How Termix protects your data

What the server can see

  • Your email address.
  • A hash of a login key derived from your master password.
  • The number of items you have, and their type (server, password, key, group).
  • Encrypted blobs, and some non-secret bookkeeping such as revision numbers.

What it can never see

  • Your master password.
  • Server names, hostnames, ports, or usernames.
  • Passwords and SSH private keys.
  • Your notes and tags.

How it works

  1. Your master password is stretched with Argon2id on your device.
  2. That produces two separate values: a login key the server checks, and a wrapping key that never leaves your device.
  3. The wrapping key protects a random vault key, which is the key that actually encrypts your data with XChaCha20-Poly1305.
  4. Because the vault key never changes, changing your master password only rewrites a small key file. Your saved servers stay exactly as they are.
  5. Losing your master password is recoverable with the recovery key shown once at signup. The server cannot reset it for you, by design.