Local operation
Prepared access-state changes and vault access are being designed to operate without a server round-trip.
Liberty Lock is in development. This page documents the security goals and limits guiding the product—not a certification, completed audit, or released guarantee.
Responsible disclosureThe security model begins with a narrow question: which information must be visible for a given action? Data that never reaches a system cannot be disclosed by that system.
These constraints are useful only if the final implementation can be tested against them.
Prepared access-state changes and vault access are being designed to operate without a server round-trip.
Protected material is intended to remain outside readable company systems during normal operation.
Key protection and authentication must use supported iOS and Android security capabilities rather than bypassing the operating system.
Recovery convenience can weaken confidentiality. The final design must state exactly who can recover what and under which conditions.
The diagram describes the intended boundary. It does not certify a released implementation.
If you identify a credible issue in the website, mobile application, or supporting infrastructure, describe the affected surface, reproduction steps, and relevant proof of concept. Avoid accessing, changing, or deleting other people’s data.
Email security disclosure