Devices, not just passwords
Each installation has its own cryptographic identity. Signing keys remain non-exportable. Exchange keys are preferably held as non-exportable CryptoKey objects; where iOS/WebKit cannot persist them reliably, the client uses a documented JWK fallback and migrates back when support becomes available. New devices are visible, verifiable and individually revocable.
- Device-bound keys
- Safety numbers and strict verification
- Targeted device removal


