Technical Whitepaper

Security Specifications

Cryptographic integrity, sandboxed addon boundaries, zero-trust isolation, and self-hosted privacy standards.

1. Cryptographic License Verification

JChat licenses use asymmetric digital signatures (RSA-2048 / Ed25519) combined with secure license server checks:

License Server Verification

The license runtime validates your purchase code and binds it to your host domain with zero transmission of chat messages or user communications.

Cryptographic Offline Fallback

Cryptographically signed tokens allow verified instances to maintain full runtime stability even during temporary network or upstream interruptions.

2. Add-on Sandboxing & Isolation

All marketplace extensions run in isolated environments governed by @jchat/addon-sdk:

  • • Capability-Based Permissions:Addons must explicitly declare scopes (network, storage, ui) in their signed manifest.
  • • Zero Core Database Access:Addons cannot execute arbitrary raw SQL or bypass core tenant boundaries; all mutations pass through validated Eden Treaty RPC boundaries.
  • • Host Runtime Sandboxing:UI components are federated and isolated, preventing malicious DOM tampering or session hijacking.

3. Encryption & Session Protections

• In Transit: All HTTP and WebSocket connections require TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers.

• Session Security: Session cookies use HttpOnly, SameSite=Lax/Strict, and Secure flags with cryptographically random UUIDv7 identifiers.

• CSRF Protection: All state mutations are guarded with double-submit CSRF tokens and origin validation.

4. Vulnerability Disclosure & Patches

We take security reports seriously. To report a security vulnerability or disclose a potential issue, please contact our security team directly. Critical security patches are released with priority changelogs across all supported versions.