Server-side search, previews and link graph: state the trade #69

Closed
opened 2026-09-21 18:06:07 +01:00 by cruelacid · 1 comment
Owner

Part of #37. Not a gap to close — a trade to state.

What Relay does

Their server reads plaintext, so server-side search, previews, a link graph and
cheap permission checks are all available to them. Their docs are candid about
the cost: cloud hosting is "traditional SaaS software without end-to-end
encryption"
, and "we could be compelled to (eg by a court)".

What we can never do

Our server stores opaque ciphertext under HMAC'd document names and never
materialises a document. Server-side search is impossible by construction,
not unimplemented.

Why this is an issue rather than a note

Because it will be asked, and the answer needs to be written down once and
consistently. docs/positioning.md already has the shape for the read-only
version of this argument: "the reason we cannot offer cheap read-only roles is
the same reason we cannot read your notes."
The same sentence works here.

Local search in Obsidian is unaffected — the vault on disk is plain markdown.
What is lost is search across devices you have not synced, which is a narrower
loss than it first sounds and should be described precisely rather than waved
away.

Action

A section in docs/security-model.md and a line in docs/positioning.md.
No code.

Part of #37. **Not a gap to close — a trade to state.** ## What Relay does Their server reads plaintext, so server-side search, previews, a link graph and cheap permission checks are all available to them. Their docs are candid about the cost: cloud hosting is *"traditional SaaS software without end-to-end encryption"*, and *"we could be compelled to (eg by a court)"*. ## What we can never do Our server stores opaque ciphertext under HMAC'd document names and never materialises a document. Server-side search is **impossible by construction**, not unimplemented. ## Why this is an issue rather than a note Because it will be asked, and the answer needs to be written down once and consistently. `docs/positioning.md` already has the shape for the read-only version of this argument: *"the reason we cannot offer cheap read-only roles is the same reason we cannot read your notes."* The same sentence works here. Local search in Obsidian is unaffected — the vault on disk is plain markdown. What is lost is search across devices you have not synced, which is a narrower loss than it first sounds and should be described precisely rather than waved away. ## Action A section in `docs/security-model.md` and a line in `docs/positioning.md`. No code.
Author
Owner

Moved to the Vikunja board as NEC-45: https://projectron.nerchure.com/tasks/45

Moved to the Vikunja board as **NEC-45**: https://projectron.nerchure.com/tasks/45
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#69
No description provided.