How Termix protects your data
What the server can see
- Your email address.
- A hash of a login key derived from your master password.
- The number of items you have, and their type (server, password, key, group).
- Encrypted blobs, and some non-secret bookkeeping such as revision numbers.
What it can never see
- Your master password.
- Server names, hostnames, ports, or usernames.
- Passwords and SSH private keys.
- Your notes and tags.
How it works
- Your master password is stretched with Argon2id on your device.
-
That produces two separate values: a login key the server checks, and a
wrapping key that never leaves your device.
-
The wrapping key protects a random vault key, which is the key that actually
encrypts your data with XChaCha20-Poly1305.
-
Because the vault key never changes, changing your master password only
rewrites a small key file. Your saved servers stay exactly as they are.
-
Losing your master password is recoverable with the recovery key shown once at
signup. The server cannot reset it for you, by design.