Ce que nous voyons
- E-mail, UID, pays
- Volume PJ chiffrées (taille agrégée)
- Dernière connexion
- Statut premium
Schéma d'architecture : la clé reste sur votre appareil ; seuls des blobs chiffrés transitent vers le cloud.
Architecture de confiance
Pipeline upload chiffré
Sélectionnez un fournisseur pour afficher le schéma de flux correspondant.
Flux e-mail / mot de passe → Auth cloud
Mot de passe jamais stocké en clair. Jeton session émis → verrou app et clés device → 2FA optionnelle.
Flux Google Sign-In (OAuth 2.0 / OpenID)
SNT Chat ne reçoit jamais votre mot de passe Google. uniquement un jeton d'identité validé par le fournisseur d'identité.
Flux Facebook Login (Meta OAuth)
Flux GitHub OAuth
Flux Passkey WebAuthn
Anti-phishing : la passkey ne fonctionne que sur sntchat.com et l'app officielle.
Flux 2FA TOTP (Google Authenticator)
Schémas verrou app, pièces jointes et téléchargement. tout le déchiffrement reste local.
Initialisation clé maître (zero-knowledge)
Envoi PJ · AES-256-GCM côté client
Téléchargement. déchiffrement uniquement sur l'appareil
Cartographie des composants et contrôles d'accès.
Stack technique SNT Chat
| Composant | Rôle | Données | Sécurité |
|---|---|---|---|
| Auth cloud | Identité | E-mail, OAuth, hash | Jetons signés |
| Base cloud | Métadonnées | Profil, index | Rules par UID |
| Cloud Functions | Logique | Passkeys, webhooks | Auth obligatoire |
| Stockage chiffré | Stockage | Blobs chiffrés | Clés API restreintes |
| Cloudflare | Réseau | Trafic web | DDoS, DNSSEC |
| Facturation in-app | Abonnements | Statut premium | Webhooks signés |
Signalement vulnérabilité : support@sntchat.com
Hors ligne, en lieu sûr.
Double couche de protection.
Protège l'app sur mobile.
Architecture diagram: the key stays on your device; only encrypted blobs travel to the cloud.
Trust architecture
Encrypted upload pipeline
Select a provider to display the corresponding flow diagram.
Email / password flow → Auth cloud
Password never stored in plain text. Session token issued → device lock and keys → optional 2FA.
Google Sign-In flow (OAuth 2.0 / OpenID)
SNT Chat never receives your Google password, only a validated identity token from identity provider.
Facebook Login flow (Meta OAuth)
GitHub OAuth flow
Passkey WebAuthn flow
Anti-phishing: passkeys only work on sntchat.com and the official app.
2FA TOTP flow (Google Authenticator)
App lock, attachments diagrams, all decryption stays local.
Master key initialization (zero-knowledge)
Attachment send · client-side AES-256-GCM
Download · decryption only on device
Component map and access controls.
SNT Chat technical stack
| Component | Role | Data | Security |
|---|---|---|---|
| Auth cloud | Identity | Email, OAuth, hash | Signed tokens |
| Base cloud | Metadata | Profile, index | Rules per UID |
| Cloud Functions | Logic | Passkeys, webhooks | Auth required |
| Stockage chiffré | Storage | Encrypted blobs | Restricted API keys |
| Cloudflare | Network | Web traffic | DDoS, DNSSEC |
| Facturation in-app | Subscriptions | Premium status | Signed webhooks |
Vulnerability reporting: support@sntchat.com
Offline, in a safe place.
Double layer of protection.
Protects the app on mobile.