Only You Can Open Your Workspace

Every encrypted service has a key. What matters is who can use it.

Here is the architecture that puts your key beyond our reach. 

Your data and its key are never in the same place

Your workspace is protected with envelope encryption, the standard practice in cloud security for handling encryption keys at scale.

In a standard envelope encryption implementation, your data is encrypted with a Data Encryption Key (DEK). The DEK is stored alongside the data it protects, and is itself encrypted with a second key, the Key Encryption Key (KEK). The KEK is stored somewhere else, usually a hardware security module. Whoever holds the data cannot read it. Whoever holds the KEK has no data to read.

MasterKey holds your key, and never holds it whole

Here the KEK is held by MasterKey, BankVault’s invisible passwordless MFA technology, protected by U.S. Patent 12,526,272, granted January 2026.

MasterKey runs as a decentralized protocol. Your KEK is double-encoded and encrypted with three secrets, held in three separate places. A temporary secret in the VanishingPoint webserver, valid for that session only. A semi-permanent secret in the browser on your phone. A permanent secret in the MasterKey infrastructure. They are never released to each other and never come together, so there is no single attack surface.

You scan the QR code and tap to confirm. The three secrets do their work without ever meeting, and your data is decrypted for reading inside your workspace. It runs on an out-of-band trusted connection established when the system was built.

Nothing to download, install, or configure.

MasterKey protocol: the VanishingPoint webserver displays a QR code, the mobile browser reads it across an air gap, and the MasterKey infrastructure completes the handshake.
The QR code is a one-way optical channel. Your screen displays it, your phone reads it, and nothing travels back. Your phone and your computer never connect.

Your recovery code was never typed on your device

The KEK is derived from your secret recovery code, entered once on the Invisible Encrypted Keyboard when you enrolled.

The Invisible Encrypted Keyboard is an illusion created on a separate device. Your recovery code is never visible to the clipboard, the browser, or the operating system on the machine in front of you. It never existed there. Infostealer malware and keyloggers on your phone or your computer had nothing to read or intercept.

A key is only as strong as the moment it was created. This was that moment.

Steal either side and you have nothing

Our storage holds two things: your encrypted workspace and the encrypted DEK beside it. Both are ciphertext.

Steal our storage and you have ciphertext.

MasterKey holds your KEK and nothing else. No data, no DEK. Steal MasterKey and you have a key with nothing to open, and one that will not release without your phone.

There is no override

Neither system can open your workspace alone.

That is true for an attacker, it is true for a court order, and it is true for our own system administrators. There is no support ticket, no administrator override and no insider route that opens it.

This is not a policy. Policies change. There is nowhere in this architecture to put a master key.

What happens when you log in

You scan to log in and tap to confirm on your phone.

Your remote machine is built, the DEK is unlocked, and your workspace opens inside that machine, and only there. Log out or disconnect and the machine is destroyed and the workspace returns to ciphertext.

Lose your phone and the key goes with it

Reset or lose your phone and the KEK goes with it.

To re-enroll, a link is sent to the email address you signed up with. You then enter your secret recovery code on the Invisible Encrypted Keyboard, and the KEK is rebuilt. Without both, the workspace cannot be recovered, by you or by us.

Delete your account and the encrypted workspace and its DEK are destroyed. The KEK then has nothing left to open.

The lock covers everything you put inside

Everything you carry into the workspace, and everything you install there, is protected by the same lock.

Whether it deserves to be there is your call. What happens step by step, from login to logout: see Before Your Session.

On the roadmap

v2.1 adds Passkeys for Proof-of-Presence.

The KEK will not be released without it. You will also be able to enroll additional backup devices, each of which also requires your Proof-of-Presence.

ULTRA goes one step further.

You can host the workspace and its storage inside your own network or on your own device, so the encrypted data never leaves infrastructure you control. Planned for v2.4, or earlier by special request.