Security & architecture

The short version: your data is encrypted before it reaches us, and we hold no key that opens it. Everything below explains how that works — and what it costs you.

Zero-knowledge by construction

Most services promise not to look at your data. We built it so we cannot. Profiles, folders and warmed sessions are encrypted on your device with a key derived from a passphrase that never leaves it. What arrives at our servers is ciphertext with an identifier and a timestamp.

That means cookies, local storage, fingerprint configuration, notes and any proxy credentials inside a profile are opaque to us, to anyone who compromises our infrastructure, and to anyone who compels us to hand over what we hold.

Team sharing without handing us the keys

Sharing normally means giving the server a key. Instead, each user has an X25519 keypair whose private half is wrapped with their own passphrase-derived key. A workspace has its own data key, and that key is sealed individually to every member’s public key. The server stores and relays sealed envelopes it cannot open.

A log that cannot be quietly rewritten

Every membership and access-control change is appended to a per-workspace audit log where each entry carries the hash of the one before it. Three properties matter:

Access control

Workspaces have four roles — owner, admin, member, viewer — with per-profile access lists on top. Access lists are default-deny where the workspace is configured that way: a profile nobody has been granted is served to nobody, rather than to everyone by accident. Removing someone from a workspace also strips them from every profile list, so re-adding them later does not silently restore old access.

What stays on your machine

Profile isolation, browser launching, fingerprint injection and the local automation API all run locally. Websites you visit inside a profile are contacted by your machine or your proxy — that traffic never passes through us, and we do not log it because we never see it.

The honest trade-offs

A design like this has costs, and you should know them before you buy rather than discover them later.

Operational practices

Questions your security team will ask

Send them over. We would rather answer a hard architecture question up front than have you discover an assumption later.

Talk to us Read the DPA