Relay feature parity, with end-to-end encryption (tracking) #37
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#37
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Relay feature parity, with end-to-end encryption
Tracking issue for the parity programme. Every issue below carries a
relay:*label classifying the feature's status at Relay, so this backlogdoubles as a live competitive ledger.
relay:supportedrelay:plannedrelay:requestedrelay:absentRisk labels are ours:
risk:none(client-only, server untouched),risk:additive(new message type or table, backward compatible),risk:contract(changes something existing accounts or stored data depend on).Why this exists, and what was wrong before it
Relay was last surveyed in
docs/competition-relay.mdon 1 September 2026.They shipped 0.8.12 on 9 September. Our own records were stale in both
directions:
say read-only access is unsupported; an
enableReaderRoleflag exists, defaultoff. Their marketed "RBAC" is private shared folders — subsetting which
members may access a folder — which we already have via
folder_members.headline, with a
relay-skillsrepo for Claude Code), Plugin API v0, Basessync, and Relay-Comments as a separate beta plugin.
Phase 6 and no document says so.
docs/plan-master.mdsays Phase 13 is "next, not built", Phase 14 ishalf-built and store submission has not happened. All three are stale — we are
listed and accumulating downloads, and 13 and 14 are complete.
The two findings that set the sequence
Both verified in code, not assumed.
1. Structured documents need no server change.
packages/server/src/doc-store.tssays in its own header "Nothing in this file interprets
payload", and thecode matches: a document is a folder-id prefix, an HMAC'd name, a sequence
counter and opaque bytes. The folder listing is already a
Y.Map(
file-sync.ts:109) on the identical encrypted pipeline, and Phase 8 set theprecedent of a second root that older clients replicate without acting on.
So Canvas, Bases, Kanban, frontmatter, comments and change attribution are
client-only work.
2. Nothing requires taking the product offline. The master key is cached
per-device in the OS credential store (
docs/security-model.md;main.ts:613),so the one contract-changing item — a signing keypair — can enrol silently,
with no passphrase prompt. Separating enrolment from enforcement removes
the deadline entirely: enrol now, decide about enforcement whenever.
What is actually urgent
doc-store.ts:190deletesdoc_updatesup to every snapshot, anddoc_snapshotskeeps exactly one row per document. With the plugin live,real users' edit history is being discarded daily and cannot be recovered.
Under this repo's central principle that is closer to a defect than a gap. It is
the first issue in Phase 15 and should ship alone if anything slips.
Sequence
Irreversible first, visible second, large last. Phases 13 and 14 are done, so
none of this competes with a launch path.
Roughly 32–42 developer-weeks to broad parity.
One finding worth stating plainly
Category 4 is nearly empty. Almost nothing we could build is novel to this
category — Relay either ships it or has been asked for it. The encryption is the
exception, and it is the whole position. Per
docs/positioning.md: lead with theserver that cannot read your notes, and never compete on licence terms.
Open question
Self-hosting pricing. Relay gives self-hosting free on every tier and
markets it as "we don't charge for privacy". We gate it behind a licence at
Business/Enterprise (Phase 12). Since our whole position is privacy, charging for
the deployment mode they give away is the one place our pricing reads worse than
theirs on our strongest ground. Matching them costs no engineering — it deletes
Phase 12.
Relay data read 21 September 2026 from relay.md, docs.relay.md,
github.com/No-Instructions/Relay (README, manifest, flags.ts, issues, PRs) and
their roadmap. Re-fetch rather than trusting this summary; it will drift.
The backlog
Classification is at Relay: 1
relay:supported· 2relay:planned·3
relay:requested· 4relay:absent.Phase 15 — Retention and enrolment (urgent; history is being lost now)
plan-master.mdmisstates Phases 10, 13, 14 and the store listingpositioning.md/competition-relay.mdcredit Relay with RBAC they do not shiplaunch-readiness.mdPhase 16 — The plugin becomes a plugin
Phase 17 — Structured documents
structuredfile kind beside text and blob — 1 (prerequisite).base) sync — 1Y.Map— 1Phase 18 — Agents and headless
packages/headlesson the vault-adapter seam — 3.nectendaignore) — 2Phase 19 — Review and history
Phase 20 — Enterprise, on demand
Backlog — unscheduled
.obsidianconfiguration — 3Where we are ahead — category 4
How to keep this current
Update the issues, not a markdown file. When Relay ships something, change its
relay:*label; when we ship something, close it. Theparitylabel returns thewhole programme:
Moved to the Vikunja board as NEC-14: https://projectron.nerchure.com/tasks/14