Security

Built so even we can't open it.

No master keys held in reserve. No secret way to decrypt your data. The architecture itself is the promise — here's exactly how it works.

Argon2idMemory-hard key derivation
AES-256-GCMOn-device vault encryption
3-of-5Shamir threshold recovery

How it works.

In one paragraph: your passphrase goes through Argon2id to derive a key that encrypts your vault with AES-256-GCM, on your device. The ciphertext is what we store. The key never leaves you. To recover for your family, we split that key into five sealed pieces — three of them, plus a 14-day hold, are needed to put it back together.

LayerChoiceWhy
Key derivationArgon2id (RFC 9106), 64 MiB, 3 iterationsBest-in-class against GPU brute-force; OWASP recommended
Symmetric cipherAES-256-GCMAuthenticated; standard; constant-time on modern hardware
Key splittingShamir's Secret Sharing (3-of-5)Each holder learns nothing alone; any three reconstruct
Holder envelopeCurve25519 NaCl box (X25519 + XSalsa20-Poly1305)Each share is sealed to a holder's individual key
Recovery phraseBIP39 24-wordIndustry-standard; word lists are public; can be written on paper
TransportTLS 1.3 onlyNo legacy ciphers, no opt-out

The release engine, in detail.

  1. You pick five trusted humans when you set up. They each install Lyfos and verify their key holder identity.
  2. Your vault key is split into five pieces. Each piece is sealed to one holder's individual public key. No piece alone reveals anything about the key.
  3. If you die, your nominee opens a claim with a death certificate. Our team reviews it manually. Once approved, three of your holders are asked to release their share.
  4. The moment three shares arrive, a 14-day owner-protection hold begins. You receive alerts every day, on email, SMS, WhatsApp, and push notification. One tap aborts everything.
  5. If the hold expires without abort, your nominee can finally combine the three shares on their device and decrypt the emergency bundle. The vault stays sealed if anything breaks the chain.

What we cannot do.

Audits & trust artefacts.

ArtefactStatus
Independent security auditPre-launch. Report + remediation will be published.
Cryptographic protocol review (academic)Engaged.
Threat modelPublic
Responsible disclosure policyPublished
Bug bountyUp to ₹3,00,000 per finding
Cyber liability insuranceIn procurement. Aggregate target ₹5-7 crore.
DPDPA grievance officergrievance@lyfos.signorvale.com
Sub-processor listPublic
Status pagelyfos.signorvale.com/status

Report a vulnerability.

Email security@lyfos.signorvale.com with details. PGP key at /.well-known/pgp-key.txt. First response within 4 hours for critical findings.