Trust Model

What Nythera trusts, and what it does not

No recovery product can remove every risk. Nythera reduces specific risks by moving plaintext out of the website and into an extension-controlled flow.

This page explains what is trusted, what is not fully trusted, and which threats are in scope.

Assumptions

Trusted components

Nythera trusts the extension to handle plaintext correctly and trusts Story CDR to provide the encrypted data rail and access-controlled recovery flow.

Browser extension: trusted plaintext boundary.
User wallet: trusted to sign intended transactions.
Story CDR: trusted for threshold encryption and recovery access.
Approved contacts: trusted to recover only under acceptable circumstances.

Reduced trust

Components that should not see secrets

The website, webpage JavaScript, DOM, React state, and browser website storage are treated as places plaintext should avoid.

Website can manage metadata and transactions.
Website should not receive or render plaintext.
Website storage should not contain plaintext.
Analytics and logs should never include plaintext.

Threat model

Threats Nythera reduces

Nythera reduces common user and web application failure modes, especially accidental plaintext exposure and unrecoverable loss.

Step 1

Website XSS or frontend bug

Plaintext text secrets are not typed into the website.

Step 2

Cloud notes or screenshots

Encrypted vault replaces common manual plaintext backups.

Step 3

Trusted contact misuse

Contacts are approved recovery actors, not upfront plaintext holders.

Limits

Threats not fully solved

Nythera is not a replacement for device security, extension supply-chain controls, or careful choice of recovery contacts.

A fully compromised browser or operating system can still be dangerous.
A malicious extension update would be a serious supply-chain risk.
A user can still reveal a secret on a shared or recorded screen.
Approved contacts must be chosen carefully.
Phishing sites or fake extensions require user education and distribution controls.