Important - Before Your Session

Read this before you log into anything that matters

VanishingPoint moves your session to a workspace your device cannot reach. That protection has edges. Most are decisions you make: what you type, install, and carry out.

1

Two workspaces

Every session builds a new desktop, in seconds. What you carry into it is your choice.

  • Your Workspace: Settings, favorites, history and plugins restored into it each time, held encrypted between sessions. It opens where you last left off. A Google account left signed in is still signed in when you return. Ticking Reset before you sign in returns your workspace to factory default: settings, favorites, history, plugins, everything. You can’t undo this once done.
  • Temporary Workspace: A burn machine, selected before you sign in. Nothing carried in. Nothing saved out. Use it to open a hazardous link or an unexpected attachment, or for anything you want no record of.

It is good security hygiene to reset whenever a piece of work is finished, and after any session where something unknown came in: a link you were sent, an attachment you did not expect, a plugin you tried once. You are back to a pristine machine, with nothing left over from previous sessions to watch this one. Treat Your Workspace as convenience, not custody. v2.1 is where that changes, with encrypted data file storage secured by Proof-of-Presence.

2

A desktop needs a big screen

VanishingPoint is a full desktop that runs alongside your own machine: files in, downloads and printing out, your clipboard pasting into the session. It needs a big screen to work on: a laptop, desktop, or even a smart TV where your phone becomes the keyboard it never had.

Your phone has another job here, and it is the more important one.

3

No password, two devices, one tap

Your workspace holds your settings, your history and your logged-in sessions. The strength of your login is what everything else rests on.

Scan the QR code with your phone, then tap to approve.

VanishingPoint uses MasterKey’s patented technology for invisible passwordless multi-factor authentication. No software. No setup. Both factors in one step, not two.

Your credentials are captured in a decentralised protocol that sidesteps your local device entirely. The attack surface is split across separate devices and factors, so compromising one is not enough. Your physical phone identifier is the second factor. The tap confirms the authentication to proceed. You can add a third factor using Passkeys, unlocked by biometrics, a PIN or a security key, as Proof-of-Presence.

Stolen credentials alone cannot get into your VanishingPoint account.

Anti-hijacking: no interception, replication or playback. The stream is end to end encrypted, session credentials are single use and scoped to your desktop, and the desktop runs in an isolated origin. A captured stream cannot be replayed, and a session cannot be silently cloned to a second watcher.

4

Keep your recovery code somewhere safe

Your recovery code is one of the factors that you may need to recover your account. Choose 8 or more characters, upper and lower case, with numbers. Write it down and keep it somewhere physical, away from the device you log in with.

There is no way to recover a lost recovery code. 

5

Never type a credential on your own keyboard

This is the most important instruction on the page.

The remote machine accepts input from your laptop keyboard, and those keystrokes pass through the computer you should not trust. Fine for ordinary typing. Never for a password, a PIN, or a cryptographic seed phrase.

Scan the QR code and enter credentials through the Invisible Encrypted Keyboard on your phone. What you type is encoded by a secret only the remote workspace can decipher. No software, no setup. On your phone, infostealer malware can only capture encoded data that cannot be deciphered or used: no keystrokes, no mouse coordinates. Your laptop is sidestepped completely.

There is a mousepad above the keyboard, and a Paste button that pastes from your phone’s clipboard into the remote desktop.

Check the “Key Feedback” toggle at the top of the keyboard is set to Off. When set to On, each key is highlighted as you press it. This helps while you learn the layout, but a screen recorder on your phone could play this back. This setting can stick in your phone’s browser cache, so check it is Off before you enter anything that matters.

6

Change your important passwords from inside VanishingPoint

Every password you have typed on your own keyboard has passed through a machine you cannot verify. Assume they are known.

Start with email. It is how every other account gets reset. Then your bank, your exchange, and your password manager.

Log into each account inside the workspace, change the password, and enter the new one on the Invisible Encrypted Keyboard. The new password has never touched your local machine.

Install your password manager’s browser plugin in the workspace, one of the few worth trusting, and update it there as you go. Bitwarden, 1Password, LastPass and Dashlane all work.

7

Come back to every tab you left open

Set your browser to resume from your last session.

  • Brave. Already set. Nothing to do.
  • Firefox. Menu, Settings, General, then under Startup check Open previous windows and tabs.
  • Chrome. Three dots, Settings, On startup, Continue where you left off.

You can also sign in to your browser account and turn on sync. Your bookmarks, plugins, saved logins and history fill the workspace. When ticking Reset returns your workspace to factory default, sync brings your browser straight back.

Signing in means typing your Google or Mozilla password inside the workspace. Enter it on the Invisible Encrypted Keyboard.

Brave has no sign-in. It joins a sync chain with a 24 word code. That code opens every saved password in the chain, so treat it like a seed phrase and enter it on the Invisible Encrypted Keyboard.

8

Every plugin can watch every tab, on your machine and ours

Browsers are built to let a plugin see every tab you have open. That is not a flaw in any one browser. It is how the technology was designed, and it is true on your own machine right now.

VanishingPoint currently gives you Chrome, Firefox and Brave, so the same rule applies inside your session. A plugin you install stays there and can read everything you do in that browser: your exchange, your bank, all of it.

We recommend not installing plugins at all. You have the freedom to do it. Only install what you trust, and know that a plugin which is safe today can change hands tomorrow.

