Security
Security you can
verify, not trust.
We don't ask you to take our word for it. Our security model is built on cryptographic guarantees and published third-party audits.
How it works
Security architecture
End-to-end encryption
All content is encrypted on your device using AES-256-GCM before transmission. Our servers never see plaintext data. Your keys are derived from your master password using Argon2id and never leave your device.
Zero-knowledge architecture
We are technically incapable of reading your data. Even under a court order, we can only provide encrypted ciphertext. This is not a policy — it is a cryptographic guarantee built into our architecture.
Key management
Your encryption keys are derived from your master password using Argon2id with a unique salt. We store only a salted hash of your password verifier — never the password or key itself. Key derivation happens entirely client-side.
Infrastructure security
Our infrastructure runs in ISO 27001-certified data centres in the UK and EU. All data is encrypted at rest using AES-256. All data in transit is protected by TLS 1.3. We perform regular penetration tests and vulnerability assessments.
Authentication
We support TOTP-based two-factor authentication, hardware security keys (FIDO2/WebAuthn), and OAuth via Google. All authentication events are logged and you are notified of new device logins.
Third-party audits
Our cryptographic implementation and infrastructure are audited annually by independent security firms. Audit reports are published in full on our website. We operate a public bug bounty programme through HackerOne.
Compliance
Certifications & standards
ISO 27001
Information security management
SOC 2 Type II
Security, availability, and confidentiality
UK Cyber Essentials Plus
NCSC-certified baseline security
GDPR / UK GDPR
Data protection compliance
Bug bounty
Responsible disclosure
Found a security vulnerability? We want to hear from you. We operate a public bug bounty programme and commit to responding within 24 hours, providing regular updates, and rewarding valid reports. We will never take legal action against researchers acting in good faith.
Report a vulnerability