FeaturesPricingFAQSecurityAffiliatesContact
Security Architecture

Encrypted. Local. Zero Trust.

Your keys stay on your device. Period. Here's how we make sure of it — no marketing fluff, just the facts.

4
Encryption Layers
3
Sub-Keys
0
Unsafe Code Lines
128 MiB
Argon2id Memory Cost

What We Promise

Zero Trust by Design
Every encryption operation happens on your machine. We never see your plaintext keys.
Battle-Tested Encryption
XChaCha20-Poly1305 — the same algorithm trusted by leading security teams worldwide.
Public Algorithms
Every encryption algorithm is published and peer-reviewed. The math is public.
Secure Memory Handling
Keys are wiped from memory the moment they're used. No traces left behind.

Under the Hood

Authenticated Encryption
XChaCha20-Poly1305 (RFC 8439) — 192-bit nonce, tamper-proof and fast.
Key Derivation
Argon2id (RFC 9106) — 128 MiB memory cost, resistant to GPU/ASIC brute-force.
Domain Separation
HKDF-SHA256 — derives encryption keys, HMAC keys, and sub-keys from the master key.
Tamper Detection
HMAC-SHA256 — independent HMAC tag separate from AEAD, prevents tampering.
Per-Key Salt
Each stored key uses an independent random salt. Same key, different ciphertext every time.

Application Security

Content Security Policy
Strict resource loading rules block XSS and data exfiltration.
IPC Rate Limiting
Password attempts: 5/60s, TOTP: 5/30s, leak scans: 5/5min.
Sandboxed File Access
File I/O restricted to app data directory. Path traversal not possible.
Authenticated Proxy Endpoints
Random token protects management API. Local processes cannot enumerate key mappings.
Response Header Filter
Only whitelisted security headers pass through from upstream API responses.

Memory Safety

Zeroize on Drop
Rust zeroize crate — keys and master password are automatically cleared when out of scope.
No Unsafe Code
#[forbid(unsafe_code)] — zero unsafe code in the encryption core.
Auto-Clear on Lock
Master key and all plaintext keys are immediately removed from memory when the vault is locked.

TOTP 2FA

Standard Protocol
RFC 6238 TOTP + RFC 4226 HOTP — 6-digit dynamic code, 30-second window.
Encrypted Storage
TOTP secret keys encrypted with XChaCha20-Poly1305, derived separately from the master key.
Rate Limited
5 failures per 30 seconds, preventing brute-force attacks.

Known Limitations & Future Improvements

  • No third-party security audit yet (planned post-launch)
  • No bug bounty program yet (planned after v2.0)
  • No FIPS 140-2 certification (planned based on market demand)
  • Currently Windows desktop only; macOS/Linux support in development