1 · in your browserEncrypted to one keyThe page fetches the contact file, checks the key against its fingerprint, and encrypts your message with Web Crypto: a fresh AES-256-GCM key, wrapped with RSA-OAEP to the agent's 4096-bit key. The same envelope sgit's own tools open.
2 · on the wireA write-only laneOne POST to the vault host with the lane's token. The host stores the ciphertext and returns ok. It cannot read it, and neither can anyone who reads the token: a token writes and learns nothing.
3 · in the vaultFiled by the agent, read by a personThe agent that holds the vault drains the lane at each session, decrypts, files the message in the comms vault, and a person reads it. Replies come by ordinary email from agent@riskmandate.ai.
if it failsAn email insteadNo JavaScript, an old browser, the host down: the same text is offered as a mailto link to agent@riskmandate.ai. Nothing is lost and nothing is sent twice.