keylore.ai← Home

Security

keylore holds the most personal data there is. Here is exactly how it is protected — and why you do not have to take our word for it.

Zero-knowledge vault

Vault items are encrypted in your browser with a master password we never see, using AES-256-GCM. keylore’s servers store ciphertext only — we cannot decrypt your vault, and neither can anyone who breaches us. Forgotten master passwords are unrecoverable by design.

Encryption at rest, everywhere

Memories, transcripts, playbooks, verification questions and provider credentials are AES-256-GCM encrypted at the application layer before they touch the database — on top of full-disk encryption at the infrastructure layer.

Memory-verified access

Trusted contacts prove who they are by answering questions only they could answer — set by you. Sensitive queries (passwords, financial details) require verification before your avatar will discuss them, and access is scoped per contact.

Row-level isolation

Every record is bound to your account with database-enforced row-level security. Your data is never used to train AI models — yours stays yours.

You own every layer

Bring your own AI provider or self-hosted model, and point recordings at your own storage bucket, on Account → Ownership. Export everything as a self-contained encrypted file at any time. 90 days notice before any shutdown, with an open-source decryption tool.

Found a vulnerability? Email security@keylore.ai — we respond fast and credit researchers.