Explore the technical foundations behind EnvX: AES-256 GCM authenticated encryption, hardware-anchored OS keychains, and automated git leak shields.
Security Whitepaper v1.0•Zero-Knowledge Verified•Back to Home
Pillar 1: Authenticated Encryption
AES-256 GCM At-Rest Encryption
Every environment variable value stored by EnvX is sealed using Advanced Encryption Standard in Galois/Counter Mode (AES-256 GCM) with 256-bit symmetric keys. GCM provides both confidentiality and cryptographic integrity verification via a 128-bit authentication tag.
Key Length:256-bit (32 bytes) cryptographically random
IV / Nonce:96-bit unique CSPRNG nonce per ciphertext
Auth Tag:128-bit tag verifying zero ciphertext tampering
Pillar 2: Hardware Key Derivation
Machine-Locked OS Keychains
Master encryption keys and authentication tokens are never saved to unencrypted flat files. Instead, they are delegated directly to native operating system credential managers:
Windows: Protected via Windows Data Protection API (DPAPI) and Windows Credential Manager, anchored to the user logon SID and TPM chip.
macOS: Stored inside the Apple Keychain Services enclave, protected by Secure Enclave hardware and user biometric/PIN gates.
Linux: Enforced via libsecret and the FreeDesktop Secret Service API (backed by GNOME Keyring or KWallet).
Pillar 3: Version Control Shield
.gitignore Leak Safety Guard
The single largest cause of enterprise secret breaches is accidental git commit of plaintext .env files. EnvX implements a mandatory filesystem safety hook:
Whenever a workspace is loaded or an environment is selected, EnvX scans the root directory for a .gitignore file.
If .env or active target files are unignored, the application blocks automated file flushes, displays a prominent warning badge in the UI, and offers a 1-click safe patch to append .env to .gitignore.
Pillar 4: Memory & UI Hygiene
Zero-Spill UI Masking & Memory Zeroing
All secret fields in the EnvX desktop UI are masked by default (••••••••) to protect against screen-sharing leaks, casual shoulder-surfing, or automated screenshot captures. In-memory secret strings are allocated in transient buffers and garbage-collected immediately upon OSD dismiss.
Responsible Vulnerability Disclosure
We welcome security researchers and ethical hackers to audit EnvX. If you discover a vulnerability, please disclose it responsibly according to RFC 9116:
Security Team Contact:
Report vulnerabilities directly to
security@envx.dev
. We acknowledge reports within 24 hours and do not pursue legal action against ethical security research.