Liberty Lock
Security posture

Security claims should follow
implementation evidence.

Liberty Lock is in development. This page documents the security goals and limits guiding the product—not a certification, completed audit, or released guarantee.

Responsible disclosure
Working posture

Reduce exposure before adding complexity.

The security model begins with a narrow question: which information must be visible for a given action? Data that never reaches a system cannot be disclosed by that system.

01Current fact
The website and product model are public; the mobile product remains in development.
02Design target
Protected information and prepared access states are intended to operate locally.
03Design target
Company systems are intended to have a narrow view of protected content.
04Platform dependent
Planned key protection depends on the security capabilities exposed by supported iOS and Android devices.
05Open question
Recovery, backup, and account boundaries will be documented before product release.
06Not claimed
No audit, certification, performance benchmark, or cryptographic guarantee is presented as complete.
Threat boundaries

Four constraints guiding development.

These constraints are useful only if the final implementation can be tested against them.

01

Local operation

Prepared access-state changes and vault access are being designed to operate without a server round-trip.

02

Narrow service visibility

Protected material is intended to remain outside readable company systems during normal operation.

03

Platform constraints

Key protection and authentication must use supported iOS and Android security capabilities rather than bypassing the operating system.

04

Documented recovery

Recovery convenience can weaken confidentiality. The final design must state exactly who can recover what and under which conditions.

Visibility model

Planned local and service responsibilities.

The diagram describes the intended boundary. It does not certify a released implementation.

Conceptual division between operations intended to stay on a user device and limited backend responsibilities.
01 / Trust zoneUser deviceDesigned to stay local
Access state LOCALProtected content LOCALContext rules LOCALKey material PLATFORM PROTECTED
Planned boundaryProtected content / context / keys do not cross
02 / Limited scopeService boundaryIntended minimum view
Account state IF REQUIREDSubscription state IF REQUIREDBackup material CIPHERTEXTReadable vault content OUTSIDE SCOPE
Responsible disclosure

Report a security concern.

If you identify a credible issue in the website, mobile application, or supporting infrastructure, describe the affected surface, reproduction steps, and relevant proof of concept. Avoid accessing, changing, or deleting other people’s data.

Email security disclosure