Relay compromise
An attacker who fully owns the relay sees metadata only: which install talks to which agent, timing, size. Payload contents are E2EE between desktop and agent. The audit chain is signed externally; tampering breaks the chain visibly.