Security
Security you can verify. Not just believe.
Keystone is only as good as its honesty. Here is exactly how we protect your information — and what we have deliberately made impossible, even for ourselves.
Three layers
The closer to the core, the fewer hold the key.
-
Layer 1 of 3
In transit
All traffic between your device and Keystone is encrypted with TLS.
Standard protection — like your online bank.
-
Layer 2 of 3
At rest
All your data in Keystone is encrypted in the database with AES-256-GCM, field by field. A copy of the database is unreadable without the keys, which are stored separately.
Keystone holds this key — which is why search works, and why your account can be recovered.
-
Layer 3 of 3
Sealed
Passwords, PINs and recovery codes are encrypted in your browser with a sealing passphrase you choose — before they are ever sent to us. The server stores only ciphertext.
Only you hold this key. We cannot read these fields — no matter who asks.
Sealed secrets
"We can't read them" has to mean something.
Many services promise not to look. We built it so we can't: sealing happens with WebCrypto in your own browser, and neither your sealing passphrase nor the raw key ever leaves your device.
When you set up sealing, you print a recovery kit: a 26-character code with a QR, stored with your will or handed to your executor. If you forget the passphrase, the kit restores access — and after a release, it's the kit that lets your contacts open what was sealed.
What we cannot recover — by design
If you lose both your sealing passphrase and your recovery kit, the sealed fields are gone. We cannot undo that — and that is precisely why no one else can read them. Everything else in your account recovers normally: your regular password is reset via email.
Where your data lives
In the EU. In Frankfurt. Full stop.
Keystone runs from Frankfurt: application, database and documents all live in the EU. We show no ads, sell no data and use no tracking cookies.
| Vendor | Role | Region |
|---|---|---|
| Fly.io | Application hosting | EU (Frankfurt) |
| Neon | Database | EU (Frankfurt) |
| Cloudflare R2 | Document storage | EU / Global (data residency configurable) |
| Stripe | Payments | EU/US · data-processing agreement |
| Postmark | Transactional email | EU/US · data-processing agreement |
The full data-processor register with agreements will be published here before launch.
Control
Security you can feel day to day
Tamper-proof audit log
Every access, download and change is written to a log that technically cannot be edited or deleted. You are notified when someone views what you've shared.
Two-factor sign-in
Protect the account with an authenticator app and one-time recovery codes. Sensitive actions — like cancelling a release — always require an extra confirmation.
A release with a brake
Access after a death requires documentation, manual verification and a 72-hour waiting period during which you can cancel. No single person can open your Keystone with one click.
Your data is yours
Full export at any time in open formats — including an offline reader for the sealed fields, so your data is never trapped with us.
Found a vulnerability?
Write to [email protected] — we respond quickly and take findings seriously. A formal disclosure policy and security.txt will follow before launch.