How your vault is stored, and why we can't read it
When you add a document to the vault, your browser locks it before it leaves your computer. What we keep is a locked file and a locked key. The only things that open them are your passphrase and the recovery key you downloaded, and we never receive either one.
Exactly what is stored
The real values only exist in readable form in your browser. See how IDs, tokens and the ciphertext fit together. When you export, your browser decrypts the document, puts the values back and writes the .pptx on your machine.
Who holds the keys
Only you. Your vault key is made in your browser and is stored on our servers only in locked form: once under your passphrase and once under the recovery key you download. We never receive the passphrase, the recovery key or the unlocked key, and the unlocked key lives only in the memory of the tab where you entered your passphrase. See how the keys, IDs and ciphertext work.
How it is protected
- Hosting: OpenGamma runs on a private server in Oracle Cloud Infrastructure. Access is limited to the operator by key-based login, and the data is not shared with anyone else.
- In transit: everything travels over TLS.
- At rest: each encrypted document is its own file under your account's folder. The database holds your locked key and the manifests you approved. Oracle also encrypts the server's disks (AES-256), which protects against someone removing a disk, but not against someone logged in to the machine.
- Backups: taken nightly to a private Oracle storage bucket, encrypted again before they leave the server, and kept for 30 days. They contain only what is listed above, so a backup holds no more than the live system does.
- Separation: every request is checked against your account, so one user's vault can't be listed or downloaded by another.
- Leak tests: our automated tests plant secret values in a vault, then search the database, file storage, logs and every response the AI receives. They run on every release.
- Limits: up to 20 documents and 500 MB per vault.
Can someone with access to the server read your files?
No. Your documents are encrypted in your browser before they reach the server, so what sits on the disk is already ciphertext. That is true for us, for anyone with administrator access to the server or the Oracle account, and for anyone who got hold of a disk or a backup. Without your passphrase or recovery key, which are never on the server, the files are unreadable.
Someone with that access could read the AI's approved version of each document (placeholders, or lengths and shapes), your account details, and your decks' layouts. They couldn't read the real values in your vault documents.
Deleting
Delete a document in the vault and its encrypted file and its AI version are removed from our live systems right away. Delete your account and everything you stored goes with it, including vault documents and your locked key. Backups drop it within 30 days, as the Privacy Policy says. We hold no readable copy, so deleted data can't be recovered by anyone.
What this doesn't protect against
- Losing both your passphrase and your recovery key. Nobody, including us, can recover the data.
- A weak passphrase. The encryption is only as hard to break as your passphrase is to guess.
- A compromised computer. Malware or a malicious browser extension on your machine can see what your browser sees.
- Our own website being tampered with. The encryption code is delivered by our site, so an attacker who changed the site could in principle capture your passphrase. A strict Content Security Policy limits that risk, but a vault that runs in a web page can't remove it completely.
- What you approve for the AI. In Masked mode the AI reads your text with identifying details hidden. Use Blind mode when even that is too much, and always check the review screen.
- Anything you paste straight into a chat. That is outside the vault.
We haven't had an independent audit yet, so we don't call the vault "zero-knowledge". We plan to commission one.
Questions about storage or security? shoumikgoswami@gmail.com · Privacy model · Terms · Privacy