Built so we can’t read it.
How SealedLight will protect your vault at launch.
Can SealedLight read my vault?
No. Your vault will be encrypted on your device, and SealedLight will not hold the keys needed to read it.
Encrypted on your device
At launch, AES-256-GCM encryption happens on your device before anything is uploaded.
Zero knowledge
SealedLight will not hold the keys needed to read your content.
Strong sign-in
Passkeys or biometrics, plus an app lock on your device.
A recovery key
A recovery key that only you hold. If it is lost, we may be unable to help.
Independent review
Independent audits, penetration tests and a responsible disclosure route. We’ll publish the results of an independent security audit before the vault opens.
Optional fingerprint
An optional blockchain fingerprint proves a file was not changed. Never the content itself.
Why is one key never enough?
Opening a vault will need two things at once, so no single person or system can open it alone.