Skip to content

Latest commit

 

History

15 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SecureX Banner

🔐 SecureX — Zero-Leakage Cryptographic Personal Vault

License: MIT Security: AES-256-GCM Privacy Key Derivation Security Policy

SecureX is a local-first, zero-knowledge cryptographic vault engineered to protect sensitive personal notes, credentials, and authentication tokens from cloud data leaks, memory scrapers, and unauthorized offline inspection.

Developed by Jaswanth Reddy (@Jaswanth1902) as an academic engineering prototype and open-source personal security initiative.


💡 Why SecureX?

Every day, developers and daily computer users entrust sensitive notes, recovery phrases, and API keys to third-party cloud apps. When these platforms suffer breaches or API outages, personal privacy is permanently compromised.

SecureX was built from first principles to provide mathematical, sovereign privacy:

  • 100% Local-First: No remote cloud sync, no tracking beacons, no analytics.
  • Military-Grade Cipher: AES-256-GCM authenticated encryption with CSPRNG-generated nonces.
  • Anti-Tamper Memory Zeroization: Master keys and plaintext buffers are overwritten in RAM immediately upon lock.
  • Constant-Time Verification: Hardened HMAC authentication tags prevent side-channel timing attacks.

🏗️ Cryptographic Architecture

flowchart TD
    User([User Master Passphrase / Biometric]) --> KDF[PBKDF2 / Argon2id Key Derivation]
    KDF --> MasterKey[256-Bit Master Cryptographic Key]
    MasterKey --> MemoryZero[Ephemeral RAM Only\nZeroized on App Lock]
    
    subgraph VaultEngine["SecureX Cryptographic Vault Engine"]
        AES[AES-256-GCM Encryption / Decryption]
        NonceGen[Cryptographically Secure CSPRNG Nonce]
        PayloadHasher[HMAC-SHA256 Integrity Verification]
    end
    
    MasterKey --> AES
    NonceGen --> AES
    AES --> PayloadHasher
    PayloadHasher --> EncryptedBlob[Encrypted Ciphertext + Auth Tag]
    EncryptedBlob --> SQLiteEncrypted[Local SQLite Storage]
Loading

🛡️ Security Hardening & Zero-Trust Policies

  1. Memory Hygiene: Raw master keys never touch persistent disk storage. All key buffers in memory are explicitly wiped with zeros (0x00) upon session timeout or window blur.
  2. Timing-Attack Resistance: Authentication tag comparisons use constant-time algorithms (crypto.timingSafeEqual / hmac.compare_digest).
  3. Replay Attack Protection: Every cryptographic block includes a 96-bit unique initialization vector (IV) that is never reused across cipher operations.

See SECURITY.md for vulnerability reporting and security advisories.


📂 Repository Map & Documentation


👤 Author & Maintainer

Jaswanth Reddy


📄 License

Licensed under the MIT License.

About

The third Semester EL project final prototype -SecureX

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages