The web vault encrypts in the browser. We hold ciphertext and wrapped keys — not your passphrase.
Files are encrypted in the browser with authenticated AES-GCM before upload. Integrity is checked on decrypt.
Vault keys are wrapped with a key derived from your passphrase on your device. We never receive the passphrase.
Server-side storage is ciphertext. We cannot open your files. Account email and operational metadata are still ours to hold.
Your vault encrypts on your device with passphrase-wrapped keys. Independent security review is on the roadmap. Report a concern anytime at admin@verndr.com.
AES-GCM runs in the browser. Plaintext files are not uploaded.
Your passphrase wraps the vault key locally. Losing the passphrase means we cannot recover the vault.
Account email, ciphertext blobs, and operational logs. That is not “no data even when compelled.”
The web vault is invitation-only Alpha. When a third-party audit exists, the report will be linked here. Until then, nothing to download.
Request inviteNo cash bounty tiers. If you find a security issue in the marketing site or the web vault Alpha, email details and reproduction steps.