
AES-256-GCM encryption happens in the extension. Plaintext credentials never leave runtime memory.
A wallet signature and passkey-derived secret are mixed with HKDF. Neither factor is enough on its own.
The chain stores ciphertext and salted domain hashes only. The current build remains pre-alpha.