Skip to main content
Security First

Security-First Protection for Your Data

Your trust is our priority. We've built LifeVault Secure with security at every layer, from encryption to infrastructure to operational safeguards.

AES-256-GCM Encryption

Strong authenticated encryption protects your data at rest and in transit. Keys are derived using PBKDF2 with 600,000 iterations.

We use AES-256-GCM, an authenticated encryption standard trusted by governments and financial institutions. GCM mode provides both confidentiality and integrity in a single pass, eliminating the need for a separate HMAC step. Each piece of data gets a unique initialization vector, so identical inputs produce completely different ciphertext. Keys are derived using PBKDF2 with 600,000 iterations, exceeding OWASP recommendations. An Argon2id KDF upgrade is coming soon for even stronger resistance to GPU-based attacks.

Learn more

Client-Side End-to-End Encryption

Your notes, passwords, and structured vault data are encrypted on your device before they ever leave your browser. We never see your plaintext notes, passwords, or your encryption keys. The files you upload are end-to-end encrypted too, just like your notes and passwords; the legal documents we generate for you use server-side AES-256.

With client-side E2EE enabled, your vault password never leaves your device. A data encryption key (DEK) is derived locally using PBKDF2, and your vault contents—the files you upload, your notes, and your passwords—are encrypted in your browser before upload. LifeVault Secure servers store only ciphertext for this client-side-encrypted content, which we cannot decrypt. Each vault has its own independent DEK, so compromising one vault cannot affect others. No recovery is possible if you lose your vault password.

Learn more

Zero-Knowledge Architecture

Only you hold the keys to decrypt your end-to-end encrypted notes, passwords, and structured vault data — we cannot read them. The files you upload are end-to-end encrypted too, just like your notes and passwords; the legal documents we generate for you use server-side AES-256.

LifeVault Secure's client-side E2EE mode is true zero-knowledge for your notes, passwords, and structured vault data: your vault password is used to derive an encryption key on your device, and only the encrypted output is transmitted to our servers. The files you upload are end-to-end encrypted too, just like your notes and passwords; the legal documents we generate for you use server-side AES-256. We store a password verifier (not the password itself) so we can confirm you entered the right password without ever learning it. We plan to open-source our crypto library so you can verify these claims independently.

Learn more

Security Reviews

We use documented security controls and regular reviews to keep improving how we protect customer data.

We use documented security controls, regular reviews, and periodic testing to strengthen security, availability, and confidentiality. We continue to improve our operational practices as the product evolves.

Security Event Logging

Every vault access, policy change, and sharing event is recorded with timestamps and IP addresses for your review.

LifeVault Secure logs security-relevant events including login activity, vault access, file operations, policy triggers, and membership changes. You can review your activity history at any time from your dashboard. Rate limiting protects authentication endpoints, and inactivity timeouts automatically lock your session.

Detailed Audit Logs

Every access attempt and action is logged with timestamps and IP addresses, providing complete transparency and accountability.

Every vault access, file download, policy change, and sharing modification is recorded with timestamps, IP addresses, and user attribution. These records provide a comprehensive activity history for transparency and accountability.

Security Practices

Documented controlsPrivacy-minded designData rights supportSensitive-data safeguardsOperational security practices

Security Questions

What encryption does LifeVault Secure use?

LifeVault Secure uses AES-256-GCM, an authenticated encryption mode that provides both confidentiality and integrity in a single pass. Each piece of data receives a unique initialization vector. Encryption keys are derived using PBKDF2 with 600,000 iterations, with an Argon2id upgrade planned. Each vault has its own independent data encryption key (DEK) derived on your device.

Can LifeVault Secure staff access my data?

Not for content protected with client-side end-to-end encryption. LifeVault applies it to text note bodies, web password secrets, structured vault entries, files uploaded through the web app to client-mode vaults, and files uploaded through the iPhone app to account-key client vaults. Our servers cannot read those encrypted content types. Audio notes are not client-encrypted today. Generated legal documents and operational metadata use server-side AES-256; our servers can read operational metadata needed for sharing, policy schedules, and audit records. If you lose your vault password, we cannot recover your client-side encrypted content.

How does LifeVault Secure approach security and privacy requirements?

We use documented security controls, regular reviews, and privacy-focused product decisions to support common security and data protection expectations. We continue strengthening our processes as the product evolves.

How are my encryption keys protected?

Your vault encryption key is derived locally on your device using PBKDF2 with 600,000 iterations of your vault password. The key never leaves your browser. Each vault uses its own unique data encryption key, so compromising one vault cannot affect others. We store only a password verifier on our servers, never your actual password or derived key.

What happens during a data breach?

Text note bodies, web password secrets, structured vault entries, files uploaded through the web app to client-mode vaults, and files uploaded through the iPhone app to account-key client vaults use client-side end-to-end encryption. Audio notes are not client-encrypted today. Generated legal documents and operational metadata use server-side AES-256 and may be readable by our servers. If we detect a security incident, we investigate, contain it, and communicate with affected users based on the facts of the incident and any applicable obligations.

Security white paper

Read our full technical white paper — a detailed, code-verified description of the encryption architecture, key derivation hierarchy, zero-knowledge design, authentication model, and infrastructure.

Try our free password generator

Generate a cryptographically random password or passphrase in your browser — no account required, nothing transmitted to our servers.

How Does Our Security Compare?

See how LifeVault Secure's security architecture stacks up against other solutions.