Onera Docs
E2EE Architecture

Industry Comparison

Comparison with Signal, Ente, Bitwarden, and ProtonMail

Comparison with Industry Standards

Signal Protocol

AspectSignalOnera
Use CaseMessagingAI chat + credentials
Key ExchangeX3DH + Double RatchetX25519 sealed boxes
Forward SecrecyPer-message (ratchet)Per-chat key
Key RecoveryNone (by design)BIP39 recovery phrase
Multi-deviceLinked devicesIndependent device shares

Key Difference: Signal prioritizes forward secrecy via ratcheting; Onera prioritizes recoverability while maintaining strong encryption.

Ente

AspectEnteOnera
Use CasePhoto storageAI chat
Recovery24-word phrase24-word phrase (same approach)
Key ShardingNot documented3-share XOR
Session SecurityStandardNon-extractable Web Crypto

Inspiration: Onera's recovery mechanism is modeled after Ente's approach.

Bitwarden

AspectBitwardenOnera
Use CasePassword managerAI chat
KDFPBKDF2/Argon2idArgon2id (always)
Key DerivationMaster password onlyPassword + device + recovery
Server TrustEncrypted vaultEncrypted + sharded keys

Key Difference: Onera's 3-share system provides additional protection beyond password-derived encryption.

ProtonMail

AspectProtonMailOnera
Use CaseEmailAI chat
EncryptionOpenPGPlibsodium
Key StorageEncrypted on serverSharded across systems
RecoveryRecovery phraseRecovery phrase

Key Difference: ProtonMail stores encrypted private keys on server; Onera distributes shares.

Summary Comparison Matrix

PropertySignalEnteBitwardenOnera
E2E Encryption
Forward Secrecy✓✓--
Key Recovery
Multi-device
Key Sharding---
XSS ProtectionN/A--
Passkey Support--
Zero-Knowledge

Legend: ✓ = supported, ✓✓ = exceptional, - = not applicable/limited, ✗ = not supported

Key Differentiators

What Sets Onera Apart

  1. 3-Share Key Sharding

    • No single point of failure
    • Requires compromise of multiple independent systems
  2. Non-Extractable Session Keys

    • Web Crypto API protection against XSS
    • Keys cannot be exported even with code execution
  3. Direct LLM API Access

    • API calls bypass Onera servers
    • Zero visibility into user conversations
  4. WebAuthn PRF Integration

    • Hardware-bound authentication
    • No password required for daily use

On this page