Skip to content

Security Policy

Last updated: 2025

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability in Ironlox, please report it to [email protected].

Encryption Standards

All vault data is encrypted with AES-256-GCM before leaving the client device. Key derivation uses Argon2id (memory-hard, GPU-resistant). The server receives only encrypted blobs and a separate authentication hash derived with a different salt. The server never has access to plaintext data, master passwords, or encryption keys under any circumstances.

Infrastructure Security

Supply Chain

We minimize third-party dependencies, particularly in the crypto package. All encryption uses the Web Crypto API (SubtleCrypto) — no third-party crypto libraries. Dependencies are pinned to exact versions and reviewed during updates.

PGP Key

You may encrypt sensitive reports to our PGP key. Download it below or fetch from keys.openpgp.org.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGdM3oMBEAC9Y5kq3F8xPm7R2jVvK6wHnT4sB1xWpL8mN9yQ0aF3dG5h
I7jK0lM3nO1pQ2rS4tU6vW8xY0zA2B4cD6eF8gH0iJ2kL4mN6oP0qR2sT4uV6
wX8yZ0aB2cD4eF6gH8iJ0kL2mN4oP6qR0sT2uV4wX6yZ0aB2cD4eF6gH8iJ
(placeholder — replace with real key before production)
-----END PGP PUBLIC KEY BLOCK-----

Fingerprint: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000

For reports that don't require encryption, use [email protected].