Skip to content

About

Inspectable cryptographic core for Agent Layer's encrypted personal-data vault

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Agent Layer Crypto

The inspectable cryptographic core used by Agent Layer's encrypted personal-data vault.

This repository contains the code that derives vault keys, seals records and documents, creates device envelopes, signs enrollment and recovery transcripts, and implements two-of-three recovery sharing. It intentionally depends only on the @noble and @scure families and has no dependency on Agent Layer applications or hosted services.

Status

  • Public source, licensed under MIT.
  • Pre-1.0 API: wire formats are compatibility-sensitive and may change only with an explicit migration.
  • Covered by 42 unit, known-answer, tamper, isolation, replay, and round-trip tests.
  • Not independently audited. Public source is evidence, not a security certification.
  • The package identity is @agent-layer/crypto; npm publication is a separate release step.

What It Implements

  • 256-bit vault master-key generation.
  • Domain-separated HKDF-SHA256 keys for chunks and blobs.
  • XChaCha20-Poly1305 authenticated encryption with canonical associated data.
  • X25519 sealed envelopes for registered devices and relay inboxes.
  • Ed25519 signatures over canonical device and recovery transcripts.
  • Optional BIP39 phrase-derived wrapping for advanced recovery.
  • Two-of-three Shamir recovery sharing over GF(256).
  • Strict base64 wire encodings with malformed-input rejection.

See the security model for exact boundaries and non-claims.

Verify It

Requirements: Node.js 22+ and Corepack.

corepack enable
pnpm install --frozen-lockfile
pnpm check

Committed compatibility vectors live beside the implementation in test/. If a derivation or canonical transcript vector changes, treat it as a vault-breaking protocol change, not as a routine test update.

Public-Source Boundary

This repository is a clean export of the cryptographic package from Agent Layer's private product monorepo. It does not contain the hosted vault service, Plaid credentials or operations, billing, deployment configuration, customer data, or private product planning.

The export begins with fresh public history so deleted files, credentials, and internal documents from the private monorepo cannot be recovered through Git history.

Security

Please do not report suspected vulnerabilities in a public issue. Follow SECURITY.md to send a private report.

License

MIT. See LICENSE.

About

Inspectable cryptographic core for Agent Layer's encrypted personal-data vault

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages