Skip to main content

Key Management

Keys handled with defence in depth

Strong encryption is only as good as its key management. LifeWyn wraps, escrows and releases keys through layered controls so your vault stays sealed until your rules — and only your rules — say otherwise.

Envelope encryption

Data keys encrypt your content, and those keys are themselves wrapped by higher-level keys. Rotating or revoking access means re-wrapping keys — never re-encrypting your entire vault.

Software key store today, not a managed KMS

Server-side wrapping currently uses a software key store: the wrapping key is held in the server's environment rather than in a hardware module or a managed KMS. The interface for a managed provider is in place, but it is not what the deployment runs today, and we would rather tell you that than imply a hardware boundary that is not there.

Shamir threshold escrow

For inheritance, a key is split into shares using Shamir's Secret Sharing over GF(2^8), and each share is encrypted to its recipient's public key. No single share reveals anything — only the threshold you choose, gathered from shares held apart, can reconstruct it.

Policy-gated release

A wrapped key is only released when your rules are satisfied — a verified inactivity period, nominee verification, and any executor approvals you configured. No policy, no key.

Your vault keys are not on our servers

The keys that decrypt your vault are derived on your device and are never sent to us. We orchestrate wrapping, escrow and release. Our own server-side wrapping key does live in the server environment — it protects stored key envelopes, and it does not decrypt your vault.

Recovery without a single point of failure

Splitting trust across threshold shares, your recovery phrase and your policy rules means there is no one secret whose loss locks you out or whose theft unlocks everything.

Questions about our key model?

Security and compliance teams are welcome to review how LifeWyn handles envelope encryption, escrow and recovery in detail.

Contact us