Security Model

Accounts, tools, encryption, and platform safety.

A public overview of how RG Herd handles standard accounts, Matrix encryption, operational coordination, access controls, help services, data retention, moderation, and administrative responsibility.

Scope

System-wide security posture

These principles apply across RG Herd tools where relevant, not only to | base |.

Identity

Standard accounts avoid identity collection

Standard RG Herd accounts do not require a legal name, government ID, phone number, email address, or external identity provider.

Coordination

Sensitive content belongs in encrypted chat

Tools such as ARGUS are intended for coordination data. Sensitive personal or tactical discussion should move through encrypted | base | rooms when appropriate.

Authority

Access is controlled by RG Herd

RG Herd reserves final authority over server access, safety decisions, infrastructure, and policy enforcement.

RG Herd is built to be safer community infrastructure, not a no-logging or no-moderation zone. The model is privacy-respecting, operationally accountable, and explicit about its limits.

Accounts

Pseudonymous by default

RG Herd asks for the least information needed to operate the system safely.

What it is

An RG Herd account

A standard RG Herd account gives access to | base | and connected community tools without requiring real-world identifying information.

What it does

One identity for core tools

The account is your local RG Herd identity. In Matrix terms, it maps to a Matrix ID such as @name:rgherd.com.

Advanced access

Higher trust may require more review

Administrative access, community administration features, RGTV stream keys, and other sensitive tools may require vetting, an access application, identifying information, and a non-disclosure agreement.

How standard registration works

Standard account creation is gated through registration tokens or operator-approved onboarding paths. This reduces automated spam, impersonation, and drive-by abuse without requiring routine users to provide identifying information.

Registration tokens may be single-use, time-limited, or revoked. If a token expires or has already been used, request a new one through the normal help path.

When identifying information may be required

Standard user accounts do not require identifying information. Higher-risk roles are different. Access to community administration features, RGTV stream keys, ARGUS operator access, and other sensitive tools may require direct vetting, an application, an NDA, and enough information for RG Herd to evaluate trust and accountability.

This protects users, community groups, operators, records, and infrastructure from preventable access abuse.

What operational data means

Operational data is data needed to run services, protect accounts, prevent abuse, support moderation, investigate security events, maintain auditability, and keep systems reliable.

It can include account records, registration-token records, session/device information, server logs, abuse signals, moderation records, help requests, application records, stream-key records, administrative audit records, and infrastructure health signals.

Pseudonymous access does not mean consequence-free access. Abuse, harassment, spam, credential attacks, doxxing, evasion, and other safety issues may still trigger moderation, access restrictions, blocking, or reporting.

Matrix basics

What Matrix is doing under | base |

| base | is RG Herd's Matrix communication layer. Matrix is the protocol underneath the client experience.

What it is

A communication protocol

Matrix is a chat and real-time communication protocol. A user registers with a provider or homeserver and uses a Matrix ID to communicate.

How it works

Client plus homeserver

A Matrix client is the app you use. The homeserver stores your account, rooms, devices, and server-side state. RG Herd's homeserver identity is rgherd.com.

Why it helps

Portable client model

Matrix accounts can be used from different Matrix clients. That gives users more choice than a single locked-in app model.

What a Matrix ID is

A Matrix ID is the handle other users use to find and invite you. RG Herd account IDs look like @username:rgherd.com.

Your display name can be friendlier than your Matrix ID, but the Matrix ID is the stable account address.

What a Matrix client is

A client is the app or web interface used to access the Matrix account. Element Web, Element Desktop, Element X, and other compatible clients can connect to Matrix accounts when configured correctly.

Different clients may expose encryption, recovery, verification, and search features differently. When in doubt, use the RG Herd setup guide and current Element documentation.

Encryption

Encrypted rooms use device-managed keys

Matrix encryption protects message content in encrypted rooms, but it depends on your devices, sessions, and recovery setup.

What it is

End-to-end encryption

In an encrypted room, message content is encrypted before it leaves your device and stays encrypted until it reaches the intended participants' devices.

How it works

Keys live with devices

Matrix devices create cryptographic keys for encrypted communication. Private key material is intended to remain on the user's device.

Why it helps

Servers carry ciphertext

RG Herd servers help deliver encrypted events, but they cannot read encrypted room history without the user's device-managed keys.

What encrypted rooms protect

Encrypted rooms protect message and file content for participants in that encrypted conversation. This is useful for private coordination, sensitive conversations, and reducing server-side exposure of message content.

Encryption is room-specific. Not every Matrix room is automatically encrypted. Public rooms, announcement rooms, and some operational rooms may be intentionally unencrypted.

What encryption does not hide

End-to-end encryption does not erase all operational metadata. Homeservers may still process account records, device/session data, room membership state, moderation records, delivery metadata, server logs, and abuse signals.

