Bank-Level Security

Built so we can't peek

Your vault is encrypted in your browser with a key only you hold. Even with full server access, we see ciphertext - nothing more.

Client-Side Encryption

AES-GCM 256, derived with PBKDF2 (600k iterations) in your browser.

Zero-Knowledge Architecture

We never receive your passphrase. Lose it and not even we can recover files.

Hidden Filenames

Filenames are encrypted too. Admins see only opaque IDs.

Immutable Audit Logs

Every vault event is append-only and visible only to you.

MFA Everywhere

Required for sign-in, vault unlock, and disclosure events.

Hardened Infrastructure

Encrypted at rest. TLS 1.3 in transit. Region-pinned storage.

What admins CAN see

  • • Your account email and billing status
  • • Vault file count and total size
  • • Disclosure request status (pending, vetoed, released)
  • • Aggregate metrics for fraud monitoring

What admins CANNOT see

  • • Your passphrase
  • • File contents or filenames
  • • Your asset locations or clues
  • • Your private audit log