Trust design

Useful to you. Unreadable to us.

The service contract stores versioned ciphertext, wrapped keys, and the minimum account metadata needed to operate—not vault plaintext.

Client-side encryption

Items and attachments are authenticated and encrypted before sync. Master passwords and unwrapped vault keys stay at the client boundary.

Separate account access

Verified email and passkeys authorize an account session; they do not unlock vault contents. Recovery authority cannot act as a universal decryption key.

Evidence, not absolutes

Internal tests are not an independent security approval. Cryptographic, penetration, privacy, extension, mobile, and operational reviews remain release gates.