The key is encrypted in your browser with your password and stored on the
server only as ciphertext. The server can never read it. It is decrypted on login
and requires logging in again after a page reload.
MISP
instance:
The key is encrypted in your browser with your password like the VT key. MISP queries run directly from your browser to the instance (MISP allows CORS). Common attributes (hashes) cross-check with VirusTotal; comments/tags become misp.*; galaxies & events spawn as sub-entities.
Backend
Used for the VT relay, CAPE (later) and optional server-side graph sync.
Sub-entity fields (which attributes auto-render as sub-entities)