Encryption in detail: IDs, tokens and ciphertext
Three different things keep your content safe in the vault, and they are easy to mix up. Block IDs and tokens are labels the AI works with, and they carry no content. The ciphertext is where the real content lives, and only your browser can open it. This page follows one sentence through the whole process.
One sentence, start to finish
Say your document contains this paragraph, and you listed "Acme Corp" as a client term:
Acme Corp renewed at $2.4M, up 18% on last year.The real paragraph. It is block P3 of the document.
P3: [CLIENT_1] renewed at [MONEY_1], up [PCT_1] on last year.The block ID and the masked text, in the manifest you approved.
<s-text ref="P3"> or [CLIENT_1] is our largest renewalThe AI points at block P3, or writes a sentence using tokens. It places both without knowing what they stand for.
Acme Corp renewed at $2.4M, up 18% on last year.Your browser decrypts the document, swaps every ID and token for its real value, and writes the .pptx on your machine.
Block IDs: how the AI points at your content
- When a document is read, your browser splits it into blocks and numbers them in reading order by type: H1, H2 for headings, P1, P2 for paragraphs, L1 for lists, T1 for tables, N1 for numbers and I1 for images.
- An ID is only a type letter and a counter. It is not derived from the content, so it can't be reversed into it.
- The AI writes
ref="P3"in a slide. The real paragraph is looked up in your browser at export time. The AI never receives it. - The manifest describes each block only by its shape: type, length, number of table rows and columns, column types (text, number, currency, percent, date) and trends (rising, falling, flat, mixed). Images are described only as landscape, portrait or square.
- Several documents in one deck: the first keeps plain IDs, and the second to fifth get a letter, such as B.P3 and [B_CLIENT_1], so IDs and tokens from different documents never collide.
Tokens: how Masked mode hides values
- In Masked mode your browser finds the sensitive spans: emails, links, phone numbers, amounts, percentages, dates, codes, numbers, names and companies, plus your own list of terms.
- Each one becomes a token with a type and a counter, in order of first appearance: [CLIENT_1], [MONEY_1], [MONEY_2]. The same value always gets the same token within a document, so the AI can write "[CLIENT_1] grew" in two places and both come back correct.
- A token is a counter, not a hash or an encryption of the value. There is nothing in it to crack, because the value isn't in it.
- The table that says which token is which value is part of the encrypted document. It never exists on our servers in readable form.
- Masking errs toward hiding too much. The review screen shows you exactly what the AI will get, and you decide whether to reveal anything.
- In Blind mode there is no text at all, so there are no tokens. The AI sees only IDs and shapes.
The ciphertext: what is actually uploaded
Everything real about a document (every block of text, every table cell, any images, the token table and its name inside the file) is serialised into one JSON object in your browser and encrypted as a single unit. This is the layout of the uploaded file:
- AES-256-GCM is a standard authenticated cipher. Without the key the bytes look like random noise, and the same document encrypted twice gives different bytes because the IV differs.
- Tamper detection: the authentication tag means that if anyone alters even one byte on our servers, decryption fails instead of returning altered content.
- Built-in browser cryptography: all of this uses your browser's own Web Crypto API. We don't ship a home-made cipher.
- One file per document. Deleting a document deletes its file, so there is no shared blob to untangle.
The keys: who unlocks the ciphertext
256 random bits made in your browser. It encrypts every document you add.
Your passphrase plus a random 16-byte salt go through PBKDF2-SHA256 for 600,000 rounds. The result encrypts one copy of the vault key.
A second random 256-bit key, shown once as a downloadable code, encrypts another copy of the vault key.
- The server stores the two locked copies, the salt and the round count. It never stores the vault key, your passphrase or your recovery key.
- Changing your passphrase locks a new copy of the same vault key. Your documents are not re-encrypted, and your recovery key keeps working.
- While you work, the unlocked vault key is held in that tab's memory only. It is not saved anywhere, so closing or reloading the tab locks the vault.
Export: where each step runs
- The AI finishes the deck. Our server holds a skeleton: the layout, with IDs and tokens in place of your content.
- You open the fill page on our site and unlock the vault with your passphrase. This happens in your browser.
- Your browser downloads the skeleton and the encrypted file or files.
- It decrypts them in memory, then swaps every token and block reference for its real value.
- It fits the text to the slides and writes the .pptx. The finished file is created on your machine and is not uploaded.
The fill step runs on our domain, never inside a chat window, so the AI app can't see the page or the result.
What the server can still see
To keep this page honest, here is everything about a vault document that is readable by the server, and so by anyone with administrator access to it:
- The manifest you approved: IDs, shapes, and in Masked mode the masked text.
- The document's name. It is stored readable and shown to the AI so it knows which document is which. You can rename it before upload, so don't put anything sensitive in it.
- Its mode (Blind or Masked), its approximate size, how many blocks it has, and when it was added.
The manifest format is strict: the server rejects any field it doesn't recognise, and a Blind manifest that carries text is refused outright. That is a safety net on top of the checks in your browser.
Questions? shoumikgoswami@gmail.com · Privacy model · Data storage · Privacy