) Emails, device names; offline guessing of weak master passwords
Malicious or compromised hub (passive) Shell traffic, vault, keys Metadata: who connects to what, when
Malicious or compromised hub (active) Machine authorisation (pairing codes), host impersonation (pins) Serving modified web-app code (see below); denial of service
Stolen device token Can't impersonate the machine (no host key) Can connect to the hub as that device (disruption)
Copied machine settings Sealed on Windows/macOS Linux relies on file permissions
Malware on the user's machine or browser — Out of scope (as for any remote-access tool)

Limits

  • Web-delivered code: the web app (including its WebAssembly crypto) is served by the hub. An active hub compromise could serve code that captures the master password. Today's mitigations: a strict Content-Security-Policy (no third-party or inline script) and TLS. The structural fix is native apps or signed, pinned web bundles.
  • Account security: no email verification and no new-device check yet (planned: emailed code, then passkeys).
  • Revocation: revoking a key or removing a machine stops new logins at once; terminals already open stay open until closed.
  • Platform coverage: the macOS and Windows agents haven't been tested on real hardware yet (Windows code paths are tested under Wine).
  • Voice: Private mode never sends terminal text or audio off the device (see Voice). A planned cloud "Smart mode" would, and will be opt-in and labelled.
  • Preview: not yet for critical use.