Security, explained simply
Aelyna® Keys is built on one principle: only you can open your vault. Here is how it works, and where the limits are.
Three keys for one vault
Your passwords are locked in an encrypted vault. To open it the app combines up to three things: without any one of those required, the content stays unreadable.
-
Always
Master password
Something you know. Never stored, never sent.
-
Always
Secret Key
A random code on your computer and on your printed Emergency Kit. Never in backups.
-
Optional
Hardware key
A FIDO2 key you touch, protected by its PIN.
Together they form the vault key, which in turn opens a different key for every item. Everything is encrypted: passwords and notes, but also titles and website names.
Behind the scenes
-
Encrypted on the device
Every item is encrypted with XChaCha20-Poly1305, a modern, well-studied algorithm, before it touches the disk.
-
Slow to guess
The key is derived from your master password with Argon2id, which needs a lot of memory and time per attempt: trying millions of passwords becomes very expensive.
-
128-bit Secret Key
Even with a weak password, someone who steals the file would have to try more combinations than any existing computer can.
-
No home-made cryptography
Only standard algorithms from well-known libraries, checked against official test vectors.
-
Tamper-evident file
If someone modifies, swaps or rolls back the file, the app notices and will not open it without asking you.
-
Automatic lock
On inactivity, sleep and screen lock: locking wipes the keys from memory.
-
Clipboard and screen
The clipboard clears itself; on Windows passwords stay out of the history. The window can be kept out of screen captures.
What happens if…
| Situation | What Aelyna protects |
|---|---|
| Your laptop is stolen while off | Everything is encrypted: nothing can be read without the master password. |
| Someone copies the vault file or a backup | Without the master password and the Secret Key the file is useless. |
| A program reads the clipboard | The clipboard clears itself; on Windows passwords stay out of the history (Win+V) and cloud sync. |
| You share your screen in a meeting | The window can be excluded from screen capture; passwords stay hidden until you press Show. |
| Malware steals the file, Secret Key and password | With the hardware key on, the stolen copy stays locked without the physical key. |
What we cannot protect
We say this in the app too, because trust means knowing where the boundaries are.
-
An infected computer while the vault is open
Malware with the right privileges can log keystrokes or read memory. We can reduce the damage, not guarantee. The hardware key protects stolen copies of the file, not an open vault on an infected computer.
-
Copies made before the hardware key
Old backups and system or cloud copies made before turning it on still open with password and Secret Key.
-
Forgotten password and lost Kit
Without the master password and the Emergency Kit (and, with a hardware key, the recovery code) the data cannot be recovered. That is the price of a vault nobody else can open.
-
A password written down elsewhere
No program protects a password that is photographed, dictated or noted on a sheet left in plain sight.
What leaves your computer
Your passwords, never. The app goes online only to check for updates and, if you turn it on and start it, for the breached-password check with Have I Been Pwned: only the first 5 characters of each password's fingerprint are sent, shared by thousands of different passwords. The service sees the request's IP address.
Signed updates, even against our own server
Every update is signed with an Ed25519 key that is not on our server: signing happens offline, before publishing.
The update server accepts a package only if its signature is valid and its version is higher than the published one: no altered packages, no rollbacks to old versions.
The app checks the signature again before installing: not even someone who took over the server could make you install a package other than ours. From the first public release, packages will also carry the Windows and Apple signatures.
Independent review
Aelyna Keys is in development. An external cryptographic audit and a penetration test are planned before version 1.0, with the report published. They have not been done yet, and we do not claim otherwise.
Found a vulnerability?
Write to us privately, without opening public reports: [email protected]
We reply within 72 hours and fix critical issues within 14 days. Good-faith research on your own copies will not face legal action from us. Our PGP key will be published before the first public release.