Onera Docs
E2EE Architecture

Conclusion

Summary of Onera's security guarantees

Conclusion

Onera's end-to-end encryption architecture provides strong security guarantees for AI chat applications:

Security Guarantees

1. True Zero-Knowledge

The server operates exclusively as an encrypted blob store with no ability to access plaintext user data, even under compulsion.

2. Defense in Depth

Multiple independent security layers—3-share key sharding, memory-hard KDFs, non-extractable session keys, and per-chat encryption—ensure that compromising any single component is insufficient to breach user privacy.

3. Usability Without Compromise

Password, passkey, and recovery phrase authentication options provide flexibility without weakening the security model.

MethodSecurityConvenience
PasswordHigh (Argon2id)Medium
PasskeyVery High (Hardware-bound)High
Recovery PhraseHighEmergency only

4. Transparent Design

This architecture is open for independent security review and audit.

  • Source code available at /packages/crypto/
  • All algorithms are industry-standard and well-audited
  • No proprietary or custom cryptographic constructions

5. Direct LLM Access

By routing LLM API calls directly from client to provider, Onera eliminates itself as a potential point of data interception.

Summary

GuaranteeImplementation
ConfidentialityXSalsa20-Poly1305 AEAD, per-chat keys
IntegrityPoly1305 MAC, authenticated encryption
Forward SecrecyPer-chat keys, sealed box ephemeral keys
RecoveryBIP39 mnemonic, encrypted backup
Multi-DeviceDevice shares, re-sharding
Zero-KnowledgeServer stores only encrypted blobs

Contact

We welcome security researchers to review this architecture and report any findings.

Security Contact: security@onera.ai

On this page