Skip to content
Zain Mahmood
Selected work

Envryn

.env files get committed, copied and left behind. Cloud secrets managers fix that by asking you to trust another company with the keys. Envryn keeps an encrypted vault on your own devices and syncs Windows and Android directly over the local network, with no account and no relay server.

Type
Security tool
State
Beta · v0.1.9
Role
Solo, end to end
  • Rust
  • Tauri
  • React
  • TanStack Router
  • XChaCha20-Poly1305
  • Argon2id
Envryn Android vault

At a glance

  • Rust core; the UI is treated as untrusted
  • Windows and Android sync with no server in between
  • CodeQL, Semgrep, Gitleaks, cargo-audit and fuzzing in CI

What I owned

Solo project. The Rust vault core and cryptography, the Tauri shell, the React interface, the Android build, the paired-device sync protocol, and the CI security tooling around all of it.

Decisions, and what they cost

  1. The interface is treated as untrusted

    A webview UI is the easiest place for a bug to leak a secret, so it never gets to decide anything. Sensitive operations cross a typed Tauri boundary and are enforced by the Rust core, and the TypeScript bindings are generated from the Rust IPC types so the two sides cannot drift apart. The optional local AI worker runs as a separate process and receives only the minimum sanitized input for the operation it was asked to do.

    What I gave upEvery feature touches three places: a Rust command, the generated contract, and the UI. That is slower to build than letting the interface read the vault directly, and it is the reason the UI can be wrong without being dangerous.

  2. Direct device sync instead of a hosted relay

    Devices pair with a code a human compares on both screens, then sync encrypted records over mutually authenticated TLS on the local network. Nothing sits in the middle, so there is no server holding ciphertext, metadata or an account list.

    Where your secrets travel between devices
    1. Cloud secrets manager (not used)

      DeviceVendor's serverDevice

      Someone else holds the ciphertext, the metadata and the account list.

    2. Envryn

      WindowsMutual TLS, local networkAndroid

      Paired with a code you compare on both screens. Nothing in the middle.

    What I gave upSync only happens when both devices are on the same network. There is no cloud fallback to reach for when you are away from home, because adding one would bring back the thing Envryn exists to avoid.

  3. Separate keys for separate jobs

    The master password goes through Argon2id, records are sealed with XChaCha20-Poly1305, and HKDF-SHA256 derives domain-separated subkeys so a key made for one purpose is never reused for another. On Windows, DPAPI and Windows Hello add optional platform protection on top.

    What I gave upThere is no account, so there is no account recovery. Lose the master password and nobody, including me, can open the vault. Encrypted backups are the answer to that, not a reset link.

Known limitations

  • Windows installers do not have a trusted publisher signature yet, so SmartScreen warns. Every release carries CHECKSUMS.txt to verify against.
  • Android has less physical-device coverage than Windows.
  • No automatic updater in the 0.1.x series; you install a newer build over the old one.
  • It has had an internal security review, not an independent audit, and the README says so.

Where it stands

Public beta. Windows .exe and .msi installers plus a universal Android APK, each release shipping checksums and a CycloneDX SBOM. CI runs unit, integration and fuzz targets alongside CodeQL, Semgrep, Gitleaks, OSV-Scanner, cargo-audit and cargo-deny. It imports .env content, detects common credential formats offline, and clears copied secrets after a delay.