Only You Can Open Your Workspace
Every encrypted service has a key. What matters is who can use it.
Here is the architecture that puts your key beyond our reach.
Your data and its key are never in the same place
Your workspace is protected with envelope encryption, the standard practice in cloud security for handling encryption keys at scale.
In a standard envelope encryption implementation, your data is encrypted with a Data Encryption Key (DEK). The DEK is stored alongside the data it protects, and is itself encrypted with a second key, the Key Encryption Key (KEK). The KEK is stored somewhere else, usually a hardware security module. Whoever holds the data cannot read it. Whoever holds the KEK has no data to read.
MasterKey holds your key, and never holds it whole
Here the KEK is held by MasterKey, BankVault’s invisible passwordless MFA technology, protected by U.S. Patent 12,526,272, granted January 2026.
MasterKey runs as a decentralized protocol. Your KEK is double-encoded and encrypted with three secrets, held in three separate places. A temporary secret in the VanishingPoint webserver, valid for that session only. A semi-permanent secret in the browser on your phone. A permanent secret in the MasterKey infrastructure. They are never released to each other and never come together, so there is no single attack surface.
You scan the QR code and tap to confirm. The three secrets do their work without ever meeting, and your data is decrypted for reading inside your workspace. It runs on an out-of-band trusted connection established when the system was built.
Nothing to download, install, or configure.

Your recovery code was never typed on your device
The KEK is derived from your secret recovery code, entered once on the Invisible Encrypted Keyboard when you enrolled.
The Invisible Encrypted Keyboard is an illusion created on a separate device. Your recovery code is never visible to the clipboard, the browser, or the operating system on the machine in front of you. It never existed there. Infostealer malware and keyloggers on your phone or your computer had nothing to read or intercept.
A key is only as strong as the moment it was created. This was that moment.
Steal either side and you have nothing
Our storage holds two things: your encrypted workspace and the encrypted DEK beside it. Both are ciphertext.
Steal our storage and you have ciphertext.
MasterKey holds your KEK and nothing else. No data, no DEK. Steal MasterKey and you have a key with nothing to open, and one that will not release without your phone.
There is no override
Neither system can open your workspace alone.
That is true for an attacker, it is true for a court order, and it is true for our own system administrators. There is no support ticket, no administrator override and no insider route that opens it.
This is not a policy. Policies change. There is nowhere in this architecture to put a master key.
What happens when you log in
You scan to log in and tap to confirm on your phone.
Your remote machine is built, the DEK is unlocked, and your workspace opens inside that machine, and only there. Log out or disconnect and the machine is destroyed and the workspace returns to ciphertext.
Lose your phone and the key goes with it
Reset or lose your phone and the KEK goes with it.
To re-enroll, a link is sent to the email address you signed up with. You then enter your secret recovery code on the Invisible Encrypted Keyboard, and the KEK is rebuilt. Without both, the workspace cannot be recovered, by you or by us.
Delete your account and the encrypted workspace and its DEK are destroyed. The KEK then has nothing left to open.
The lock covers everything you put inside
Everything you carry into the workspace, and everything you install there, is protected by the same lock.
Whether it deserves to be there is your call. What happens step by step, from login to logout: see Before Your Session.
On the roadmap
v2.1 adds Passkeys for Proof-of-Presence.
The KEK will not be released without it. You will also be able to enroll additional backup devices, each of which also requires your Proof-of-Presence.
ULTRA goes one step further.
You can host the workspace and its storage inside your own network or on your own device, so the encrypted data never leaves infrastructure you control. Planned for v2.4, or earlier by special request.