Security

We would rather say the hard part out loud. This page describes how MiSalvo is built to protect your Vault. What we can stand behind today, what we do not claim, and how to report a problem.

Our rule

Do not claim what we cannot prove. If it is not true in code and copy, we do not put it on the site or in the app.

Why we do not ask for your email or phone

We do not collect an email address or a mobile number to create an account. You open MiSalvo with Face ID or Touch ID on this phone. There is no password. There is no reset email. There is no text message code.

If we stored those, they would become a target. Most account theft starts with “click here to reset” or a text that looks like us. We would also hold a list of household contacts the product does not need.

We talk to you in the app. Optional push if you turn it on. We do not send product email, SMS, or WhatsApp about your life admin.

This is the same honest limit as your Vault. Staff cannot reset you. If you lose every recovery path, we cannot get you back in. Apple handles the subscription at this US launch. Google will when we launch on Google Play. We never see your card.

Zero-knowledge by design

Vault papers are encrypted on your device before they leave it. Keys that open your papers stay with you. Vault key, device keys, and optional Spare Key material. MiSalvo staff have no tool to decrypt your Vault. That is the product design. It is not a third-party certificate or an “independently audited” badge. We have not published an audit letter yet (see below).

What MiSalvo can and cannot see

  • Cannot read: Vault document contents, document keys, your Vault key, Spare Key package plaintext, OCR bodies used for search, or Salvo pack letter prose stored sealed.
  • May hold for sync: Sealed ciphertext, IVs, and coarse metadata (timestamps, tier Protected/Fortified, share status, capture source tags).
  • Account metadata: Name, Circle membership, market, app language, subscription state. Needed to run the service.
  • Never: Sell your data, train AI on your papers, or run ad trackers in the app.

How encryption works (plain language)

Vault documents are sealed on your phone under separate Protected and Fortified encryption keys. We use standard algorithms. AES-256-GCM for documents, X25519 and HKDF for sharing and recovery wraps. Sharing re-encrypts under a fresh key for the recipient; your key does not travel. Salvo secure links encrypt the pack on your device; the server stores ciphertext and a token. When possible, the link key stays in the URL fragment, not on our servers.

Recovery and lockout

You need at least one path: your written Vault key, Spare Key, or another signed-in device. MiSalvo cannot reset you by email or support ticket. Lose every path and your Vault contents are gone permanently. By design. Details: FAQ. Recovery and Spare Key.

Honest custody

While you use MiSalvo, we store sealed copies so your devices stay in step. Encryption means staff cannot read them. It does not mean “nobody holds anything.” After you leave and wipe completes, we do not keep a product stash of your Vault for debugging or AI. Backup systems can lag briefly; our Privacy Policy states that honestly.

Where sealed copies live

Today, households in the United States, Canada, and Mexico use a host in Ohio, United States. When we open the UK, those households will use Frankfurt, Germany. EU households, including Ireland, will use the same host in Frankfurt, Germany. South America is planned for São Paulo, Brazil. Asia-Pacific is planned for Singapore. When we open India, those households will use Mumbai, India. South Africa stays on the United States host until a local option exists. Apple billing and optional push can still run outside that country. Picking a city is not a privacy certification. Details: Privacy.

What we do not claim (yet)

  • No independent security audit letter published yet. We are pre-seed; a scoped review is planned when funded.
  • No SOC 2, ISO 27001, or GDPR certification.
  • No “unbreakable” or “military-grade” marketing.
  • No system is 100% secure. We designed MiSalvo for a worst case on our servers. If someone reached them, they would find sealed Vault blobs, not readable papers. Keys stay on your phone. We fix issues we find. If encryption cannot finish, we stop. We do not save an unlocked copy.

Trackers and on-device intelligence

The public site uses no ad pixels or tag managers. On misalvo.com we use Cloudflare Web Analytics for aggregate page views and site performance. That is not advertising. The app ships without ad, MMP, or third-party product-analytics SDKs. Document recognition and spend hints run on your phone first. Cloud label assist is not on at this launch. If we later add a thin, capped, disclosed MiSalvo-paid cloud classify, it would never send whole Vault images by default.

Report a security issue

Good-faith reports welcome: [[mail:security]]. Include steps to reproduce and impact. Do not include live Vault keys, recovery codes, or other people’s data. We do not offer a paid bug bounty yet; we will acknowledge reports and work on fixes.

Product support and Vault recovery requests still go through Account → Help or [[mail:support]]. We cannot decrypt your papers.

What comes next

When budget allows, we plan a scoped third-party review of the iOS crypto module and recovery Edge paths. Then publish a summary of scope, date, and fixes. Until then, this page and our Privacy Policy are the honest source.

Related

Privacy Policy §12 · FAQ · Terms · Contact

Last updated: 16 September 2026. Plain language. If this page and Privacy or Terms disagree, the legal pages win. Tell us so we can fix the gap.