Technical details

How unlocking, encryption and sync work, so you can check the claims yourself. Describes the current testnet beta.

Unlocking

Verus Notes never sees your recovery phrase or spending keys. Your wallet sends one app-specific viewing key, sealed to a one-time address that only this unlock attempt can open.

  • Verus Notes on your computer
  • Request signer AWS KMS
  • Your Verus wallet holds your keys
  • Unlock relay Cloudflare
  1. Verus Notes to Request signer One-time address
  2. Request signer to Your Verus wallet Signed request, by QR or link
  3. Your Verus wallet to Unlock relay Sealed key, signed by you
  4. Unlock relay to Request signer Read once, then deleted
  5. Request signer to Verus Notes Sealed response
  6. Verus Notes Verifies your signature and the request ID, then opens it with the one-time key
Request signing
Signed with Verus Notes' app identity. The key lives in AWS KMS and can't be exported.
What the wallet returns
An incoming viewing key for Verus Notes' channel only. Spending keys are never requested, and a response containing one is rejected.
Accepted only if
Your VerusID's signature checks out at its signing height, the chain is VRSCTEST, the request ID matches, and it was created within the last hour.
Relay
Holds one sealed response for up to 90 seconds, deletes it on read, and keeps no logs. It can delay an unlock, not read one.

Keys

Every key comes from the viewing key your wallet sends. Secret keys live only in memory and are never written to disk or sent anywhere.

Incoming viewing key From your wallet, wiped after use

HKDF-SHA256 salted with your vault's context

Vault root key In memory while unlocked

  • Note keys One per note and version
  • Folder keys One per folder
  • Sync sign-in key Ed25519. Server keeps the public half
  • Backup key Seals .verusnotes files
  • Vault ID A hash, so the server can file records

Encryption

Cipher
XChaCha20-Poly1305
Nonce
24 random bytes from the operating system, new for every save.
Bound to its record
The vault ID, record ID and format versions are authenticated with each ciphertext, so a record can't be passed off as another.
Padding
Each note is padded to 1, 4, 16, 64, 256 or 512 KB before it's encrypted.
Encrypted
Titles, text and bookmarks, which folder a note is in, and folder names and order.
Not encrypted
Vault ID, record IDs, format versions, padded size and sync state. On your computer, also when each note was created, last edited or deleted.

What's stored where

PlaceWhat it holdsKept for
Your computer Encrypted notes and folders, plus record IDs, timestamps and sync state.Until you delete them. A deleted note leaves a small marker.
Sync server Convex, if you syncEncrypted notes and folders, vault ID, padded sizes, dates rounded to the day, a keyed hash of your VerusID and the sign-in public key.Until you delete your cloud copy. A deleted note's content is removed right away.
Request signer AWSYour VerusID and the one-time address for each unlock.Until the session expires
Unlock relay CloudflareOne sealed wallet response it can't open.Up to 90 seconds
Verus network Public APILookups of your VerusID while an unlock is checked.Outside Verus Notes' control
  • Your computer

    Encrypted notes and folders, plus record IDs, timestamps and sync state.

    Kept until you delete them. A deleted note leaves a small marker.

  • Sync server · Convex

    Encrypted notes and folders, vault ID, padded sizes, dates rounded to the day, a keyed hash of your VerusID and the sign-in public key.

    Kept until you delete your cloud copy. A deleted note's content is removed right away.

  • Request signer · AWS

    Your VerusID and the one-time address for each unlock.

    Kept until the session expires

  • Unlock relay · Cloudflare

    One sealed wallet response it can't open.

    Kept up to 90 seconds

  • Verus network

    Lookups of your VerusID while an unlock is checked.

    Outside Verus Notes' control

Sync sign-in

How the app signs in
It signs a one-time server challenge with its Ed25519 key. The server only ever sees the public key.
Tied to a wallet unlock
Before it issues a challenge, the server checks a one-time attestation from the request signer.
Sessions
Stored as a SHA-256 hash of the token and valid for 2 hours. Challenges expire after 5 minutes.
Free sync
20 notes and 2 MB in total, up to 512 KB per note. You choose which notes sync; the rest stay on your computer.
Deleting your cloud copy
Needs a wallet unlock from the last 10 minutes, then removes every record, session and usage count. Notes on your computer stay. Turning sync off doesn't delete it.

Backups

Format
A .verusnotes file sealed with XChaCha20-Poly1305 under the backup key. Each note inside stays individually encrypted.
What's inside
Every note and folder on this computer, including bookmarks and deletions.
Restoring
Only into the same vault, which means the same VerusID and wallet. Existing notes stay, and conflicting edits are kept side by side.
Checked on save
The app decrypts each backup right after writing it, so a broken file is caught straight away.

Open questions

Known gaps in the current beta. This list is updated as they're resolved.

Viewing key as secret
Using the wallet's incoming viewing key as the app's root secret still needs confirmation from the Verus maintainers.
Wallet support
App encryption requests are still experimental in Verus wallets.
Request signer
It limits abuse, but it can't prove a request came from the genuine app.
Compromised computer
Malware on an unlocked computer can read notes and use the sync key without a new wallet approval.
Backup size
Backup files aren't padded, so their size shows roughly how big a vault is.
Audits
No independent security audit yet. Dependencies are checked with pnpm audit and cargo audit.