Aelyna® Keys, home page

Security, explained simply

Aelyna® Keys is built on one principle: only you can open your vault. Here is how it works, and where the limits are.

Three keys for one vault

Your passwords are locked in an encrypted vault. To open it the app combines up to three things: without any one of those required, the content stays unreadable.

  1. Always

    Master password

    Something you know. Never stored, never sent.

  2. Always

    Secret Key

    A random code on your computer and on your printed Emergency Kit. Never in backups.

  3. Optional

    Hardware key

    A FIDO2 key you touch, protected by its PIN.

Together they form the vault key, which in turn opens a different key for every item. Everything is encrypted: passwords and notes, but also titles and website names.

Behind the scenes

  • Encrypted on the device

    Every item is encrypted with XChaCha20-Poly1305, a modern, well-studied algorithm, before it touches the disk.

  • Slow to guess

    The key is derived from your master password with Argon2id, which needs a lot of memory and time per attempt: trying millions of passwords becomes very expensive.

  • 128-bit Secret Key

    Even with a weak password, someone who steals the file would have to try more combinations than any existing computer can.

  • No home-made cryptography

    Only standard algorithms from well-known libraries, checked against official test vectors.

  • Tamper-evident file

    If someone modifies, swaps or rolls back the file, the app notices and will not open it without asking you.

  • Automatic lock

    On inactivity, sleep and screen lock: locking wipes the keys from memory.

  • Clipboard and screen

    The clipboard clears itself; on Windows passwords stay out of the history. The window can be kept out of screen captures.

What happens if…

SituationWhat Aelyna protects
Your laptop is stolen while offEverything is encrypted: nothing can be read without the master password.
Someone copies the vault file or a backupWithout the master password and the Secret Key the file is useless.
A program reads the clipboardThe clipboard clears itself; on Windows passwords stay out of the history (Win+V) and cloud sync.
You share your screen in a meetingThe window can be excluded from screen capture; passwords stay hidden until you press Show.
Malware steals the file, Secret Key and passwordWith the hardware key on, the stolen copy stays locked without the physical key.

What we cannot protect

We say this in the app too, because trust means knowing where the boundaries are.

  • An infected computer while the vault is open

    Malware with the right privileges can log keystrokes or read memory. We can reduce the damage, not guarantee. The hardware key protects stolen copies of the file, not an open vault on an infected computer.

  • Copies made before the hardware key

    Old backups and system or cloud copies made before turning it on still open with password and Secret Key.

  • Forgotten password and lost Kit

    Without the master password and the Emergency Kit (and, with a hardware key, the recovery code) the data cannot be recovered. That is the price of a vault nobody else can open.

  • A password written down elsewhere

    No program protects a password that is photographed, dictated or noted on a sheet left in plain sight.

FAQ about theft and infected computers

What leaves your computer

Your passwords, never. The app goes online only to check for updates and, if you turn it on and start it, for the breached-password check with Have I Been Pwned: only the first 5 characters of each password's fingerprint are sent, shared by thousands of different passwords. The service sees the request's IP address.

Signed updates, even against our own server

Every update is signed with an Ed25519 key that is not on our server: signing happens offline, before publishing.

The update server accepts a package only if its signature is valid and its version is higher than the published one: no altered packages, no rollbacks to old versions.

The app checks the signature again before installing: not even someone who took over the server could make you install a package other than ours. From the first public release, packages will also carry the Windows and Apple signatures.

Independent review

Aelyna Keys is in development. An external cryptographic audit and a penetration test are planned before version 1.0, with the report published. They have not been done yet, and we do not claim otherwise.

Found a vulnerability?

Write to us privately, without opening public reports: [email protected]

We reply within 72 hours and fix critical issues within 14 days. Good-faith research on your own copies will not face legal action from us. Our PGP key will be published before the first public release.