Treat encryption as strong content protection, not as a promise that every trace of platform activity disappears.

Encrypted content cannot be recovered by RG Herd

It is not possible for RG Herd to read or recover user encrypted content without the user's encryption material. RG Herd will not attempt, authorize, or permit attempts to recover encrypted user content lost because of encryption, device, session, or Recovery Key issues.

This applies whether the loss was caused by user error, device loss, client behavior, or an RG Herd service issue.

Official Matrix encryption references

Matrix's official documentation explains that Matrix end-to-end encryption is based on Olm and Megolm, with separate device keys and room encryption behavior.

Matrix end-to-end encryption guide → Element encryption help →
Recovery

Recovery Key and Secure Backup

Recovery setup is what keeps encrypted history usable when devices change.

What it is

Encrypted key backup

Key storage lets your encrypted message keys be backed up in encrypted form so new devices can regain access to encrypted history.

What it does

Restores history access

Your Recovery Key helps unlock that encrypted backup when you add a new device or lose access to existing trusted sessions.

Why it matters

Lost keys can mean lost history

If you lose all trusted sessions and your Recovery Key, old encrypted messages may not be decryptable.

Where to store a Recovery Key

Store the Recovery Key somewhere durable and private: a password manager, hardware-encrypted storage, or a secure offline physical location.

Do not post it in chat, send it casually to another person, or leave it in a place that would compromise your account if found.

What happens if the Recovery Key is lost

You may still be able to use the account if you can log in, but old encrypted history may be unavailable on new devices.

If all devices are lost and the Recovery Key is gone, you may need to reset encryption recovery. Other users may see that your digital identity was reset, and previously verified contacts may need to verify you again.

Official recovery reference

Element documents key storage, Recovery Keys, and what happens when recovery material is lost.

Element Recovery Key help →
Verification

Trusted devices and trusted people

Verification helps confirm that devices and contacts are who they claim to be.

What it is

Device verification

Device verification confirms that a new session belongs to the account owner rather than someone who merely obtained account access.

What it does

Builds trust

Verification connects a new device to an existing trusted session or Recovery Key so encrypted conversations remain trustworthy.

Why it matters

Reduces impersonation risk

User verification helps protect sensitive conversations against identity replacement and advanced man-in-the-middle attacks.

How verification usually works

Element commonly uses QR-code scanning or emoji comparison for user verification. The comparison should happen through a trusted side channel, such as in person, live video, or another channel you already trust.

For new devices, verify from an existing trusted session when possible. If that is not available, use the Recovery Key.

Digital identity reset alerts

If a contact's digital identity resets, confirm with them before assuming everything is normal. A reset often happens because someone lost all devices or recovery material, but it can also indicate a security issue.

Previously verified contacts should be re-verified after a reset.

Official verification reference

Element's documentation explains identity pinning, user verification, digital identity reset warnings, and new-device verification.

Element verification help →
Connected tools

How RG Herd tools fit the model

Different tools have different trust levels, data boundaries, and access rules.

| base |

Account and communication layer

| base | is the Matrix communication layer for accounts, rooms, encrypted chat, verification, and coordination between users.

ARGUS

Operational coordination

ARGUS is RG Herd's operational coordination system. Responder participation can be gated by vetted members, while dispatch and administration roles require RG Herd application and direct vetting.

Sites

Public information surfaces

RG Herd sites, including public help pages, ALERTS, and related public pages, are used for information, onboarding, publishing, and public access points.

ARGUS access and data boundaries

ARGUS uses tiered access. Vetted members and approved organizations may be able to add or gate responder-level users for coordination work. Deeper access, including dispatch, administration, sensitive records, or elevated operational roles, requires an ARGUS Access application and direct RG Herd vetting.

Dispatch, administration, community administration, and other sensitive ARGUS roles may require identifying information, an Administrative Access application, and a non-disclosure agreement. Sponsorship can streamline enrollment, but RG Herd retains final authority over access.

ARGUS should be used as coordination data only. Records may include operational requests, needs, resources, statuses, assignments, notes, and related coordination records. Sensitive details should move through encrypted | base | chat when appropriate.

ARGUS records may be held until purged by an administrator. Retention and purge policy may be adjusted through RG Herd's community-informed democratic procedures, subject to final RG Herd operational authority.

Help services

RG Herd support is split between member support and public contact. Active RG Herd users can use the member support form for account setup, login trouble, | base | issues, ARGUS access problems, public site issues, and related support.

People who are not active RG Herd users should use the public contact email for general help, individual access requests, group access requests, registration questions, onboarding, and community organization inquiries.

A | base | Help Bot for Matrix chat support is planned for a later phase.

Open member support form → Email RG Herd help →
RGTV and stream keys

RGTV streamer access is available to users in high standing and community group leaders. Stream keys require approval and a Stream Key application.

