SecureX is a local-first, zero-knowledge cryptographic vault engineered to protect sensitive personal notes, credentials, and authentication tokens from cloud data leaks, memory scrapers, and unauthorized offline inspection.
Developed by Jaswanth Reddy (@Jaswanth1902) as an academic engineering prototype and open-source personal security initiative.
Every day, developers and daily computer users entrust sensitive notes, recovery phrases, and API keys to third-party cloud apps. When these platforms suffer breaches or API outages, personal privacy is permanently compromised.
SecureX was built from first principles to provide mathematical, sovereign privacy:
- 100% Local-First: No remote cloud sync, no tracking beacons, no analytics.
- Military-Grade Cipher: AES-256-GCM authenticated encryption with CSPRNG-generated nonces.
- Anti-Tamper Memory Zeroization: Master keys and plaintext buffers are overwritten in RAM immediately upon lock.
- Constant-Time Verification: Hardened HMAC authentication tags prevent side-channel timing attacks.
flowchart TD
User([User Master Passphrase / Biometric]) --> KDF[PBKDF2 / Argon2id Key Derivation]
KDF --> MasterKey[256-Bit Master Cryptographic Key]
MasterKey --> MemoryZero[Ephemeral RAM Only\nZeroized on App Lock]
subgraph VaultEngine["SecureX Cryptographic Vault Engine"]
AES[AES-256-GCM Encryption / Decryption]
NonceGen[Cryptographically Secure CSPRNG Nonce]
PayloadHasher[HMAC-SHA256 Integrity Verification]
end
MasterKey --> AES
NonceGen --> AES
AES --> PayloadHasher
PayloadHasher --> EncryptedBlob[Encrypted Ciphertext + Auth Tag]
EncryptedBlob --> SQLiteEncrypted[Local SQLite Storage]
- Memory Hygiene: Raw master keys never touch persistent disk storage. All key buffers in memory are explicitly wiped with zeros (
0x00) upon session timeout or window blur. - Timing-Attack Resistance: Authentication tag comparisons use constant-time algorithms (
crypto.timingSafeEqual/hmac.compare_digest). - Replay Attack Protection: Every cryptographic block includes a 96-bit unique initialization vector (IV) that is never reused across cipher operations.
See SECURITY.md for vulnerability reporting and security advisories.
00_START_HERE_FIRST.md— Initial onboarding guide and setup walkthrough.00_INTRO_OVERVIEW.md— System motivation and foundational security assumptions.00_FINAL_REPORT.md— Complete academic engineering report and threat model.ACADEMIC_PAPER_REFERENCE.md— Theoretical citations on zero-knowledge vaults.ARCHITECTURE/— Deep technical specifications and encryption benchmarks.
Jaswanth Reddy
- GitHub: @Jaswanth1902
- Email:
jaswanthreddy1537@gmail.com
Licensed under the MIT License.