Security Policy
Security is our foundation. We don't ask for your trust; we provide the math.
1. Client-Side Encryption
All encryption is performed using the WebCrypto API. We use AES-256-GCM for symmetric encryption and RSA-OAEP 4096-bit for asymmetric operations.
2. Key Derivation
Your Master Password is never sent to the server. We use PBKDF2-SHA256 with 600,000 iterations to derive your Master Key locally. This protects against brute-force attacks.
3. Infrastructure Security
Our servers run on hardened Linux instances. We use Caddy to enforce HTTPS with HSTS and modern TLS protocols. All database and storage services are isolated in private networks.
4. Vulnerability Disclosure
We welcome security researchers. If you find a vulnerability, please report it to security@cryphos.site. We do not currently have a bug bounty program, but we provide public credit.
Audit Logs
All administrative actions are logged and immutable.
Data Isolation
Your vault data is logically separated from all other users.