Sign inOpen console
Security

How tilder keeps you safe

tilder is built so that the server in the middle does not have to be trusted. It introduces your browser to your machines; everything that matters is decided on your devices.

Keys stay on your devices

  • Each browser you use makes a signing key it cannot export. Script on the page can use it while the page is open, but never copy it out.
  • Your account's root key exists only wrapped: under your recovery code, and under each passkey you add. It is opened in memory for an admin action (confirming a machine, adding or removing a device) and dropped.
  • The server stores the wrapped copies. Without your recovery code or passkey they are useless.

Machines trust your root, not the server

When a machine joins, it learns your root's public key and keeps it. From then on it checks every connection against it: the device must hold a certificate your root signed, not removed, valid by the machine's own clock, and the offer must be signed by that device. A server that lies cannot open a shell or read a file.

Traffic is peer to peer

Browser and machine connect directly over WebRTC, encrypted with DTLS and pinned to the fingerprint in the offer your device signed. When a network blocks the direct path, a TURN relay carries the traffic; it sees only ciphertext.

Removing a device

In Settings → Devices, remove a lost or old device. Your machines cut it off within a minute, including shells it has open, and it cannot get back in.

What the server sees

Your account id, your devices' and machines' public keys, which machines are online, and the addresses they connect from. It relays signalling messages it cannot alter without being caught. It never sees what you type, the files you open, or what you copy.

Check it yourself

The agent, the identity and key code, and the wire protocol are open source under Apache-2.0: github.com/nghyane/tilder. Report a vulnerability privately as its SECURITY.md says.