Trust Model
What Nythera trusts, and what it does not
No recovery product can remove every risk. Nythera reduces specific risks by moving plaintext out of the website and into an extension-controlled flow.
This page explains what is trusted, what is not fully trusted, and which threats are in scope.
Assumptions
Trusted components
Nythera trusts the extension to handle plaintext correctly and trusts Story CDR to provide the encrypted data rail and access-controlled recovery flow.
Reduced trust
Components that should not see secrets
The website, webpage JavaScript, DOM, React state, and browser website storage are treated as places plaintext should avoid.
Threat model
Threats Nythera reduces
Nythera reduces common user and web application failure modes, especially accidental plaintext exposure and unrecoverable loss.
Step 1
Website XSS or frontend bug
Plaintext text secrets are not typed into the website.
Step 2
Cloud notes or screenshots
Encrypted vault replaces common manual plaintext backups.
Step 3
Trusted contact misuse
Contacts are approved recovery actors, not upfront plaintext holders.
Limits
Threats not fully solved
Nythera is not a replacement for device security, extension supply-chain controls, or careful choice of recovery contacts.