Security you can inspect
CodeMantis Cloud never receives the session secret and cannot decrypt end-to-end encrypted session content by design. That is a precise claim — not a promise that any system “cannot be breached.”
Phone ● — Cloud relay (routes, cannot read) — ● Desktop
What the Cloud can see
- Account identity and registered device public keys and fingerprints
- Pairing session metadata and relay session timing, region, and byte/frame counts
- Ciphertext in transit and short-lived relay tickets
What the Cloud never receives
- Your endpoint private keys, the QR pairing secret, or session keys
- Prompts, commands, files, terminal output, approvals, or any work content
- Anything needed to decrypt an end-to-end encrypted session
Residual risks we name honestly
A Cloud compromise can still expose metadata and ciphertext, deny or replay traffic, or corrupt entitlement state. Endpoint, account-recovery, update, and supply-chain compromise remain separate risks. Pairing starts on your desktop and requires two-sided human confirmation.