Nomosis Docs
The Nomosis Viewer

Encrypted Capsules

Protect molecular data in an encrypted, signed container and verify its provenance before use.

A capsule is an encrypted, signed molecular-data container with the .nmc extension. Encryption protects content confidentiality; the signature and integrity information help you confirm who created the capsule and whether its contents have changed.

When to use a capsule

Use a capsule when molecular data requires protected storage or controlled exchange and provenance must travel with the file. Use a normal structure export when encryption and verification are not part of the workflow.

Save a capsule

Encryption is enabled intentionally when you save the capsule.

Confirm the active project and molecular scope.
Open Applications → Capsules → My capsules.
Choose the action to create or save a capsule.
Select the molecular data that should be included.
On first use, create or unlock the protected signing and encryption key with your passphrase.
Save the .nmc file and preserve the associated recovery material according to your organization's policy.

Capsule content is encrypted end to end. The service stores protected data without receiving the plaintext molecular content or your private keys.

Verify before you trust

When you open a capsule, inspect its trust state before using the data.

Verified state

A green Verified badge indicates that the available signature and integrity checks passed. Open the provenance details and review:

  • Signer identity.
  • Signing date.
  • Integrity root or fingerprint.
  • Encryption information.

Verification confirms technical integrity and signer provenance. You must still decide whether the signer is trusted and whether the data is appropriate for your scientific workflow.

Warning state

An amber or red warning indicates that verification did not complete successfully or the capsule does not match its signed integrity information.

Stop the workflow and do not export or redistribute the data.
Record the warning and provenance details.
Confirm the source with the expected sender through an approved channel.
Obtain a new capsule if integrity or provenance cannot be established.

Do not dismiss a verification warning merely because the molecular structure appears plausible. Visual appearance does not prove file integrity or origin.

Protect and recover your key

Your key is protected by a passphrase and can be recovered from the supported protected backup. Use a unique, strong passphrase and store recovery material according to your organization's security policy.

  • Do not share your passphrase in chat, email, or a story subtitle.
  • Do not store the capsule and unprotected recovery material together.
  • Test the approved recovery process before a critical handoff depends on it.
  • Report suspected key exposure through your organization's security process.

Share a capsule

Where internal sharing is enabled, use explicit grants to share selected capsule content with named people. Grants can be time-limited or revoked according to the available controls.

Before sharing:

  1. Verify the recipient identity.
  2. Confirm the exact molecular scope.
  3. Set the shortest practical access period.
  4. Verify the capsule yourself.
  5. Revoke access when the collaboration ends.

Do not assume that forwarding a .nmc file provides the same identity, policy, or revocation controls as an approved internal grant.

Capsule versus viewer session

CapabilityCapsuleViewer session
Encrypted molecular containerYesNot its primary purpose
Signature and integrity verificationYesNo
Complete visual workspace checkpointLimited to supported capsule contentYes
Camera, presentation, and analysis continuityNot the primary useYes
Controlled protected exchangeYesUse project access or approved sharing workflow

Use both when necessary: a capsule for protected molecular data, and a named viewer session for the reproducible analysis state.

On this page