Only you hold the key.
Your documents are encrypted on your device before they ever leave it. Our servers only ever hold scrambled blobs and public keys — never anything they could read.
How your data is protected
Locked before it leaves your hands
Encryption happens entirely on your device. Here is the chain that keeps your documents readable to you and no one else.
- 01
Your passphrase
You choose a passphrase only you know. It is strengthened with Argon2 and never sent to us — it stays on your device.
- 02
Unlocks your Master Key
Your passphrase unlocks a private Master Key that lives on your device. We only store it in a locked, unreadable form.
- 03
Every file gets its own key
Each document is sealed with its own unique AES-256-GCM key, so no two files share the same lock.
- 04
Wrapped so only you can open
Each file key is wrapped by your Master Key before upload. Only your device can unwrap it — the server never sees it open.
Your passphrase, Master Key, private key, file keys, and documents never leave your device unencrypted.
Secure sharing
Share without handing over the keys
When you share, your device re-wraps that file’s key to the recipient’s public key (X25519). The server only relays the scrambled file and the wrapped key — it never sees either one unlocked.
Your device
Re-wraps the file key to the recipient
Our server
Relays the blob — can’t read it
Recipient
Unwraps it with their private key
Account level
Family Access
Enter a family member’s email and a number of days. Access starts immediately, lets them view your documents, and expires automatically when the window ends.
- No acceptance step needed
- Auto-expires after N days
File level
Single document
Share just one file for a one-off request — a certificate or a bill — while the rest of your library stays completely private.
- Everything else stays private
- Perfect for one-off requests
Instant revocation
Take back access the instant you change your mind
Because shared documents pull their key live for every view, revoking is immediate. Access ends the second you say so — no waiting, no leftover copies that stay readable.
Keys fetched live, per view
Each time someone opens a document you shared, their device fetches the wrapped key fresh from the server.
Revoke and it stops
The moment you revoke, that key is gone. The next view — even mid-session — can no longer be decrypted.
No re-encryption needed
Nothing has to be re-scrambled or re-uploaded. Cutting off the key is enough to lock people out.
Offline & on-device
Fast when you are offline, safe when you are not
Everything is designed to work on your device first — so speed never comes at the cost of who can read your files.
Your documents, offline
Your own files cache their encrypted blob and wrapped key on your device, so you can open them even with no signal.
Shared docs stay honest
Documents shared with you cache the encrypted blob only. The key is still fetched live, so revocation always holds.
Biometric & offline unlock
Unlock with your fingerprint or face. Decryption still happens on your device — the passphrase never leaves it.
Full transparency
What our servers can and cannot see
Zero-knowledge means exactly that. Here is the honest split of what lives on our servers.
Never visible to us
- Your passphrase
- Your Master Key
- Your private key
- Your file keys (unwrapped)
- Your documents in readable form
Only ever stored
- Encrypted document blobs
- Wrapped (locked) keys it can’t open
- Your public key, for sharing
Security you don’t have to think about
See the full journey of a document, or pick a plan and start protecting what matters.