Security words, in plain language.
The terms at the heart of how SecureIDsafe protects you, defined without jargon or fine print — so you can make an informed choice about your data.
Zero-knowledge
We see nothing usable.
Your password and encryption keys are created on your device and never sent to us. The data we receive is already scrambled into ciphertext we cannot unscramble. Because we never hold the key, we cannot read your messages, open your files, or hand your data to anyone — even under a legal demand. Think of a safety deposit box where only you have a key: the bank stores the box but cannot open it.
End-to-end encryption
Locked at your end, unlocked only at theirs.
Your content is encrypted the moment it leaves your device and stays encrypted all the way to the person you sent it to. Nobody in between — not the network, not the servers, not the storage provider — can read it. Only the intended recipient's device holds the key. If a server is breached mid-transit, the attacker finds only ciphertext. This is the opposite of most providers, who can decrypt your data on their servers whenever they choose.
Seed phrase
Your personal master key, written on paper.
A list of 24 ordinary words generated by your device that mathematically reconstructs your encryption key. It is the only thing that can bring your data back if you lose your device or forget your password — and it is non-bypassable, meaning no support agent, email reset, or operator override can replace it. Write it on paper, keep it somewhere only you control, and never store it online. If you lose it, no one — including us — can recover your data. That is the guarantee that makes the recovery path yours alone.
Ciphertext
The scrambled version of your data.
Ciphertext is what your files and messages become after encryption — a random-looking string that carries no meaning without the key. SecureIDsafe stores ciphertext only. Even if every server were seized, the contents would remain unreadable to whoever holds them.
AES-256
The lock on the box.
AES-256 is the encryption standard used by banks, militaries, and governments. The '256' refers to the length of the key in bits — so many possible combinations that no computer, now or in the foreseeable future, could guess it by brute force. It is the strongest widely-adopted encryption available.
Key custody
Who actually holds the key.
Custody is about who can unlock your data. With most providers, custody is shared — they hold a copy of your key and can use it. With SecureIDsafe, custody is yours alone: the key is derived on your device and never leaves it.
Non-bypassable recovery
No back door, on purpose.
Recovery is non-bypassable when there is genuinely no alternative path back into your account. No 'forgot password' email, no SMS code, no customer-service override — only your seed phrase. This protects you from social engineering, stolen phones, and court orders, at the cost of personal responsibility for your seed.
Geo-redundant backup
Your data, copied across safe places.
Geo-redundancy means encrypted copies of your data are stored in more than one physical location. If one data center fails or is destroyed, your data survives — still encrypted, still yours. Crucially, these are backups of ciphertext, never of keys.
ECDH key exchange
How two devices agree on a secret in public.
Elliptic-Curve Diffie-Hellman is the method two devices use to agree on a shared secret key over an open channel — without ever sending the key itself. Even someone recording every byte of the conversation cannot derive the key. It is how end-to-end encrypted messages get their lock without exposing it.
Why we publish this openly
Security only works when you can verify it. By defining these terms plainly and in advance, we hold ourselves to the same standard we promise: zero-knowledge custody, end-to-end encryption, and a recovery path that belongs to you and no one else. If a provider cannot explain their security in plain language, that is usually the warning.
