Inside AI Memory Vault: how the architecture differs from the last generation

Passkey-derived keys, on-device AES-256-GCM encryption, zero-knowledge storage and permissioned AI agents. How AI Memory Vault is built, and why the future needs it.

In the next few years, a growing share of everyday tasks will be handled by AI rather than by us clicking through apps. To do those tasks, AI will need our personal and private data — and today that data is spread across systems that were never designed for AI to use safely.

AI Memory Vault is built for that future: one private place where you and the AI you trust can both reach your information, without anyone else being able to read it. Here's how the architecture works, and how it differs from what came before.

The last generation, in one table

Last generationAI Memory Vault
Sign-inPasswords (+ codes)Passkeys (WebAuthn / FIDO2)
Encryption keysHeld by the providerDerived from your passkey, never on our servers
Where encryption happensOn the serverOn your device, before upload
Who can read your dataYou and the providerOnly you
App/AI accessBroad, long-livedScoped, time-limited, revocable
VisibilityLittle or noneFull audit log
LeavingHardExport or delete anytime

1. Sign-in with passkeys

There are no passwords. You sign in with a passkey, unlocked by your fingerprint, face or device PIN. Your biometrics never leave your device, and our servers store only a public key — so there's no password database to steal or phish. (Why this matters: Passkeys went mainstream.)

2. Keys that only you hold

Your vault's encryption keys are derived from your passkey credentials and are never transmitted to or stored on our servers. That's what makes the rest of the design possible: if we never have the keys, we can't read your data — and neither can anyone who breaks into our systems.

3. Encrypted before it leaves your device

Everything you add — documents, photos, notes, voice memos — is encrypted with AES-256-GCM on your device before it's uploaded. Data is also protected in transit with TLS 1.3, and stored encrypted at rest on AWS infrastructure. Our servers hold ciphertext.

4. Zero-knowledge by design

Put together, this is a zero-knowledge architecture: we can't see your vault content, can't hand it to third parties, don't use it to train AI models, and have no backdoor.

5. Understanding, on your side

A vault is only useful if it understands what's inside. AI Memory Vault organises and connects your information — dates, amounts, people, deadlines — into a private knowledge base, so you can ask "When does my passport expire?" or "What did we agree with the client on payment terms?" and get an answer with its source, plus reminders before things expire.

6. AI agents with permission, not possession

This is the part built for what's next. When you want an AI agent to act for you, you grant it access that is:

  • scoped — it sees only what you permit;
  • time-limited — access expires automatically;
  • fully logged — every read appears in your audit trail;
  • revocable — cancel instantly.

It works with any AI assistant through a permissioned API. You → Memory Vault → AI agent → Action. (Background: AI agents will need your private data.)

7. Yours to keep

You can export your whole vault, or close your account and have the content permanently deleted within 30 days.

Why this is the future

As AI does more of the work, the bottleneck stops being intelligence and becomes trusted context. The winners won't be the apps that collect the most data about you; they'll be the systems that let your AI use your data without you giving it away. That's the bet behind AI Memory Vault — and why we think memory is the missing layer between humans and AI.

AI Memory Vault is in private beta. An independent security audit is in progress, and we'll publish the results on our Security page. If you'd like to help shape it, join the waitlist.

Frequently asked questions

Can Hushkey Labs read my vault?

No. Content is encrypted on your device with AES-256-GCM using keys derived from your passkey, which never reach our servers.

How do AI agents access AI Memory Vault?

Through a permissioned API with scoped, time-limited, logged and revocable grants that you control.

Sources

  1. FIDO Alliance — The State of Passkeys 2026
  2. Gartner agentic AI predictions (via Campus Technology)
  3. IBM — Cost of a Data Breach Report 2026: key findings (eSecurity Planet)

Figures are as reported by the sources above at the time of writing; survey data from vendors is indicative. AI Memory Vault is in private beta — product details describe how it is designed.

Follow Hushkey:

AI Memory Vault

Give your AI a memory you own.

Private, encrypted, passkey-protected — with permissioned access for your AI agents. Join the private beta waitlist.

No spam. One email when your invite is ready.

Keep reading

Your personal data is scattered — and that’s the security problem

Record breach costs, AI-assisted attacks and data spread across dozens of apps. What the 2026 IBM and Verizon reports tell us, and what a safer home for personal data looks like.

Own your keys: passkeys, your own AI and real decentralisation

Centralised databases are honeypots. Passkeys move the key back to you — and combined with client-side encryption and permissioned AI, they make a genuinely user-owned model possible.