Skip to main content
This is the plain-language version of the threat model. Standard notes are readable by the server. Notes in Private are encrypted on the device. We do not call the product zero-knowledge, and we have not had an external penetration test.

Private notes passphrase

A new passphrase must be at least 12 characters. Ela also rejects common passwords and simple patterns. The check runs when you turn Private notes on or change the passphrase. Unlock of a passphrase you already use does not apply the minimum. The server never receives the passphrase. Enabling Private notes on the web creates the wrapped key in the browser and uploads only that wrap. Desktop change-passphrase and enable do the same check on the device. The API cannot enforce this minimum. If you lose the passphrase and do not have a recovery key, Ela cannot reset it. There is no escrow. A Library that already uses a shorter passphrase can still unlock. Where Settings can change the passphrase, Ela asks you to replace one that is below the minimum. The wire recovery notice is unchanged: notes in Private stay unrecoverable without the passphrase or a recovery key.

What is encrypted where

The web app does not keep an offline copy of your notes. Unlock with the passphrase or a recovery key stays in that tab’s memory and locks on idle, sign-out, reload, or Lock. Search in that tab can include the notes you have unlocked, and that search does not ask the server to match Private text. Sync does not skip Private. It uploads ciphertext. The filename, the size of that ciphertext, and the time of the change stay visible. Cloud search and cloud MCP do not return those notes, and coverage says Private notes not searched. The coverage JSON still lists private/. If you lose the passphrase, those notes are unrecoverable. There is no reset, and we do not hold a copy of the key.

What a few attackers can do

The server, or someone who can read the database. They can read ordinary notes, attachment files, filenames of private notes, and ciphertext. They cannot read a private note without the passphrase. They can hide new edits or replay an old copy of the op log. A private note’s ciphertext is bound to its library, note, and field, so a payload moved to another note is rejected. An older copy of the same note can still be replayed. A library that started on e2ee:v1 can still be swapped in a web session that has not latched to v2-only. Someone who steals the laptop. Desktop keeps markdown in the clear, including Private, and keeps a decrypted copy in the local database. Full-disk encryption is what stops this. Ela does not turn that on. The desktop app is unsigned. Someone who steals the phone. The local database is encrypted, the key and the session tokens sit in the Keychain (this device only, when unlocked), and the store is excluded from phone backup. The phone passcode is what protects the Keychain. After the phone is unlocked, private notes that were already synced are plaintext inside that database, so the passphrase is not a second lock on the local copy. An agent connected to your notes. It reads the text you let it read, including instructions hidden in a note. Cloud writes wait in the review queue unless you turn that off. Local MCP can read Private. Each signed-in account gets its own library. A shared organization claim is not access. Session lifetime stays at the WorkOS defaults. API request logs drop the query string and redact authorization, cookies, and validation inputs. Production refuses to boot when a static bearer token is set.

What we do not claim yet

  • No external penetration test.
  • Desktop signing and notarization are not done. There is no auto-update feed.
  • Browser unlock of Private runs in the tab. Each visit trusts the code the site just sent. The installed desktop and iOS apps do not re-fetch the decryptor on every load. The web key is memory-only.
  • Deleting a note does not erase provider backups. The backup retention window is a value the operator has to confirm. We do not publish a number we have not verified.
  • Moving a note into Private removes it from search. Attachment files uploaded earlier can remain in object storage until they are collected. SVG is not an upload type.
  • Required multi-factor sign-in is a WorkOS setting the operator turns on. This page does not claim it is on.

Report a vulnerability

Email [email protected]. Please include what you did, what you expected, and the version or commit if you have it. Do not include note text from a real library. Give us a chance to fix the issue before you publish it. Response times are listed in the repository SECURITY.md. Those times are placeholders until the owner confirms them. They are not a service level yet. https://elanotes.com/.well-known/security.txt points at this page.