Functional security commitments
A clear account of intended protections, limits, and validation still required before release.
Important limits
- End-to-end encryption cannot protect an unlocked device already controlled by malware.
- If you forget the account password with no unlocked device or optional recovery kit, support cannot recover the old vault.
- Time-based codes can still be stolen by real-time phishing.
No independent security audit has been completed. A review remains required before production claims.