My Signet provides software identity and signing. Heartwood is the hardware-held-key alternative.
Bark and Cambium bridge signing requests; Sapwood manages Heartwood.
↔↕
Signing requests and approvals
Your device
KithMoot
Shows conversations, manages contacts and displays the actual lane. New web source adds encrypted local history search.
Web / Android
↔↕
Pairing, admission and messages
Your circle's keeper
Bothy box
Stores events and enforces access and resource limits. New source adds encrypted archives and governed deletion.
Circle-owned infrastructure
Further integration required
Signer-backed history and circle recovery
The full design connects box storage to signer-held keys and recovery shares held across the circle. The reviewed recovery library does not yet establish that protection in the running box.
The paired Android-to-Bothy journey has emulator evidence. This diagram describes responsibilities; it does not claim every connection is complete on every platform.
My Signet also manages credentials, family relationships, app permissions and identity backup. Signet is the protocol; My Signet is the app. See the identity and signer roles.
02 / Library and capability map
Small components. Specific responsibilities.
Follow a branch to see the tools behind a capability. This is a map of roles in the profile, not a package dependency graph or a claim that everything is wired together.
The composition
Vennel profile
Shared rules for identity, delivery, custody and recovery
Identity & authority
Keep authority explicit.
nsec-treePurpose-separated personas and rendezvous keys
nostr-successionVerifiable movement to a successor key
signet-protocol / signet-loginMy Signet's protocol and consuming-app signer access
My Signet and hardware signer options sit above these libraries. Full pairing and identity migration still need acceptance.
Contacts & admission
Decide who gets in.
nostr-contact-cardSigned contact and box information
kenspeckleBonds, relationship tiers and invitations
SignetAttestations and delegated authority
Contact cards and admission components exist. Complete family mode and onboarding still need integration.
Delivery & quiet messages
Control the route.
forgesworn-linkKey- and tag-addressed transport
nostr-deaddropQuiet-message counters, padding and slots
Bothy + Tor / I2PBox storage, carrier routes and scheduling
Paired preview and quiet components exist. Box cadence activation and full carrier delivery remain open.
History & recovery
Make old history harder to take.
epoch-sealSealed periods of history and delayed recovery
dominionEncrypted access and recovery-share machinery
nostr-anon-voteAnonymous recovery refusal
Reviewed recovery library. Signer-backed box storage and the complete recovery flow remain open.
Files & distribution
Carry encrypted bytes.
Wildbloom / Wildbloom NodeEncrypted content-addressed files over Blossom
shelter-kitSupporting shelter and transport components
File components exist. Complete archive portability and signed distribution of the profile remain open.
Protection still to connect
Reduce the damage.
canary-kitDuress signals and verification components
nostr-veilAnonymous corroboration and attestations
RFC 9420 MLS / VMLSMessage-key protection design; vmls-core implements only the outer-envelope codec
Full duress and MLS integration remain open. Constrained anonymous rooms are implemented in source, with release and real Orbot/phone acceptance still required.
This is the short view. The full catalogue adds My Signet's dependencies, signer bridges, family and presence mechanisms, payments, candidates and reserved work. Read each component's evidence label before treating it as a working product feature.
History comparison is separate from delivery. Bothy and Android now have bounded, authenticated NIP-77 ID comparison primitives, not automatic replication or message fetching. Browser Link transport and the complete recovery journey remain open.
Carrier routes hide addresses at particular points in the path.
Tor onion servicesI2P destinations
They do not establish box ownership or prevent every form of traffic analysis.
↔↕
Carrier traffic
Your contact's side
Their circle's box
Admitted private delivery
↕
Their client
Reads the conversation
Logical ownership boundaries, not a required count of physical machines. The released paired preview and the Tor/I2P connection probes are separate evidence; neither proves this whole target route.
PublicThrough ordinary Nostr relays+
Sender
Your app
Public events or encrypted private-message envelopes
→↓
Publish
Outside operator
Public relay
Stores and forwards events. Controls its own retention and access policies.
→↓
Receive
Recipient
Their app
Reads a public event or decrypts a private message
DM encryption protects message content. A relay can still observe the outer recipient, timing and connecting network address. Using a carrier can change which address it sees.
This remains the compatible public lane. The profile requires visible downgrades from ordinary sheltered delivery; quiet and anonymous modes must not silently take this fallback.
Public + quietA schedule that keeps running+
Box activation pendingQuiet client components exist. The box-owned journey below still needs controlled activation and device proof.
Sending circle
Box-owned queue
Your phone hands off messages. The box schedules a message or filler for each slot.
→↓
Scheduled wraps over a carrier
Public infrastructure
Gift-wrap stream
Relays carry encrypted wraps. They still observe traffic arriving and being fetched.
→↓
Broadcast pull over a carrier
Receiving circle
Recipient's box
Pulls the stream, tries its keys locally and syncs matching messages to the client.
Quiet mode reduces the signal from the moment someone presses Send. It uses public relays and incurs delay and bandwidth costs. Calls are never quiet; this is not a promise of global invisibility.
Agree the responsibilities before moving the conversation.
Choose your circle and keeper.
Decide who will run supported Bothy infrastructure and handle availability, updates and storage. Confirm which preview versions work together.
Choose a compatible client and signer.
Keep public Nostr activity working. Use the supported pairing and admission flows for the private experiment.
Prove the journeys you need.
Check sending, receiving, restart, withdrawal of access and recovery on your actual devices. Do not assume an emulator result covers background phone behaviour.
There is no finished one-click Vennel installation to promise here. The current entry point is a coordinated preview across the client and box.