Security you can inspect

CodeMantis Cloud never receives the session secret and cannot decrypt end-to-end encrypted session content by design. That is a precise claim — not a promise that any system “cannot be breached.”

What the Cloud can see

  • Account identity and registered device public keys and fingerprints
  • Pairing session metadata and relay session timing, region, and byte/frame counts
  • Ciphertext in transit and short-lived relay tickets

What the Cloud never receives

  • Your endpoint private keys, the QR pairing secret, or session keys
  • Prompts, commands, files, terminal output, approvals, or any work content
  • Anything needed to decrypt an end-to-end encrypted session

Residual risks we name honestly

A Cloud compromise can still expose metadata and ciphertext, deny or replay traffic, or corrupt entitlement state. Endpoint, account-recovery, update, and supply-chain compromise remain separate risks. Pairing starts on your desktop and requires two-sided human confirmation.