Security

Security you can
verify, not trust.

We don't ask you to take our word for it. Our security model is built on cryptographic guarantees and published third-party audits.

How it works

Security architecture

End-to-end encryption

All content is encrypted on your device using AES-256-GCM before transmission. Our servers never see plaintext data. Your keys are derived from your master password using Argon2id and never leave your device.

Zero-knowledge architecture

We are technically incapable of reading your data. Even under a court order, we can only provide encrypted ciphertext. This is not a policy — it is a cryptographic guarantee built into our architecture.

Key management

Your encryption keys are derived from your master password using Argon2id with a unique salt. We store only a salted hash of your password verifier — never the password or key itself. Key derivation happens entirely client-side.

Infrastructure security

Our infrastructure runs in ISO 27001-certified data centres in the UK and EU. All data is encrypted at rest using AES-256. All data in transit is protected by TLS 1.3. We perform regular penetration tests and vulnerability assessments.

Authentication

We support TOTP-based two-factor authentication, hardware security keys (FIDO2/WebAuthn), and OAuth via Google. All authentication events are logged and you are notified of new device logins.

Third-party audits

Our cryptographic implementation and infrastructure are audited annually by independent security firms. Audit reports are published in full on our website. We operate a public bug bounty programme through HackerOne.

Compliance

Certifications & standards

ISO 27001

Information security management

SOC 2 Type II

Security, availability, and confidentiality

UK Cyber Essentials Plus

NCSC-certified baseline security

GDPR / UK GDPR

Data protection compliance

Bug bounty

Responsible disclosure

Found a security vulnerability? We want to hear from you. We operate a public bug bounty programme and commit to responding within 24 hours, providing regular updates, and rewarding valid reports. We will never take legal action against researchers acting in good faith.

Report a vulnerability