Security Architecture
Zero-knowledge encryption, strict authorization boundaries, and auditable control planes.
Implemented Architecture
- Client-Side Encryption: Master Vault Encryption Keys (VRK) and Item DEKs are derived locally and never sent to servers in plaintext.
- Recipient Packages: Recipients receive an immutable cryptographic envelope using HPKE (RFC 9180) and AES-GCM.
- Release Broker Isolation: Release authority is structurally separated from storage and notification delivery.
- Mandatory Final Hold: 72-hour minimum cool-off period enforced by database timestamps. Trigger events never immediately release secrets.
- Default-Deny RLS: Row-level security strictly segregates owner and recipient data at the database layer.
Pre-Production Transparency Note
The QIP Vault platform is currently in authorized development stages (Phases 1–14). Production deployment is subject to formal external cryptographic audit, hardware security module (HSM) deployment, and physical multi-device validation.