Security model and trade-offs
What an attacker can hold, what stops each, what each still costs, and what the protocol deliberately does not do.
What the protocol relies on
Who am I talking to: a root pinned from a card or an invite exchanged human to human, and every call proving the leaf key of a chain that validates to it and names the address in use. Consent: manual approval on both sides, always. Wire privacy: TLS 1.3 between the two endpoints, and sealed envelopes past terminating edges. Revocation: delete the contact or the invite server-side, instantly and locally; a host’s authority ends at its leaf’s notAfter, or the moment a newer leaf reaches a contact — no CRL, no OCSP. Replay: an idempotent msg_id per call. Spam: a guest tier of two tools, invites with expiry and uses, and call budgets. Prompt injection: every inbound string is untrusted data, length-capped, never concatenated into the agent’s instructions, and rendered to humans as quoted content (§ 11).
What an attacker can hold
The compromise table names, for each thing an attacker can hold, what stops it and what remains (§ 14.5). The root: nothing cryptographic, by decision — whoever holds the root is the person; what makes the theft hard is the wallet’s own window and the deliberate act asked again for a new endpoint, what lets contacts notice a move the person never made is the ask setting and the event shown under auto, and what prevents the theft is a root there is no vault to steal, in a hardware key or derived from a passkey; what remains is a new identity, re-shared over human channels. A leaf key, from a host: it speaks only from its one address and can neither issue nor move, a renewal with a fresh key outranks it with every contact it reaches, and it expires within the span the person chose; what remains is the contacts that exchange nothing until then, and ciphertext recorded to that key. A former host’s leaf, still valid after a move: the newest leaf wins with every contact reached, the campaign runs before the old host is told, the address is not reassigned until the leaf expires, and the host has a duty to delete. The wire: sealing, with the sender inside the ciphertext; what remains is messages tied to one recipient leaf for its life, no forward secrecy, and nothing post-quantum yet.
Blocked is indistinguishable from unknown
A rejected stranger’s next request receives the same answer any stranger gets, a blocked sender’s envelopes are processed exactly as an unknown sender’s, and the guest-tier error is one catch-all — so that neither a refusal nor a sealing answer becomes an oracle for who the owner knows (§ 5, § 12, § 13.3).
What was given up, and what it costs
Against an earlier hardened draft the text gave up a directory and SAS ceremonies, delegation-expiry machinery, root rotation, sequence windows, admission tokens and a transparency log, and says what each drop costs (§ 11). The non-goals stand: no forward secrecy at the envelope layer; edges see metadata; no anonymity or traffic-analysis resistance; no directory; no store-and-forward; no recovery and no rotation of a lost or compromised root; no post-quantum cryptography yet, deferred by decision with the path recorded (the non-goals, § 13.5).
Custodial hosting, stated plainly
A host holds the leaf key and can act as you while the leaf is valid — as every hosted service can — but never the root: its authority is written on a certificate you signed, for an address you saw, until a date you chose, and is outranked by the next leaf you sign (§ 11, § 9).