The security model
What VaultSec protects, how, and where its limits are. Written for people who want to check our work.
What VaultSec protects, how, and where its limits are. Written for people who want to check our work.
A forensic extraction of the device, and a partner or family member with the phone in hand. Everything else follows from those two.
The master key exists on disk only in sealed form. Unsealing it takes a key derived from your Primary PIN (scrypt) combined with a non-exportable secret held by the phone's security chip (Secure Enclave on iPhone, Keystore/StrongBox on Android). A copy of the phone's storage cannot be brute-forced elsewhere, because the chip's half never leaves it.
Each item is sealed under its own random key with AES-256-GCM, in authenticated chunks. Deleting an item destroys its key. Thumbnails are sealed the same way, and pictures are decoded in memory, never written out in plain form.
File records live in an encrypted SQLCipher database whose key is derived from the master key, so it opens only after a successful unlock.
Nothing on disk or in the keychain is named after a vault, and app data is excluded from iCloud and computer backups. The app registers no URL scheme that could be probed.
VaultSec contains no analytics, crash reporting, advertising or notification services, and makes no network connections of its own.
VaultSec cannot protect files you export and share as ordinary copies, cannot stop someone who watches you type your PIN, and cannot defend a phone that is already compromised by spyware with system-level access.
If you find a security issue, please tell us before anyone else so we can fix it. Write to the address below; we reply within 5 working days and credit you, if you want, once it is fixed. We will not take legal action against good-faith research that respects users' privacy, avoids data destruction and gives us reasonable time to respond.
In scope: the VaultSec app and this website. Out of scope: denial-of-service, social engineering, and attacks that need an already unlocked, compromised device.