Security
- Vault, private clipboard, private secret shares, and scratch-pad note bodies are encrypted in the browser (Argon2id + AES-256-GCM) before upload. Note titles stay visible in the list.
- The server stores ciphertext only for those secrets. It cannot read your passwords.
- Voice notes are labelled: AWS Transcribe processes the audio, then DeskVane encrypts the transcript. Audio is not kept.
- Tab sessions are plaintext URLs/titles so you can restore windows without unlocking.
- Secret share links store plaintext so anyone with the URL can open them. Private secret shares stay encrypted with no link.
- Two-step verification is optional for the first week, we remind you in the second week, then we require it. Prefer a passkey (Face ID, Touch ID, Windows Hello, or a security key). Authenticator apps and email codes are also available. New devices are confirmed by email. Operator accounts must use a passkey or authenticator.
- After the first password unlock, you can let that passkey reopen the vault after a timeout. The server stores only ciphertext. The Chrome extension still needs a DeskVane tab for Face ID because Chrome will not run the passkey on the popup.
- Save your recovery key offline. Account password reset does not decrypt the vault — use the recovery key, then re-wrap.
- Operator access to AWS, Stripe, and Postmark uses MFA. The operator console requires authenticator MFA.