Hermes · Research arc · 2026-05-29

Secret-Data Handling — OSS Self-Host Survey

Survey of self-host OSS for agency↔client secret-data exchange on boas.dev infrastructure. Three product layers covered. Both E2E and SSE trust tiers. Reuse hostinger-vps + R2 where viable. No SOC 2 / ISO 27001 cert gate.

Method · 3 parallel sub-agent tracks (S6 mimir pattern), ~75 calls Persisted · research/secret-data-oss-2026-05-29/ Status · operator-owned ratification

Recommended Stack

Layer Top pick License Trust Why it wins
A · Credentials Psono CE Apache-2.0 E2E Only candidate with native bidirectional "Link Share" to non-account recipients (passphrase + use-count + expiry). Genuine browser-side E2E. Docker + Postgres single-VPS footprint.
B · Intake (client→agency) Lufi AGPL-3.0 E2E Browser-side SJCL E2E, key-in-URL-fragment, anonymous upload, S3/R2-capable. Active (0.07.3 Nov 2025). Single-maintainer bus-factor flagged.
B · Delivery (agency→client) YOPass Apache-2.0 E2E OpenPGP browser-side E2E, 14.0.0 shipped 2026-05-28. Two-instance read-only/creator pattern. S3/R2 backend. NDJSON audit log (gating uncertain).
C1 · Vault (E2E) Seafile CE AGPL-3.0 E2E Client-held-key encrypted libraries for high-sensitivity persistent storage. R2 broken — use local FS + nightly encrypted R2 backup.
C1 · Vault (SSE + collab) Nextcloud Hub + ONLYOFFICE AGPL-3.0 SSE Server-side encryption with collab editing. Nextcloud-native E2EE rejected (mnemonic-loss = data-loss, no browser collab on E2EE).
C2 · SSO/Auth Authentik MIT First-class connectors for Vaultwarden + Nextcloud. Forward-auth proxy for legacy (covers Seafile CE SAML-Pro gap via LDAP outpost). Invitation wizard + magic-link.

Combined Architecture

Auth glue · single OIDC realm Authentik · id.boas.dev
↓ OIDC tokens · forward-auth for legacy
vault.boas.dev Psono Credentials, API keys. Link-share to non-account clients.
drop.boas.dev Lufi Client→agency intake. Anonymous E2E uploads.
share.boas.dev YOPass Agency→client delivery. Read-once + expiring.
files.boas.dev Seafile Persistent E2E vault. Client-held keys.
cloud.boas.dev Nextcloud SSE + ONLYOFFICE collab. Agency processing tier.

Non-account clients enter per-tool (magic links, share links). Account clients flow through Authentik invitation wizard once → SSO across all five services. Per-client tenancy via Authentik groups (operator decides single-Authentik-with-groups vs one-per-client at sequencing).

Cross-Cutting Findings

License — AGPL exposure

3-of-5 cores (Lufi, Seafile, Nextcloud) AGPL-3.0. Fine for agency self-host serving clients. Forecloses future SaaS productization. Forward-flag.

Seafile + R2 = broken

Date-header parse failures, open 2023–2024 GH issues, no fix. Workaround: local FS + nightly encrypted R2 backup. Cross-route flag for atlas if Seafile adopted.

Bus-factor watch

Lufi single-maintainer. YOPass small team (strong 2026-05-28 release signal). Padloc, YeetFile, timvisee/send all rejected for stagnation.

Audit-log gaps to validate

Psono granularity (per-secret-view detail unverified). YOPass NDJSON licence-key gating ambiguous. Both need Layer-2 confirmation before client-evidence promises.

Hosting footprint

~3.5–4 GB steady, ~5 CPU cores under load. Co-locates on existing hostinger-vps with plutus. Exception: credentials likely deserve isolated VPS (~€4-7/mo Hetzner CX22) for blast-radius separation.

Non-account-client UX (load-bearing)

All 5 picks satisfy bidirectional + non-account-client natively. Psono Link Share, Lufi anonymous, YOPass expiring, Nextcloud public-link, Authentik magic-link.

