Trust
Security at
Stackroom.
Stackroom's privacy model starts in the browser: private project content is encrypted before it reaches the backend.
Client-side encryption
Encryption and decryption of private project content happen in the browser using the Web Crypto API. Stackroom currently uses AES-256-GCM for encrypted project data.
Private Vault
Your vault passphrase is used locally to derive a cryptographic wrapping key. That wrapping key protects your encrypted master key, which is then used to encrypt and decrypt private project content inside the browser.
The vault passphrase is not sent to Stackroom's server.
What the server stores
- Encrypted project payloads and encryption metadata
- Encrypted master-key metadata required by the Private Vault
- Account identifiers required for ownership isolation
- GitHub integration metadata
- Encrypted GitHub access and refresh tokens
GitHub tokens
GitHub tokens follow a different security model from Private Vault project content. The backend must use GitHub access tokens to communicate with GitHub on your behalf, so those tokens are encrypted at rest on the server rather than encrypted with your Private Vault.
Application hardening
- Authenticated per-user ownership checks
- Restrictive Content Security Policy
- Restricted public asset serving
- Request body limits and encrypted payload validation
- Cross-origin write protection
- XSS and unsafe URL protections
- Security and migration regression tests
Threat model
Client-side encryption reduces the amount of plaintext private project data available to the backend. However, Stackroom currently serves the frontend JavaScript responsible for encryption.
A compromised or malicious frontend deployment could theoretically attempt to access information while it is decrypted in the browser. Stackroom therefore does not claim absolute zero-knowledge protection against every possible operator or frontend compromise scenario.
Responsible disclosure
If you discover a security issue, please avoid publishing exploitable details before there has been a reasonable opportunity to investigate.
Contact contact@stackroom.site.