OpenGamma

Security / Storage

How your vault is stored, and why we can't read it

When you add a document to the vault, your browser locks it before it leaves your computer. What we keep is a locked file and a locked key. The only things that open them are your passphrase and the recovery key you downloaded, and we never receive either one.

What a document goes through

  1. Read. Your browser reads the file and splits it into blocks: headings, paragraphs, lists, tables, numbers and images. Nothing is uploaded yet.
  2. Split in two. Your browser keeps the full document (every real value) and, separately, builds the version the AI is allowed to see: placeholders in Masked mode, or structure only in Blind mode.
  3. Review. You see the AI's version block by block. Until you approve it, it isn't shared with the AI.
  4. Lock. The full document is encrypted with AES-256-GCM using a random 256-bit vault key that is generated in your browser.
  5. Upload. Only the encrypted file and the approved AI version reach our server.

Who holds what

Your browser

  • The real document
  • The unlocked vault key, in this tab's memory only
  • Your passphrase, while you type it
locked
→

OpenGamma servers

  • The encrypted document (unreadable)
  • Your vault key, locked twice (unreadable)
  • The AI's approved version
approved
version
→

Your AI app

  • Placeholders such as [CLIENT_1]
  • Never the real values

Exactly what is stored

ItemForm on our serversCan we read it?
Your documentsOne AES-256-GCM encrypted file each, with a fresh random IV per fileNo
Masking table (which token stands for which real value)Inside the encrypted file, never stored separatelyNo
Your vault keyStored only wrapped: once under a key from your passphrase, once under your recovery keyNo
Your passphrase and recovery keyNever sent to usWe don't have them
The AI's version of each document (the manifest)Stored as readable text, because the AI is meant to read it. It holds only what you approved: placeholders, or lengths, table shapes and trendsYes, by design
Skeleton decksLayouts with filler text, built from the AI's versionYes, no real values in them

The real values only exist in readable form in your browser. When you export, your browser decrypts the document, puts the values back and writes the .pptx on your machine.

The keys

  • Vault key. 256 random bits that encrypt your documents. It is created in your browser.
  • Your passphrase (at least 12 characters) is stretched into a key with PBKDF2-SHA256 and 600,000 rounds, which makes guessing slow. That key encrypts one copy of your vault key. Our server also refuses any setup that uses fewer than 310,000 rounds.
  • Your recovery key is a second random key, shown once for you to download. It encrypts a second copy of the vault key, so you can get back in if you forget your passphrase.
  • The unlocked key stays in the memory of the browser tab where you entered your passphrase. It is never written to disk, localStorage or IndexedDB. Close or reload the tab and the vault locks.

How it is protected

  • Hosting: OpenGamma runs on a private server in Oracle Cloud Infrastructure. Access is limited to the operator by key-based login, and the data is not shared with anyone else.
  • In transit: everything travels over TLS.
  • At rest: each encrypted document is its own file under your account's folder. The database holds your locked key and the manifests you approved. Oracle also encrypts the server's disks (AES-256), which protects against someone removing a disk, but not against someone logged in to the machine.
  • Backups: taken nightly to a private Oracle storage bucket, encrypted again before they leave the server, and kept for 30 days. They contain only what is listed above, so a backup holds no more than the live system does.
  • Separation: every request is checked against your account, so one user's vault can't be listed or downloaded by another.
  • Leak tests: our automated tests plant secret values in a vault, then search the database, file storage, logs and every response the AI receives. They run on every release.
  • Limits: up to 20 documents and 500 MB per vault.

Can someone with access to the server read your files?

No. Your documents are encrypted in your browser before they reach the server, so what sits on the disk is already ciphertext. That is true for us, for anyone with administrator access to the server or the Oracle account, and for anyone who got hold of a disk or a backup. Without your passphrase or recovery key, which are never on the server, the files are unreadable.

Someone with that access could read the AI's approved version of each document (placeholders, or lengths and shapes), your account details, and your decks' layouts. They couldn't read the real values in your vault documents.

Deleting

Delete a document in the vault and its encrypted file and its AI version are removed from our live systems right away. Delete your account and everything you stored goes with it, including vault documents and your locked key. Backups drop it within 30 days, as the Privacy Policy says. We hold no readable copy, so deleted data can't be recovered by anyone.

What this doesn't protect against

  • Losing both your passphrase and your recovery key. Nobody, including us, can recover the data.
  • A weak passphrase. The encryption is only as hard to break as your passphrase is to guess.
  • A compromised computer. Malware or a malicious browser extension on your machine can see what your browser sees.
  • Our own website being tampered with. The encryption code is delivered by our site, so an attacker who changed the site could in principle capture your passphrase. A strict Content Security Policy limits that risk, but a vault that runs in a web page can't remove it completely.
  • What you approve for the AI. In Masked mode the AI reads your text with identifying details hidden. Use Blind mode when even that is too much, and always check the review screen.
  • Anything you paste straight into a chat. That is outside the vault.

We haven't had an independent audit yet, so we don't call the vault "zero-knowledge". We plan to commission one.

Questions about storage or security? shoumikgoswami@gmail.com · Security model · Terms · Privacy