AV on ciphertext = useless

ClamAV server-side can't see inside E2E payloads. Any malware-scan strategy must run post-decrypt at agency endpoint. Cross-route candidate for Hades or defer.

R2 reuse posture

Lufi · YOPass · Nextcloud — R2-compatible, confirmed. Seafile broken (see above). No net-new storage spend for v1.

Sequencing (if adopt-arc elected)

1AuthentikFoundation. All other layers consume it.
2PsonoSeparate VPS. Credentials, isolated blast-radius.
3Lufi + YOPassColocate on hostinger-vps. Single-client pilot.
4Nextcloud HubVault SSE tier. Operator processing surface.
5SeafileDefer until persistent client-held-key demand materializes.

Each step independently abortable. Not Pantheon-ceremony — research-arc brief, not adoption-execution arc.

Open Questions for Operator

  1. Hosting layout — colocate full stack on hostinger-vps with plutus, or break out credentials (Psono) to separate small VPS for blast-radius isolation?
  2. YOPass audit-log gating — confirm whether NDJSON audit-log is OSS-free or license-key-gated (vendor docs ambiguous). Affects GDPR-record posture.
  3. R2 custody for ciphertext KYC — comfortable holding E2E ciphertext on Cloudflare R2, or pin all KYC ciphertext to Hetzner/Advania EU disk?
  4. Single vault vs two-tier — pick Nextcloud SSE-only (accept E2E gap) vs recommended Seafile+Nextcloud split?
  5. Cryptomator Hub overlay — adopt as separate encryption-overlay product, or skip for simplicity?
  6. Per-client tenancy in Authentik — single Authentik with per-client groups (ops simplicity) vs one-Authentik-per-client (stronger isolation)?
  7. Client-side IdP federation — accept federation to client's Google Workspace / Microsoft Entra (lower friction) vs require fresh Authentik account per client (cleaner audit)?
  8. DocuSeal handoff for client-intake — front the intake door with DocuSeal (already adopted) + webhook into Psono/Lufi, or run parallel intake UX?
  9. Endpoint AV strategy — pursue post-decrypt ClamAV at agency endpoint now, or defer until incident motivates?
  10. AGPL forward-flag — confirm shared understanding: today's self-host posture unaffected; future SaaS productization re-opens licensing arc.

Reject Pile

Track A — Credentials (7 rejected)
  • Padloc — abandoned, 0 commits in 90d
  • Pleasant / Topicus KeyHub — proprietary
  • Bitwarden self-host — 60× RAM vs Vaultwarden, no UX edge
  • Passbolt CE — no link-share-to-non-user, SSO Pro-walled
  • Teampass — weaker E2E story
  • KeePassXC + sync — not a server
  • Vaultwarden — considered top contender, but Send is one-way only (intake direction violates spec)
Track B — File intake/delivery (7 rejected)
  • YeetFile — archived 2026-04-07
  • PsiTransfer / Erugo / ProjectSend — transport-only, no E2E
  • Hush Line — one-direction tip-line only
  • Bitwarden Send file tier — paid, weak self-host parity
  • OnionShare — Tor-only edge case
  • CryptPad — heavy full office suite, AGPL embedding constraint
  • timvisee/send (Firefox Send fork) — technically excellent, but 11-month release gap; reconsider only if 2026 release lands
Track C — Vault + Auth (11 rejected)
  • Standard Notes server / Joplin Server — notes only, no file vault
  • Cryptee — proprietary
  • Pydio Cells — commercial-first
  • ownCloud Infinite Scale — less mature than Nextcloud for this use case
  • Authelia — lighter, but weaker connector breadth than Authentik
  • Ory stack — developer-grade, not turnkey enough
  • FusionAuth — commercial-OSS license uncertainty
  • Pocket-ID — too narrow
  • Keycloak — Red Hat heavyweight, overkill
  • Nextcloud-native E2EE alone — mnemonic-loss = data-loss, browser collab off, ONLYOFFICE Desktop the only E2EE co-edit path