docsget pocketty

Security

Security Model

What pocketty protects, who can see what, and what it leaves to you.

pocketty’s rule is simple: your terminal and your agents’ work stay between your phone and your computers. The one service we run, the push relay, only ever carries sealed bytes.

Who Sees What

PartySeesNever sees
Your phoneEverything you open in pockettyn/a
Your hostEverything, it is your computern/a
The push relayA push token, the size of a sealed note, the time, your IP addressTerminal text, agent names, host names, keys
Apple PushThe sealed note, and the text “pocketty: Agent update”What the note says
TailscaleThat your devices talk, under Tailscale’s own modelThe SSH traffic, which is encrypted end to end
UsNothing about your use of the App. The App has no account and no analytics. The website counts visits without cookies: see Privacyn/a

The Terminal Path

The App opens SSH connections straight to your hosts. No pocketty server is on that path.

  • Host keys are pinned on first use, or given by the daemon during code setup. A changed key stops the connection.
  • Agent forwarding is off.
  • One connection per host carries the shells, the herdr socket, the Pane streams and uploads.

The Notification Path

Notifications are optional. When they are on:

  1. The daemon on your host writes a short note: agent, state, host, workspace and tab. Never terminal text.
  2. It seals the note with HPKE in auth mode for your phone’s key. Only your phone can open it, and the phone can tell which daemon sealed it.
  3. The relay checks a signed grant and forwards the sealed bytes to Apple. It stores nothing, and its logs are off.
  4. The notification extension on your phone opens the seal and shows the text.

The details are in Sealed Notifications.

Keys

  • Your device key is a P-256 key made in the Secure Enclave. It cannot leave the phone.
  • Imported keys stay in the phone’s Keychain.
  • The App lock can ask for Face ID before any connection.

See Keys.

Adding a Key with a Code

The daemon listens for code setup on the host’s Tailscale addresses only. It asks Tailscale who is calling, accepts only devices of the host’s own Tailscale user, and adds the key only after someone at the host types the six-digit code that the phone shows. See Keys.

What pocketty Does Not Protect Against

  • A compromised host. It runs your agents and your shell. pocketty can’t hide anything from it.
  • A compromised phone. If someone controls your unlocked phone, they control pocketty too. The App lock adds one step.
  • Metadata at the relay. The relay sees when a notification passes and how big it is. It does not keep it.

    Type to search keys, notifications, the CLI, and more.