How it works

Your app is the front door.
Your circle runs the house.

Vennel is a profile: rules for combining Nostr-compatible components into a coherent private experience.

These are the roles in the full design. Availability depends on the client, box and integrations you are using.

01 / System architecture

Where your keys, conversations
and history belong.

The client asks for authority, the signer grants it, and the box handles admitted traffic and storage. Each has a different job and a different owner.

Component roles A relationship, not a completion claim

At a glance

  1. SigningMy Signet / hardware
  2. Requests & approvals

    ConversationsKithMoot
  3. Pairing & messages

    Storage & accessBothy box

Choose a role to read its details below.

Your signing authority

My Signet or a hardware signer

My Signet provides software identity and signing. Heartwood is the hardware-held-key alternative.

Bark and Cambium bridge signing requests; Sapwood manages Heartwood.

Signing requests
and approvals

Your device

KithMoot

Shows conversations, manages contacts and displays the actual lane. New web source adds encrypted local history search.

Web / Android

Pairing, admission
and messages

Your circle's keeper

Bothy box

Stores events and enforces access and resource limits. New source adds encrypted archives and governed deletion.

Circle-owned infrastructure

Further integration required

Signer-backed history and circle recovery

The full design connects box storage to signer-held keys and recovery shares held across the circle. The reviewed recovery library does not yet establish that protection in the running box.

The paired Android-to-Bothy journey has emulator evidence. This diagram describes responsibilities; it does not claim every connection is complete on every platform.

My Signet also manages credentials, family relationships, app permissions and identity backup. Signet is the protocol; My Signet is the app. See the identity and signer roles.

02 / Library and capability map

Small components.
Specific responsibilities.

Follow a branch to see the tools behind a capability. This is a map of roles in the profile, not a package dependency graph or a claim that everything is wired together.

The composition

Vennel profile

Shared rules for identity, delivery, custody and recovery

Identity & authority

Keep authority explicit.

  • nsec-treePurpose-separated personas and rendezvous keys
  • nostr-successionVerifiable movement to a successor key
  • signet-protocol / signet-loginMy Signet's protocol and consuming-app signer access

My Signet and hardware signer options sit above these libraries. Full pairing and identity migration still need acceptance.

Contacts & admission

Decide who gets in.

  • nostr-contact-cardSigned contact and box information
  • kenspeckleBonds, relationship tiers and invitations
  • SignetAttestations and delegated authority

Contact cards and admission components exist. Complete family mode and onboarding still need integration.

Delivery & quiet messages

Control the route.

  • forgesworn-linkKey- and tag-addressed transport
  • nostr-deaddropQuiet-message counters, padding and slots
  • Bothy + Tor / I2PBox storage, carrier routes and scheduling

Paired preview and quiet components exist. Box cadence activation and full carrier delivery remain open.

History & recovery

Make old history harder to take.

  • epoch-sealSealed periods of history and delayed recovery
  • dominion Encrypted access and recovery-share machinery
  • nostr-anon-voteAnonymous recovery refusal

Reviewed recovery library. Signer-backed box storage and the complete recovery flow remain open.

Files & distribution

Carry encrypted bytes.

  • Wildbloom / Wildbloom NodeEncrypted content-addressed files over Blossom
  • shelter-kitSupporting shelter and transport components

File components exist. Complete archive portability and signed distribution of the profile remain open.

Protection still to connect

Reduce the damage.

  • canary-kitDuress signals and verification components
  • nostr-veilAnonymous corroboration and attestations
  • RFC 9420 MLS / VMLSMessage-key protection design; vmls-core implements only the outer-envelope codec

Full duress and MLS integration remain open. Constrained anonymous rooms are implemented in source, with release and real Orbot/phone acceptance still required.

This is the short view. The full catalogue adds My Signet's dependencies, signer bridges, family and presence mechanisms, payments, candidates and reserved work. Read each component's evidence label before treating it as a working product feature.

History comparison is separate from delivery. Bothy and Android now have bounded, authenticated NIP-77 ID comparison primitives, not automatic replication or message fetching. Browser Link transport and the complete recovery journey remain open.

Explore the full ForgeSworn catalogue

03 / Network paths

Who carries the message?
Who can see the delivery?

Open a route to inspect its network boundary. Sheltered delivery, ordinary public delivery and quiet scheduling have different properties.

ShelteredBetween circle-owned boxes

Full-profile targetDashed connections indicate unfinished end-to-end integration.

Your side

Your client

Conversations and lane labels

Your circle's box

Admission, storage and forwarding

Carrier traffic

Network carriers

Tor / I2P

Carrier routes hide addresses at particular points in the path.

Tor onion servicesI2P destinations

They do not establish box ownership or prevent every form of traffic analysis.

Carrier traffic

Your contact's side

Their circle's box

Admitted private delivery

Their client

Reads the conversation

Logical ownership boundaries, not a required count of physical machines. The released paired preview and the Tor/I2P connection probes are separate evidence; neither proves this whole target route.
PublicThrough ordinary Nostr relays

Sender

Your app

Public events or encrypted private-message envelopes

Publish

Outside operator

Public relay

Stores and forwards events. Controls its own retention and access policies.

Receive

Recipient

Their app

Reads a public event or decrypts a private message

DM encryption protects message content. A relay can still observe the outer recipient, timing and connecting network address. Using a carrier can change which address it sees.

This remains the compatible public lane. The profile requires visible downgrades from ordinary sheltered delivery; quiet and anonymous modes must not silently take this fallback.

Public + quietA schedule that keeps running

Box activation pendingQuiet client components exist. The box-owned journey below still needs controlled activation and device proof.

Sending circle

Box-owned queue

Your phone hands off messages. The box schedules a message or filler for each slot.

Scheduled wraps
over a carrier

Public infrastructure

Gift-wrap stream

Relays carry encrypted wraps. They still observe traffic arriving and being fetched.

Broadcast pull
over a carrier

Receiving circle

Recipient's box

Pulls the stream, tries its keys locally and syncs matching messages to the client.

Quiet mode reduces the signal from the moment someone presses Send. It uses public relays and incurs delay and bandwidth costs. Calls are never quiet; this is not a promise of global invisibility.

Evidence snapshot: project records through 15 September 2026. See what has been exercised and what remains.

Adopting the preview

Agree the responsibilities before moving the conversation.

  1. Choose your circle and keeper.

    Decide who will run supported Bothy infrastructure and handle availability, updates and storage. Confirm which preview versions work together.

  2. Choose a compatible client and signer.

    Keep public Nostr activity working. Use the supported pairing and admission flows for the private experiment.

  3. Prove the journeys you need.

    Check sending, receiving, restart, withdrawal of access and recovery on your actual devices. Do not assume an emulator result covers background phone behaviour.

There is no finished one-click Vennel installation to promise here. The current entry point is a coordinated preview across the client and box.

Read current readiness