Aegis

How Aegis protects you

Professionals state their limits. Amateurs claim perfection. Here is the honest version.

What we store

Your email address, the date you joined, which household you belong to, an append-only audit log, and, for every vault item, ciphertext plus the category. That is all.

What is encrypted in your browser

Item titles, item bodies and uploaded files are encrypted with AES-256-GCM before they leave your device. The key is derived from your passphrase using PBKDF2 with 600,000 iterations.

Where the keys live

Your passphrase is never sent to us. It unwraps a random master key that exists only in your browser's memory while you are unlocked. Close the tab and it is gone. We never see either one.

What we can, and cannot, see

DataEncrypted in browser?Can we read it?
Email addressNoYes, to send sign-in codes
Account created dateNoYes
Vault item titleYesNo
Vault item bodyYesNo
Vault item categoryNoYes, for filtering
Uploaded filesYesNo
Which household you are inNoYes
Audit logNoYes, it is our security record

So yes, we can see you have 47 items in "Insurance". We cannot see what any of them say. That metadata is a real, unavoidable leak, and we will not pretend otherwise.

If you lose your passphrase

Then your data is gone, permanently. No reset link, no way for us to recover it. That is exactly what makes it private. Recovery codes and passkeys make it survivable, but the trade-off is real.

A trade-off we chose on purpose

We lock accounts on the email address, not the IP, after repeated failed sign-ins. An attacker cannot bypass the lock by changing IP. It also means someone could deliberately fail sign-ins to lock a real person out for a while. We accept that cost because locking on IP protects nobody.