The security model

What VaultSec protects, how, and where its limits are. Written for people who want to check our work.

  1. The threats we design for

    A forensic extraction of the device, and a partner or family member with the phone in hand. Everything else follows from those two.

  2. The PIN is the key, not a gate

    The master key exists on disk only in sealed form. Unsealing it takes a key derived from your Primary PIN (scrypt) combined with a non-exportable secret held by the phone's security chip (Secure Enclave on iPhone, Keystore/StrongBox on Android). A copy of the phone's storage cannot be brute-forced elsewhere, because the chip's half never leaves it.

  3. Files

    Each item is sealed under its own random key with AES-256-GCM, in authenticated chunks. Deleting an item destroys its key. Thumbnails are sealed the same way, and pictures are decoded in memory, never written out in plain form.

  4. The database

    File records live in an encrypted SQLCipher database whose key is derived from the master key, so it opens only after a successful unlock.

  5. Deniability on disk

    Nothing on disk or in the keychain is named after a vault, and app data is excluded from iCloud and computer backups. The app registers no URL scheme that could be probed.

  6. No network

    VaultSec contains no analytics, crash reporting, advertising or notification services, and makes no network connections of its own.

  7. Known limits

    VaultSec cannot protect files you export and share as ordinary copies, cannot stop someone who watches you type your PIN, and cannot defend a phone that is already compromised by spyware with system-level access.

Report a vulnerability

If you find a security issue, please tell us before anyone else so we can fix it. Write to the address below; we reply within 5 working days and credit you, if you want, once it is fixed. We will not take legal action against good-faith research that respects users' privacy, avoids data destruction and gives us reasonable time to respond.

security@vaultsec.app

In scope: the VaultSec app and this website. Out of scope: denial-of-service, social engineering, and attacks that need an already unlocked, compromised device.

Machine-readable contact: /.well-known/security.txt