EnvX
Home Features Pricing
Sign In Download App
Home
Features
Pricing
Sign In
Download App
Cryptographic Whitepaper

Zero-Knowledge Security Architecture

Explore the technical foundations behind EnvX: AES-256 GCM authenticated encryption, hardware-anchored OS keychains, and automated git leak shields.

Security Whitepaper v1.0 • Zero-Knowledge Verified • Back to Home
Pillar 1: Authenticated Encryption

AES-256 GCM At-Rest Encryption

Every environment variable value stored by EnvX is sealed using Advanced Encryption Standard in Galois/Counter Mode (AES-256 GCM) with 256-bit symmetric keys. GCM provides both confidentiality and cryptographic integrity verification via a 128-bit authentication tag.

Cipher Algorithm: AES-256 GCM (Galois/Counter Mode)
Key Length: 256-bit (32 bytes) cryptographically random
IV / Nonce: 96-bit unique CSPRNG nonce per ciphertext
Auth Tag: 128-bit tag verifying zero ciphertext tampering
Pillar 2: Hardware Key Derivation

Machine-Locked OS Keychains

Master encryption keys and authentication tokens are never saved to unencrypted flat files. Instead, they are delegated directly to native operating system credential managers:

  • Windows: Protected via Windows Data Protection API (DPAPI) and Windows Credential Manager, anchored to the user logon SID and TPM chip.
  • macOS: Stored inside the Apple Keychain Services enclave, protected by Secure Enclave hardware and user biometric/PIN gates.
  • Linux: Enforced via libsecret and the FreeDesktop Secret Service API (backed by GNOME Keyring or KWallet).
Pillar 3: Version Control Shield

.gitignore Leak Safety Guard

The single largest cause of enterprise secret breaches is accidental git commit of plaintext .env files. EnvX implements a mandatory filesystem safety hook:

  • Whenever a workspace is loaded or an environment is selected, EnvX scans the root directory for a .gitignore file.
  • If .env or active target files are unignored, the application blocks automated file flushes, displays a prominent warning badge in the UI, and offers a 1-click safe patch to append .env to .gitignore.
Pillar 4: Memory & UI Hygiene

Zero-Spill UI Masking & Memory Zeroing

All secret fields in the EnvX desktop UI are masked by default (••••••••) to protect against screen-sharing leaks, casual shoulder-surfing, or automated screenshot captures. In-memory secret strings are allocated in transient buffers and garbage-collected immediately upon OSD dismiss.

Responsible Vulnerability Disclosure

We welcome security researchers and ethical hackers to audit EnvX. If you discover a vulnerability, please disclose it responsibly according to RFC 9116:

Security Team Contact: Report vulnerabilities directly to security@envx.dev . We acknowledge reports within 24 hours and do not pursue legal action against ethical security research.
EnvXEnvX

The developer-first desktop manager for multi-environment secrets, encrypted storage, and instantaneous hotkey switching.

All systems operational

Product

Features Pricing Download Desktop Changelog

Resources

Documentation GitHub Repository Discord Community GitHub Discussions System Status

Security & Legal

Security Whitepaper Privacy Policy Terms of Service 30-Day Refund Policy RFC 9116 security.txt

© 2025–2026 EnvX Inc. Built for developers with zero-compromise security.

AES-256 GCM • Gitignore Safety • Offline First