Skip to content

Documentation

What is protected

Words stay private. Who, when, and size stay public. How to report a problem.

This is the public security write-up for Raven. It is conservative on purpose. If something is not listed as protected, assume it is not.

What is protected

  • Message contents. Words are encrypted on your device before they leave. Only the person you are writing to can read them. If someone tampers with a message on the way, Raven notices.
  • Your keys. The 25-word recovery phrase is created on this device and stored encrypted here. Raven never uploads it. There is no account server that could hand it over.

Raven talks straight to Algorand. There is no Raven company in the middle of the messages.

What stays public

Each message is an Algorand transaction. Anyone can see:

  • Who messaged whom (the two addresses).
  • When it was sent.
  • Roughly how long the message was (the size of the locked bytes).

Only the words are private. Raven does not hide that you talked, or to whom. If you need that, Raven alone is not enough.

The recovery phrase is the whole history

Anyone with your 25 words can pretend to be you and read your everyday chats, including old ones. Ciphertext stays on Algorand forever. Rotating to a new account protects future mail, not the past. Treat the phrase as your whole history, not just a login.

Extra lock adds a second secret both of you hold. An attacker then needs that secret as well as a key. It is still not a promise that old Extra lock chats become unreadable if the secret leaks. See Extra lock.

Post-quantum signing is not Extra lock

Optional post-quantum signing changes how sends are authorized (about 0.003 ALGO per send). Your Raven address still sends. A second signing address can hold 0 ALGO; fees still come from the Raven address. Same 25 words. Chat contents still use everyday encryption. Extra lock is a separate shared secret.

Report a vulnerability

Open a ticket in the CorvidLabs Discord. Include the version from About, what happened, and how to reproduce it. Do not post exploit details in a public channel.

The Raven GitHub repository is private, so GitHub security advisories are not a public reporting path. Protocol issues may also belong with AlgoChat security and the published ts-algochat library.