A workspace that remembers you also accumulates baggage. Reset and you’re back to a pristine machine, carrying no plugin from the sessions before it. Sync will reinstall whatever is still in your browser account, so remove what you no longer trust there first, then reset.

9

One way clipboard

Two machines, one desk. Everything that passes between them moves in one direction, by design.

Copy something from your local machine and paste it into the workspace. A password from your local password manager, for example. This works from Chrome-based browsers. Firefox blocks it.

Your local machine cannot read the remote clipboard. A seed phrase or private key copied inside the workspace stays there, out of reach of infostealer malware reading the clipboard on your own machine.

If you need to bring text out, print to PDF, save it to a file and download it, or email it to yourself. None of these happen by accident, which is the point.

10

Drag files in, click files out

Drag a file from your computer onto the desktop window and it uploads. On PRO and ULTRA, the Files button in the toolbar downloads what you need back. Print anything and a PDF is handed back to your local desktop where you can save or print it. 

11

Your bank or exchange never touches your device

Everything you open runs in the remote machine. Sites, session cookies, account pages and balances exist solely there, out of reach of malware on your device or your network.

Session cookies are how most account takeovers happen, and they defeat 2FA. Yours are never on your device to steal.

12

Malware only sees asterisks

Your device receives a stream of pixels over an encrypted connection, like a television receiving a signal from a station.

Infostealer malware cannot inject code into a pixel stream, but it can record the display.

Enter a password or a cryptographic phrase into a web form and asterisks appear. On a local machine that is a mask for the human sitting next to you. Software on that machine reads the field as clear text. Password managers store credentials encrypted, but then load the decrypted password into web forms. You see asterisks. Infostealers see the password.

The Invisible Encrypted Keyboard sidesteps the local device. What you type creates encoded data that only the remote desktop can decipher. Infostealer malware on your local machine sees only an image of asterisks.

You can’t hack something that doesn’t exist.

13

The Invisible Wallet

Reconstruct your cryptocurrency wallet inside a machine that is invisible from the internet. Hardware wallet security, online wallet convenience.

Use the desktop wallets in the menu, or install your own wallet as a browser plugin.

Enter your 12-24 word seed phrase on the Invisible Encrypted Keyboard. It is typed on your phone, encoded, and reconstructed only inside the remote workspace. Your local device is sidestepped. Keyloggers, clipboard scrapers and infostealers have nothing to read.

Use a wallet that masks the seed phrase as you enter it. Not all do. Exodus displays every word, readable by anyone behind you and by a screen recorder. We include it because customers ask for it. We do not recommend it.

Hardware wallet support arrives in v2.1 on PRO and ULTRA, connecting through USB passthrough. Your device will talk to the wallet app in the remote machine directly. Ledger Live, Trezor Suite, Blockstream Green and BitBoxApp are supported. ULTRA will support air-gapped QR code wallets.

We give you a secure environment. What you run inside it is your choice. We keep the operating system current and patched. We do not write the wallets. A seed phrase is only as strong as the randomness used to create it, and weak generation has left wallets open to reconstruction, in hardware and software alike. Nothing you do afterwards fixes a phrase that was predictable from the start. Generate on an independently audited wallet, on a dedicated hardware device where you can supply your own entropy.

Good policy is to log out of your wallet and close it when you finish.

Stolen crypto is gone forever. No chargebacks, no insurance, no recovery. Never enter a seed phrase on your own keyboard. Use the Invisible Encrypted Keyboard.

14

If your network connection drops

Your screen freezes and a small message says the connection is lost. Most outages are brief and your browser may reconnect quickly.

Your disconnected session keeps running for a while: LITE 5 minutes, PRO 15 minutes, ULTRA 60 minutes. Reconnect inside that window and you have not lost a keystroke.

You may be required to confirm Proof-of-Presence again, from the same devices and the same network. Switching from wifi to a mobile hotspot will not work. That is one of the steps preventing anyone else resuming your session.

Log out deliberately when you finish. Do not leave a session open and walk away.

15

Isolation protects the session, not the decision

VanishingPoint moves your session off your device. It does not remove your judgement.

Internet isolation cannot stop social engineering. What it does is add a step. Make it a rule to move into an isolated session before you transact. That deliberate step disrupts the reflexes social engineering relies on.

Confirm the site you are on is the one you meant to visit. Check every wallet address against a source you trust before you send. Treat an unexpected request the same way inside the workspace as you would outside it.

A transaction you approve is a transaction you approved.

16

Where the protection ends

VanishingPoint gives you a clean machine, built fresh, invisible from the internet, and gone when you leave. What happens inside it is yours.

Two things we cannot reach. What you carry in, and what was already broken before you arrived. A seed phrase generated with weak randomness was compromised at birth. A password stolen last year is stolen whether you type it here or anywhere else. Isolation removes the attack surface. It does not rewrite history, and it does not overrule your decisions.

Run through this before a session that matters:

  1. A file you download or print to your device has left the protected environment.
  2. Drag an infected file into the workspace and it can infect the workspace.
  3. A plugin you install can read everything you do in that browser.
  4. A Reset will not remove a plugin if sync reinstalls it.
  5. A credential typed on your laptop keyboard, or copied to your local clipboard, can be read by infostealer malware.
  6. Login credentials or a wallet already compromised before you started are still compromised.
  7. A lost recovery code cannot be recovered by anyone.
  8. Anything displayed on your screen can be recorded by malware on your device.