Prototypes Prototype docsP11 · Docs and assistant
Client portal (P6)
DocsPage 7 of 30

Client portal (P6)

An adviser shares documents with a client and can take the access back. The server holds ciphertext only.

Keys

The adviser and the client each have an X25519 key pair in their browser. The server stores the public halves.

Sharing

Each document is encrypted with its own random key. That key is wrapped once for each reader with the reader's public key, and the server stores the wrapped keys beside the ciphertext. To share, the adviser wraps the document key for the client.

Removing access

To remove access, the adviser's browser encrypts the document again with a new key as a new version, wraps the new key only for the readers who stay, and deletes the client's wrapped key. A key the client kept from an earlier version opens nothing on the server afterwards. The log on the server records uploads, shares, downloads and removals.

Limits

The portal takes files up to 1 MB, and the server deletes its data after 7 days.

Previous: Passkey sign-in (P5). Next: Whistleblower channel (P7).

How Prototype docs is built

The pages are written in Markdown and built into these pages and an index of 154 sections. The assistant answers from the index, and every answer names the sections it was taken from.