DocWallet
Zero-knowledge encryption

Only you hold the key.

Your documents are encrypted on your device before they ever leave it. Our servers only ever hold scrambled blobs and public keys — never anything they could read.

Encrypted on your device
Unreadable to us
Keys never leave you

How your data is protected

Locked before it leaves your hands

Encryption happens entirely on your device. Here is the chain that keeps your documents readable to you and no one else.

  1. 01

    Your passphrase

    You choose a passphrase only you know. It is strengthened with Argon2 and never sent to us — it stays on your device.

  2. 02

    Unlocks your Master Key

    Your passphrase unlocks a private Master Key that lives on your device. We only store it in a locked, unreadable form.

  3. 03

    Every file gets its own key

    Each document is sealed with its own unique AES-256-GCM key, so no two files share the same lock.

  4. 04

    Wrapped so only you can open

    Each file key is wrapped by your Master Key before upload. Only your device can unwrap it — the server never sees it open.

Your passphrase, Master Key, private key, file keys, and documents never leave your device unencrypted.

Secure sharing

Share without handing over the keys

When you share, your device re-wraps that file’s key to the recipient’s public key (X25519). The server only relays the scrambled file and the wrapped key — it never sees either one unlocked.

Your device

Re-wraps the file key to the recipient

ciphertext only

Our server

Relays the blob — can’t read it

wrapped key

Recipient

Unwraps it with their private key

Account level

Family Access

Enter a family member’s email and a number of days. Access starts immediately, lets them view your documents, and expires automatically when the window ends.

  • No acceptance step needed
  • Auto-expires after N days

File level

Single document

Share just one file for a one-off request — a certificate or a bill — while the rest of your library stays completely private.

  • Everything else stays private
  • Perfect for one-off requests

Instant revocation

Take back access the instant you change your mind

Because shared documents pull their key live for every view, revoking is immediate. Access ends the second you say so — no waiting, no leftover copies that stay readable.

  • Keys fetched live, per view

    Each time someone opens a document you shared, their device fetches the wrapped key fresh from the server.

  • Revoke and it stops

    The moment you revoke, that key is gone. The next view — even mid-session — can no longer be decrypted.

  • No re-encryption needed

    Nothing has to be re-scrambled or re-uploaded. Cutting off the key is enough to lock people out.

Offline & on-device

Fast when you are offline, safe when you are not

Everything is designed to work on your device first — so speed never comes at the cost of who can read your files.

Your documents, offline

Your own files cache their encrypted blob and wrapped key on your device, so you can open them even with no signal.

Shared docs stay honest

Documents shared with you cache the encrypted blob only. The key is still fetched live, so revocation always holds.

Biometric & offline unlock

Unlock with your fingerprint or face. Decryption still happens on your device — the passphrase never leaves it.

Full transparency

What our servers can and cannot see

Zero-knowledge means exactly that. Here is the honest split of what lives on our servers.

Never visible to us

  • Your passphrase
  • Your Master Key
  • Your private key
  • Your file keys (unwrapped)
  • Your documents in readable form

Only ever stored

  • Encrypted document blobs
  • Wrapped (locked) keys it can’t open
  • Your public key, for sharing

Security you don’t have to think about

See the full journey of a document, or pick a plan and start protecting what matters.