Security
Zero-knowledge encryption
The profile key is created on your computer. It encrypts cookies and tabs, the proxy password and 2FA keys before anything is sent. Only ciphertext reaches the server: it stores your data but can’t read it.
The server stores, but can’t read
Your account password is turned into a key via Argon2id, and that key locks the master key. The master key wraps the keys of all profiles. The profile key (XChaCha20-Poly1305) encrypts the browser data archive and secrets.
- Keys are created on your computer
- Your password never leaves your computer
- The team key is shared through members’ public keys
Profile password and recovery
A separate profile password is a second layer on top of the account. A forgotten account password is recovered by Support with an offline key that isn’t and never was on the server.
- A password-protected profile won’t open without it
- Offline recovery key kept off the server
- Profiles stay in place after recovery
FAQ
What does the server see?
Only ciphertext. The profile key is created locally and sent wrapped in the account key, which is locked with your password via Argon2id. The server can’t decrypt your data.
What if I forget my account password?
The server can’t decrypt your data. Support restores access with an offline key that isn’t on the server. After recovery you set a new password, and your profiles stay in place.
What is a profile password?
An extra layer on top of account encryption: such a profile won’t open, even from your own account, until the password is entered.
See also
Install it and create your first profile
Three profiles free, no card required.
Download for macOSApple Silicon · signed and notarized by Apple · automatic updates