Security Policy

Security is our foundation. We don't ask for your trust; we provide the math.

1. Client-Side Encryption

All encryption is performed using the WebCrypto API. We use AES-256-GCM for symmetric encryption and RSA-OAEP 4096-bit for asymmetric operations.

2. Key Derivation

Your Master Password is never sent to the server. We use PBKDF2-SHA256 with 600,000 iterations to derive your Master Key locally. This protects against brute-force attacks.

3. Infrastructure Security

Our servers run on hardened Linux instances. We use Caddy to enforce HTTPS with HSTS and modern TLS protocols. All database and storage services are isolated in private networks.

4. Vulnerability Disclosure

We welcome security researchers. If you find a vulnerability, please report it to security@cryphos.site. We do not currently have a bug bounty program, but we provide public credit.

Audit Logs

All administrative actions are logged and immutable.

Data Isolation

Your vault data is logically separated from all other users.