Local encrypted workspace
Vaults
Protected names and item fields appear only after this device verifies its certificate and unlocks a current key envelope.
Local key required
Contents remain sealed
The server can return ciphertext and public certificates, but this browser will not show protected fields until every trust check passes.
- Device certificate matches the pinned account identity
- Membership digest and signature verify locally
- Checkpoint history has not moved backward or forked
Device trust
Enroll this browser
1. Create a local request
Generate independent signing and encryption keys, then compare the authentication string on an already trusted device.
No enrollment request exists in this tab.
Recovery
No operator backdoor
Recovery requires your high-entropy recovery key plus Core account recovery and step-up. Losing every trusted device and the recovery key permanently loses the vault.
Not configuredDV1 acceptance evidence
Two-device lifecycle drill
Exercise sharing, offline ciphertext, conflict rejection, key rotation, revocation, recovery, and encrypted export without sending protected values to the server.
Two-device share
HPKE wraps one vault key to each device.
Offline change
IndexedDB receives ciphertext envelopes only.
Conflict
A stale optimistic revision fails closed.
Rotation
A fresh vault key advances the epoch.
Revocation
The removed device cannot open future data.
Recovery
A context-bound recovery key restores client material.
Export
The portable archive remains encrypted.