Security model

Protection begins
before storage.

VerityVault combines client-side encryption, controlled access, secure transport, and account protections so sensitive information remains useful without becoming casually readable.

Security boundary

What leaves your device is already encrypted

Your device

Plaintext becomes encrypted content

You can read

In transit

Protected while moving to storage

Encrypted

Stored vault

Retained as encrypted information

Unreadable

Security is a chain, not a badge

No single control carries the whole system. Each layer reduces what an attacker, or the service itself, can learn or do.

Encryption keys stay essential

Vault content is protected with keys derived through the user's secure access flow.

Zero-knowledge architecture

The service is designed so stored vault content cannot be casually read by VerityVault.

Account verification

Email verification and optional two-factor authentication strengthen account access.

Layered infrastructure

Application controls, secure transport, database protection, and monitoring work together.

What VerityVault can and cannot see.

Transparency matters more than vague security language. Account operations require some service data; protected vault content is treated differently.

InformationService visibility
Account email and profile settingsRequired for account
Subscription and plan statusRequired for billing
Encrypted vault payloadsCannot be read as plaintext
Your master passphraseNot stored as plaintext
Sharing permissions and delivery stateUsed to enforce access

Controls you can use

Strong architecture works best when everyday account behavior supports it.

Use a unique account password

Keep it separate from passwords used on other services and store it in a trusted password manager.

Protect your recovery material

Keep your recovery passphrase offline in a place only you, or a carefully chosen person, can reach.

Review shared access

Remove access when a relationship, responsibility, or practical need changes.

Security questions deserve specific answers.

If you are evaluating VerityVault for sensitive personal or family information, ask us about the architecture, access model, or data handling that matters to you.

Ask a security question

Build continuity without giving up privacy.

Keep the record useful to you and unreadable to everyone you have not chosen.

Start your vault