Security
Security Model
What pocketty protects, who can see what, and what it leaves to you.
pocketty’s rule is simple: your terminal and your agents’ work stay between your phone and your computers. The one service we run, the push relay, only ever carries sealed bytes.
Who Sees What
| Party | Sees | Never sees |
|---|---|---|
| Your phone | Everything you open in pocketty | n/a |
| Your host | Everything, it is your computer | n/a |
| The push relay | A push token, the size of a sealed note, the time, your IP address | Terminal text, agent names, host names, keys |
| Apple Push | The sealed note, and the text “pocketty: Agent update” | What the note says |
| Tailscale | That your devices talk, under Tailscale’s own model | The SSH traffic, which is encrypted end to end |
| Us | Nothing about your use of the App. The App has no account and no analytics. The website counts visits without cookies: see Privacy | n/a |
The Terminal Path
The App opens SSH connections straight to your hosts. No pocketty server is on that path.
- Host keys are pinned on first use, or given by the daemon during code setup. A changed key stops the connection.
- Agent forwarding is off.
- One connection per host carries the shells, the herdr socket, the Pane streams and uploads.
The Notification Path
Notifications are optional. When they are on:
- The daemon on your host writes a short note: agent, state, host, workspace and tab. Never terminal text.
- It seals the note with HPKE in auth mode for your phone’s key. Only your phone can open it, and the phone can tell which daemon sealed it.
- The relay checks a signed grant and forwards the sealed bytes to Apple. It stores nothing, and its logs are off.
- The notification extension on your phone opens the seal and shows the text.
The details are in Sealed Notifications.
Keys
- Your device key is a P-256 key made in the Secure Enclave. It cannot leave the phone.
- Imported keys stay in the phone’s Keychain.
- The App lock can ask for Face ID before any connection.
See Keys.
Adding a Key with a Code
The daemon listens for code setup on the host’s Tailscale addresses only. It asks Tailscale who is calling, accepts only devices of the host’s own Tailscale user, and adds the key only after someone at the host types the six-digit code that the phone shows. See Keys.
What pocketty Does Not Protect Against
- A compromised host. It runs your agents and your shell. pocketty can’t hide anything from it.
- A compromised phone. If someone controls your unlocked phone, they control pocketty too. The App lock adds one step.
- Metadata at the relay. The relay sees when a notification passes and how big it is. It does not keep it.