Stream access can be granted, limited, rotated, or revoked to protect the broadcast surface and the wider community.

Admin tooling and sensitive features

Administrative tooling is not ordinary user access. Access to community administration features, registration controls, stream keys, ARGUS operator features, and other sensitive tools may require vetting, an Administrative Access application, identifying information, and a non-disclosure agreement.

Administrative actions are logged. Privileged workflows may be reviewed when needed for safety, auditability, abuse response, or operational integrity.

Infrastructure

Public edge, monitoring, and operational controls

RG Herd separates public access from administrative control and treats security as an ongoing operating practice.

Access edge

HTTPS and reverse proxy

Public services are served over HTTPS through a reverse-proxy and access-gating model. Internal and administrative services are separated from ordinary public access.

Observability

Stability and error monitoring

RG Herd monitors uptime, service health, errors, and operational signals that affect reliability and safety.

Continuity

Backups and restoration

Backup and restoration procedures are part of the operating model for critical configuration, databases, and services.

Reliability posture

RG Herd is operated with a high-availability goal and currently presents a 99.99% uptime posture for public confidence. This is not a service guarantee.

Formal limitations, warranty language, and user obligations are governed by the RG Herd Terms of Service and Privacy & Security policy.

Read Terms → Read Privacy & Security →
Abuse controls

RG Herd may use intrusion detection, rate limits, reputation-based reporting, access controls, forced secret rotation, and manual review to respond to spam, probing, credential attacks, evasion, and abusive behavior.

The goal is to reduce harm without forcing routine users to provide identifying information.

Data retention and secret rotation

RG Herd retains operational data only as long as needed for service operation, safety, abuse response, moderation, auditability, or legal and technical requirements.

Forced secret rotation and retention-policy changes may be handled through RG Herd's community-informed democratic procedures, subject to final RG Herd operational authority.

Open-source verification

Public/community RG Herd tools are open-source where practical. Private configuration, credentials, secrets, infrastructure internals, and administrative tooling are excluded.

Open-source review helps users and outside reviewers inspect the behavior of public tools rather than relying only on trust.

Sensitive access

Applications, vetting, and approval

Public availability is not the same as unrestricted access.

ARGUS

Application and vetting

ARGUS responder access may be gated by vetted members or approved organizations. Dispatch and administration roles require application, direct RG Herd vetting, and may require an NDA.

RGTV

High-standing users and group leaders

RGTV stream keys are available to approved users in high standing and community group leaders through a Stream Key application.

Admin features

Higher trust threshold

Registration controls, community administration features, and sensitive tools may require an Administrative Access application, identifying information, vetting, and an NDA.

RG Herd may grant, deny, limit, rotate, suspend, or revoke sensitive access based on operational need, user standing, safety concerns, policy requirements, or infrastructure risk.

Governance

Community safety and operator responsibility

RG Herd is community-informed infrastructure with operator responsibility for safety, legality, and uptime.

Moderation

Community-led where practical

Moderation is intended to reflect community needs, clear safety expectations, context, and real risk.

Policy

Community-informed

RG Herd policies may adjust as user needs, safety realities, technical constraints, and operational limits change.

Operations

Final operator authority

RG Herd reserves final say over server operation, access, security, infrastructure, and policy enforcement.

Why final operator authority exists

Community input matters, but infrastructure has legal, security, abuse, privacy, and reliability obligations that cannot be delegated to open-ended debate during an incident.

Final operator authority keeps emergency decisions, access control, and policy enforcement accountable and fast enough to protect the platform.

Security, vulnerability, and safety reports

Active RG Herd users should use Help Intake for structured issues. Other help requests and sensitive security concerns should be directed to the public contact email unless RG Herd gives different instructions.

Do not test against RG Herd infrastructure in ways that disrupt users, bypass access controls, expose private data, or create operational risk.

Open Help Intake → Email RG Herd help →
Limits

What this model does not promise

Clear limits are part of a credible security model.

No recovery of lost encrypted content

RG Herd cannot read or recover encrypted user content without the user's encryption material. RG Herd will not attempt or allow attempts to recover user encrypted content lost because of encryption, device, session, or Recovery Key issues.

No guarantee that metadata does not exist

Encrypted room content may be protected, but operational metadata can still exist. Account records, device/session data, logs, room state, moderation records, help records, and abuse signals may be processed when needed.

No unrestricted access to sensitive tools

ARGUS dispatch/admin access, RGTV stream keys, registration controls, community administration features, and other sensitive tools require approval. Access may be limited, denied, rotated, suspended, or revoked.

No service warranty from uptime language

RG Herd may publish uptime posture and operational confidence information, but service availability, warranty limits, acceptable use, and liability are governed by the Terms of Service and Privacy & Security policy.

Read Terms → Read Privacy & Security →