How Aegis protects you
Professionals state their limits. Amateurs claim perfection. Here is the honest version.
What we store
Your email address, the date you joined, which household you belong to, an append-only audit log, and, for every vault item, ciphertext plus the category. That is all.
What is encrypted in your browser
Item titles, item bodies and uploaded files are encrypted with AES-256-GCM before they leave your device. The key is derived from your passphrase using PBKDF2 with 600,000 iterations.
Where the keys live
Your passphrase is never sent to us. It unwraps a random master key that exists only in your browser's memory while you are unlocked. Close the tab and it is gone. We never see either one.
What we can, and cannot, see
| Data | Encrypted in browser? | Can we read it? |
|---|---|---|
| Email address | No | Yes, to send sign-in codes |
| Account created date | No | Yes |
| Vault item title | Yes | No |
| Vault item body | Yes | No |
| Vault item category | No | Yes, for filtering |
| Uploaded files | Yes | No |
| Which household you are in | No | Yes |
| Audit log | No | Yes, it is our security record |
So yes, we can see you have 47 items in "Insurance". We cannot see what any of them say. That metadata is a real, unavoidable leak, and we will not pretend otherwise.
If you lose your passphrase
Then your data is gone, permanently. No reset link, no way for us to recover it. That is exactly what makes it private. Recovery codes and passkeys make it survivable, but the trade-off is real.
A trade-off we chose on purpose
We lock accounts on the email address, not the IP, after repeated failed sign-ins. An attacker cannot bypass the lock by changing IP. It also means someone could deliberately fail sign-ins to lock a real person out for a while. We accept that cost because locking on IP protects nobody.