Security
Encrypted end to end. Really.
Vyre.Api is designed as a blind relay — it moves and stores ciphertext, and by construction it never has the ability to decrypt what passes through it.
Security at a glance
Per-tab AES-256-GCM keys
Every terminal gets its own symmetric key, generated fresh at creation time — a leaked key exposes one tab, not your whole history.
X25519 key-wrapping per device
Each authorized device gets its own encrypted copy of a tab’s key. Vyre.Api forwards wrapped blobs it can never open.
MFA-gated recovery, not zero-trust-breaking
Lose every device and you can still recover scrollback — but only after a fresh re-authentication with multi-factor, escrowed through KaxlinCore.
No admin break-glass, ever
Nobody at Kaxlin — including us — can decrypt your terminal content outside your own devices or your own MFA-gated recovery flow. It’s a product principle, not a support feature.
The full flow
What happens, byte by byte
From the moment you open a tab to the moment it renders on another device — every hop in between only ever sees ciphertext.
A tab is created
Vyre.Host generates a fresh AES-256-GCM key for that tab alone — nothing is reused across sessions.
The key is wrapped per device
Using an ECIES-style X25519 exchange with a fresh ephemeral keypair per recipient, the tab key gets its own encrypted copy for every device you’ve authorized.
Ciphertext streams out
PTY output is encrypted before it ever leaves the Host process. Vyre.Api relays and stores bytes it has no ability to read.
Your device unwraps locally
WebCrypto in the browser, or the platform Keystore on Android, unwraps the tab key using a private key that never leaves that device.
Servers
A headless host you can trust on a server
A server running vyre-host gets the same end-to-end encryption as your PC. Adding one to your account works like this.
Approved in your browser
The server prints a code and a key fingerprint. Enter the code at vyre.kaxlin.com/pair, where you are already signed in, and approve only if the fingerprints match. The server never sees your password.
Its key is sealed to the machine
The server’s host key is encrypted to that machine’s own public key and handed over once. Vyre stores only the sealed copy. On disk it sits in an owner-only file on Linux, or under Windows DPAPI for the service account.
Runs as a user you name
Tabs run as the account you chose, so they can do what it can and nothing more. Root is refused unless you pass --allow-root, and the Windows service never runs as SYSTEM.
Nothing listening
The host only makes outbound HTTPS connections. There is no port to open and no inbound firewall rule to add.
Our commitments
Principles, not just settings
No admin break-glass, ever
There is no support tool, database query, or internal role that can produce decrypted terminal content outside your own devices or your own recovery flow. This is a hard product principle we designed the architecture around, not a policy layered on top.
Notifications never see your content
Alerts are metadata only — a host going offline, a process exiting, or a host key used from somewhere new. Vyre.Api never inspects terminal output to raise one, because it never has any plaintext to inspect.
Honest about what recovery means
Losing every device doesn’t have to mean losing your scrollback history — but that convenience means recovery is account-recoverable, not pure zero-knowledge encryption. We’d rather say that plainly than overclaim.
Security FAQ
The questions we get asked most
Can Vyre see or read my terminal output?+
No. Every tab is encrypted on your device before it leaves — Vyre.Api relays and stores ciphertext only, and there is no admin override or break-glass path.
What happens if I lose my only device?+
An encrypted backup of each tab’s key is escrowed with KaxlinCore. After a fresh sign-in with multi-factor authentication, you can recover access to your scrollback.
Could a Kaxlin employee ever see my data, even for support?+
No. Support for a stuck session works from metadata and connection logs only — device online/offline state, timestamps, error codes. There is no internal path to decrypted content, for anyone, ever.
Your next terminal is one tab away.
Install Vyre on your PC or a server, open a tab, and it’s already on the web. Free tier, no card needed.