Security
End-to-end encrypted, by construction
Orbit moves your agents' questions, their output and your answers between your Mac, your iPhone and your servers. Every one of those messages is sealed before it leaves a device, and only your devices can open it. The relay in the middle, whether you run it or we do, forwards bytes it cannot read.
Keys
Each device makes its own keys the first time it runs, and they never leave it.
- Identity: Ed25519. The device id is the public key. The relay authenticates each connection with a signature over a fresh nonce, so nobody can connect as your device without its private key.
- Box key: X25519. Used to receive the mesh key during pairing and when the key is rotated.
- Mesh key. Thirty-two random bytes made by your primary Mac. Every message is sealed with it using NaCl secretbox (XSalsa20-Poly1305). Only your paired devices hold it.
- Signed inside the seal. Every message also carries an Ed25519 signature from its sender. Receivers check it against the device the relay authenticated, so no other member, and no removed device holding an old key, can speak for your Mac or your phone.
Keys are stored with user-only permissions on Macs and servers, and in the app's protected storage on iPhone.
Pairing
Adding a device starts on your Mac, which shows a one-time code (as a QR code and as text). The code holds the relay address, the mesh id, your Mac's public keys and a 32-byte secret. It is valid for thirty minutes and works once.
- Your Mac registers a hash of the secret with the relay as a one-time ticket.
- The new device connects with that hash, so the relay lets it into the mesh.
- The new device sends its box key together with a proof made from the secret. The relay has only the hash, so it cannot forge this for a key it substitutes.
- Your Mac checks the proof and returns the mesh key, sealed to the new device's box key and signed by your Mac, whose public key the code already gave the device. The device knows the reply came from your Mac, not the relay.
The device list
Your primary Mac keeps a signed list of the devices allowed to command your machines: answer, message, stop, start and read. A machine trusts the device that invited it first, and after that only versions of the list signed by a device already on it. Older versions cannot replace newer ones, and commands older than five minutes are refused.
Removing a device rotates the mesh key. The Mac takes the device off the list, makes a new mesh key and hands it to each remaining device, boxed to that device's own key and signed. Then the relay drops the removed device. Devices that were offline get the new key when they reconnect.
What the relay can and cannot see
| Relay operator | Push gateway | Apple (APNs) | |
|---|---|---|---|
| Agent output, questions, your replies | no | no | no |
| Device public keys and mesh membership | yes | no | no |
| Who is online, message timing and sizes | yes | push timing only | push timing only |
| Push handle for a phone | handle only | yes (it issues them) | device token |
| Pairing secret, mesh key | no | no | no |
This is the same whether you self-host or use our hosted relay at relay.agentorbit.app. The hosted
relay is the open-source relay run by us; it holds public keys, pairing ticket hashes and push handles, and
forwards sealed payloads. It stores no message content, because it never has any.
Push notifications
A push is built and sealed on the machine where the agent runs, with the mesh key. The relay hands the sealed envelope to Apple's push service, which delivers it to your iPhone, where the app opens it and shows the real text. Apple sees an opaque payload and your device token. Nothing readable is ever in a push.
Push Gateway. Only Orbit's Apple push key can reach the iPhone app, and that key cannot be handed
to self-hosters. So a self-hosted relay sends its sealed envelopes to push.agentorbit.app, which holds
the Apple key and forwards them. The gateway sees a license key, an opaque phone handle and the sealed bytes. It
issues the handles itself, so relays never see raw Apple device tokens either.
Model calls
Talk's router runs on your primary Mac, using your own Claude Code login or an Anthropic API key you add in Settings. Requests go from your Mac to the provider directly. Nothing about your agents passes through our servers to get there. See Router engines.
Limits
- The relay sees metadata: which devices are online, when, and how large messages are.
- Any paired device can drive any of your agents. Pair only devices you control.
- Remote "start a new agent" requests are limited to directories the machine already works in or that you have listed.
- On-device speech recognition is used for voice. Typing avoids speech processing entirely.
- If you do not trust a relay operator, run your own: the Mac app has one built in, and a server relay is a single binary. See Self-hosting.
Responsible disclosure
Found something? Please email security@agentorbit.app with the details and steps to reproduce. We will acknowledge within three business days, keep you informed while we fix it, and credit you if you would like. Please give us a reasonable window before publishing.
Orbit's relay, connector and crypto are open source, so you can check the above against the code.