Security architecture

How Valtira protects your vault

A plain-language overview of the design. The complete technical specification is part of the Valtira repository (CRYPTO_ARCHITECTURE.md and THREAT_MODEL.md).

  1. Your master password

    Typed on your device. Never stored, never sent.

  2. Key derivation

    Argon2id with 64 MiB of memory makes every guess expensive.

  3. Your vault key

    A random 256-bit key, unlocked only with your master password or recovery key.

  4. Encrypted vault

    Every item is sealed with AES-256-GCM and bound to its identity.

  5. Only your devices decrypt it

    Our servers store ciphertext they cannot read.

What our servers see
AQHx9…c7Qe AQF2m…9kLr AQG8s…Tz3w

Encrypted blobs, item counts and timestamps — never names, URLs, usernames or passwords.

01

Keys, not passwords, protect your data

Your master password is normalised and fed into Argon2id (64 MiB memory, 3 passes, random 16-byte salt) on your device. From the result, HKDF-SHA-256 derives two independent keys: one that unlocks your vault key, and one that proves your identity to the sync server. The server can never turn the second into the first.

02

A random vault key encrypts everything

Your vault key is 256 bits from the operating system’s random number generator. Each item — including its name, URLs, tags and history — is encrypted with AES-256-GCM, a fresh random nonce and additional data that binds the ciphertext to the item. Swapped or modified ciphertexts are rejected. Items are padded so their exact length is hidden.

03

Keys that can’t be copied out of the browser

Once unlocked, the vault key lives as a non-extractable WebCrypto key. Page scripts can use it while the vault is open, but cannot read its bytes. When you lock, the key and all decrypted data are dropped.

04

Zero-knowledge sync

Sync moves only ciphertext. The server authenticates you with a derived proof it stores as a keyed hash, enforces row-level security for every request, and never sees names, URLs or passwords. Devices reject older versions of items (rollback protection) and never accept key-derivation settings weaker than the built-in minimum.

05

Recovery without a backdoor

During setup you get a 256-bit recovery key. It unlocks a second, separately wrapped copy of your vault key. Kunz Systems has no admin key and no way to reset your master password.

06

Biometric unlock the secure way

Biometric unlock uses passkeys with the WebAuthn PRF extension. The authenticator releases a secret only after user verification; it unlocks a device-bound copy of your vault key. Without secure support, the option is simply not offered.

07

A hardened web app

Strict Content Security Policy with Trusted Types, no third-party scripts, no analytics, HSTS, isolated origins for the app and this website, and automatic locking after inactivity.

!

Honest limits

No system is unbreakable. A compromised device or browser extension can read what you see on screen. Someone who steals encrypted data can try to guess a weak master password — which is why Valtira asks for a strong one. Web apps rely on the code delivered to your browser. We document these limits instead of hiding them.

@

Found a vulnerability?

Please report it privately to contact@kunzsystems.com. We respond quickly and credit researchers who want to be named.