NoBreachProtocol
DocsCA / SoonRobinhood ChainOpen vault
Documentation / NoBreach Protocol

NoBreach Protocol

Private storage without the usual password surface.

NoBreach is a wallet-authenticated encrypted file vault on Robinhood Chain. The browser encrypts file content before upload; the server stores encrypted file data and metadata records needed to retrieve it.

Design intentReduce exposure from password databases and plaintext cloud uploads. A wallet signature verifies access, but wallet custody remains the user's responsibility.

Security model

What protects a vault.

Client-side encryptionAES-GCM, 256-bit

Files are encrypted in the browser before upload. The object store receives encrypted bytes rather than the original file contents.

Wallet authenticationNonce + signature

A unique server nonce is signed by the wallet. The server verifies the signature and creates a temporary in-memory session token.

Vault secretEncrypted locally

A per-vault secret is wrapped using material derived from the wallet unlock signature. The stored secret is encrypted, not plaintext.

Access boundaryOwner scoped

File listing, download, deletion, and vault-secret requests require an authenticated session and are scoped to the wallet owner.

Identity and access

NoBreach does not use email/password accounts. A wallet address is the vault identity. Each login signs a one-time nonce, and that nonce is deleted after successful verification to prevent replay through the same challenge.

A session is held in the backend process memory. Restarting the backend invalidates active sessions, requiring users to sign in again.

Encryption flow

  1. The wallet connects to Robinhood Chain.
  2. The browser signs a login nonce and a vault-unlock message.
  3. The browser creates or retrieves an encrypted vault secret.
  4. Files and metadata are encrypted locally with Web Crypto before upload.
  5. The encrypted object is stored under a generated UUID; PostgreSQL stores ownership and encrypted metadata.

Operations

How the service runs.

BrowserConnect wallet, sign messages, encrypt and decrypt files.
1
APIExpress service verifies signatures, sessions, payments, and ownership.
2
DataPostgreSQL/Prisma stores users, payments, nonces, file records, and encrypted vault secrets.
3
Object storageS3-compatible R2 stores encrypted file objects.

Storage operations

Uploads use in-memory request handling with a 50 MB file-size limit. Each encrypted object uses a generated UUID key. File metadata is persisted with the matching owner record. Downloads first confirm that the requested UUID belongs to the authenticated owner, then stream the encrypted object from storage.

Deleting a file removes its object from storage and its database record. Storage credentials are server-only and must never be placed in `NEXT_PUBLIC_` frontend variables.

Configuration

DATABASE_URLPostgreSQL connection for Prisma
DIRECT_URLDirect database URL for migrations
R2_ENDPOINT / R2_BUCKETS3-compatible encrypted object storage location
R2_ACCESS_KEY_ID / R2_SECRET_ACCESS_KEYServer-only storage credentials
PAYMENT_RECEIVERWallet that receives one-time activation payments
USDG_TOKEN_ADDRESSConfigured USDG contract address for token verification
FRONTEND_URL / FRONTEND_URLSAllowed web origins for CORS; FRONTEND_URLS accepts comma-separated origins

Reference

Network, payments, and API.

NetworkRobinhood ChainChain ID 4663 / eip155:4663
AuthenticationEIP-1193 compatible injected walletPersonal message signatures
EncryptionWeb Crypto AES-GCM256-bit file encryption
PaymentsETH and configured USDGOne-time activation, verified on-chain
Stock tokensAvailable soonRegistry lookup exists; payment acceptance is not enabled

Activation payments

Wallets without a verified payment require a one-time payment before file and secret endpoints are available. The API retrieves the submitted transaction from Robinhood Chain, confirms the chain, receipt success, sender, recipient, and required amount before saving the payment record.

API surface

POST/nonceCreate or return a wallet login nonce.
POST/loginVerify signature and issue a session.
GET/payment/optionsReturn configured activation options.
POST/payment/verifyValidate a payment transaction.
GET / POST/secretRetrieve or store the encrypted vault secret.
GET / POST/files / uploadList encrypted file records or upload an encrypted payload.
GET / DELETE/download/:id / files/:idRetrieve or remove a vault-owned encrypted file.
Recovery limitsNoBreach cannot recover a lost wallet, recovery phrase, or signing capability. Keep a secure wallet backup. As with any hosted service, access also depends on the application, network, database, and storage systems operating correctly.

Status and support

Contract address and social channels are marked as coming soon. For production operations, monitor API availability, PostgreSQL health, storage access, payment RPC availability, failed signature checks, and object-storage errors.