In the next few years, a growing share of everyday tasks will be handled by AI rather than by us clicking through apps. To do those tasks, AI will need our personal and private data — and today that data is spread across systems that were never designed for AI to use safely.
AI Memory Vault is built for that future: one private place where you and the AI you trust can both reach your information, without anyone else being able to read it. Here's how the architecture works, and how it differs from what came before.
The last generation, in one table
| Last generation | AI Memory Vault | |
|---|---|---|
| Sign-in | Passwords (+ codes) | Passkeys (WebAuthn / FIDO2) |
| Encryption keys | Held by the provider | Derived from your passkey, never on our servers |
| Where encryption happens | On the server | On your device, before upload |
| Who can read your data | You and the provider | Only you |
| App/AI access | Broad, long-lived | Scoped, time-limited, revocable |
| Visibility | Little or none | Full audit log |
| Leaving | Hard | Export or delete anytime |
1. Sign-in with passkeys
There are no passwords. You sign in with a passkey, unlocked by your fingerprint, face or device PIN. Your biometrics never leave your device, and our servers store only a public key — so there's no password database to steal or phish. (Why this matters: Passkeys went mainstream.)
2. Keys that only you hold
Your vault's encryption keys are derived from your passkey credentials and are never transmitted to or stored on our servers. That's what makes the rest of the design possible: if we never have the keys, we can't read your data — and neither can anyone who breaks into our systems.
3. Encrypted before it leaves your device
Everything you add — documents, photos, notes, voice memos — is encrypted with AES-256-GCM on your device before it's uploaded. Data is also protected in transit with TLS 1.3, and stored encrypted at rest on AWS infrastructure. Our servers hold ciphertext.
4. Zero-knowledge by design
Put together, this is a zero-knowledge architecture: we can't see your vault content, can't hand it to third parties, don't use it to train AI models, and have no backdoor.
5. Understanding, on your side
A vault is only useful if it understands what's inside. AI Memory Vault organises and connects your information — dates, amounts, people, deadlines — into a private knowledge base, so you can ask "When does my passport expire?" or "What did we agree with the client on payment terms?" and get an answer with its source, plus reminders before things expire.
6. AI agents with permission, not possession
This is the part built for what's next. When you want an AI agent to act for you, you grant it access that is:
- scoped — it sees only what you permit;
- time-limited — access expires automatically;
- fully logged — every read appears in your audit trail;
- revocable — cancel instantly.
It works with any AI assistant through a permissioned API. You → Memory Vault → AI agent → Action. (Background: AI agents will need your private data.)
7. Yours to keep
You can export your whole vault, or close your account and have the content permanently deleted within 30 days.
Why this is the future
As AI does more of the work, the bottleneck stops being intelligence and becomes trusted context. The winners won't be the apps that collect the most data about you; they'll be the systems that let your AI use your data without you giving it away. That's the bet behind AI Memory Vault — and why we think memory is the missing layer between humans and AI.
AI Memory Vault is in private beta. An independent security audit is in progress, and we'll publish the results on our Security page. If you'd like to help shape it, join the waitlist.
Frequently asked questions
Can Hushkey Labs read my vault?
No. Content is encrypted on your device with AES-256-GCM using keys derived from your passkey, which never reach our servers.
How do AI agents access AI Memory Vault?
Through a permissioned API with scoped, time-limited, logged and revocable grants that you control.
Sources
- FIDO Alliance — The State of Passkeys 2026
- Gartner agentic AI predictions (via Campus Technology)
- IBM — Cost of a Data Breach Report 2026: key findings (eSecurity Planet)
Figures are as reported by the sources above at the time of writing; survey data from vendors is indicative. AI Memory Vault is in private beta — product details describe how it is designed.