Security

Unreadable to anyone but you.

We built AI Memory Vault on one principle: your data should be unreadable to anyone but you.

End-to-end encryption

Every piece of data in your vault is encrypted with AES-256-GCM — the standard used by banks and governments — before it ever leaves your device. Your keys are derived from your passkey and are never sent to or stored on our servers.

Passkey authentication

No passwords. AI Memory Vault uses WebAuthn / FIDO2 passkeys. Your fingerprint or Face ID never leaves your device, and there's nothing to steal, reuse or phish.

Zero-knowledge architecture

We cannot see your vault content, cannot hand it to third parties, do not use it to train AI models, and have no backdoor.

Infrastructure security

Hosted on AWS with enterprise-grade controls: TLS 1.3 in transit, encryption at rest, regular automated security scans, and strict internal access control and audit logging.

AI agent permissions

Scoped — agents see only what you permit. Time-limited — access expires automatically. Fully logged in your audit trail. Revocable instantly.

Independent audit

An independent third-party security audit is in progress. Results will be published on this page when complete.

Passkeys, explained

  • Your biometric data (fingerprint, Face ID) never leaves your device
  • No passwords to steal, reuse or phish
  • Resistant to credential stuffing and man-in-the-middle attacks
  • An open standard supported by Apple, Google and Microsoft

Built on production-grade technology

These are the tools we build with. No partnership or certification is implied.

AES-256-GCMWebAuthn / FIDO2AWSPostgreSQLNext.jsReact NativeOpenAIAnthropic

Responsible disclosure

If you discover a security vulnerability, please report it responsibly to hello@hushkey.io (subject: "Security"). We take all reports seriously and will respond within 48 hours. We do not pursue legal action against good-faith security researchers.