Deppie Vault Experimental · review pending

Local encrypted workspace

Vaults

Protected names and item fields appear only after this device verifies its certificate and unlocks a current key envelope.

Current teamServer metadata only
Locked
Encrypted vaultObject count and epoch withheld until unlock
Encrypted vaultNames unavailable while locked

Local key required

Contents remain sealed

The server can return ciphertext and public certificates, but this browser will not show protected fields until every trust check passes.

  • Device certificate matches the pinned account identity
  • Membership digest and signature verify locally
  • Checkpoint history has not moved backward or forked

Device trust

Enroll this browser

Keys stay in memory

1. Create a local request

Generate independent signing and encryption keys, then compare the authentication string on an already trusted device.

No enrollment request exists in this tab.

Recovery

No operator backdoor

Recovery requires your high-entropy recovery key plus Core account recovery and step-up. Losing every trusted device and the recovery key permanently loses the vault.

Not configured

DV1 acceptance evidence

Two-device lifecycle drill

Exercise sharing, offline ciphertext, conflict rejection, key rotation, revocation, recovery, and encrypted export without sending protected values to the server.

Two-device share

HPKE wraps one vault key to each device.

Not run

Offline change

IndexedDB receives ciphertext envelopes only.

Not run

Conflict

A stale optimistic revision fails closed.

Not run

Rotation

A fresh vault key advances the epoch.

Not run

Revocation

The removed device cannot open future data.

Not run

Recovery

A context-bound recovery key restores client material.

Not run

Export

The portable archive remains encrypted.

Not run