Skip to content
Keystone

Security

Security you can verify. Not just believe.

Keystone is only as good as its honesty. Here is exactly how we protect your information — and what we have deliberately made impossible, even for ourselves.

Three layers

The closer to the core, the fewer hold the key.

  1. Layer 1 of 3

    In transit

    All traffic between your device and Keystone is encrypted with TLS.

    Standard protection — like your online bank.

  2. Layer 2 of 3

    At rest

    All your data in Keystone is encrypted in the database with AES-256-GCM, field by field. A copy of the database is unreadable without the keys, which are stored separately.

    Keystone holds this key — which is why search works, and why your account can be recovered.

  3. Layer 3 of 3

    Sealed

    Passwords, PINs and recovery codes are encrypted in your browser with a sealing passphrase you choose — before they are ever sent to us. The server stores only ciphertext.

    Only you hold this key. We cannot read these fields — no matter who asks.

Sealed secrets

"We can't read them" has to mean something.

Many services promise not to look. We built it so we can't: sealing happens with WebCrypto in your own browser, and neither your sealing passphrase nor the raw key ever leaves your device.

When you set up sealing, you print a recovery kit: a 26-character code with a QR, stored with your will or handed to your executor. If you forget the passphrase, the kit restores access — and after a release, it's the kit that lets your contacts open what was sealed.

What we cannot recover — by design

If you lose both your sealing passphrase and your recovery kit, the sealed fields are gone. We cannot undo that — and that is precisely why no one else can read them. Everything else in your account recovers normally: your regular password is reset via email.

Where your data lives

In the EU. In Frankfurt. Full stop.

Keystone runs from Frankfurt: application, database and documents all live in the EU. We show no ads, sell no data and use no tracking cookies.

Sub-processors
Vendor Role Region
Fly.io Application hosting EU (Frankfurt)
Neon Database EU (Frankfurt)
Cloudflare R2 Document storage EU / Global (data residency configurable)
Stripe Payments EU/US · data-processing agreement
Postmark Transactional email EU/US · data-processing agreement

The full data-processor register with agreements will be published here before launch.

Control

Security you can feel day to day

Tamper-proof audit log

Every access, download and change is written to a log that technically cannot be edited or deleted. You are notified when someone views what you've shared.

Two-factor sign-in

Protect the account with an authenticator app and one-time recovery codes. Sensitive actions — like cancelling a release — always require an extra confirmation.

A release with a brake

Access after a death requires documentation, manual verification and a 72-hour waiting period during which you can cancel. No single person can open your Keystone with one click.

Your data is yours

Full export at any time in open formats — including an offline reader for the sealed fields, so your data is never trapped with us.

Found a vulnerability?

Write to [email protected] — we respond quickly and take findings seriously. A formal disclosure policy and security.txt will follow before launch.

[email protected]

Do it today. Forget it safely tomorrow.

Ten minutes now means your family never has to search. Create your account, add what matters most, and let Keystone remind you about the rest.

From 9 kr/mo · Cancel anytime · Trusted contacts are free