Trust is not a color.
It is a receipt.

We hold ciphertext. Your passphrase, device keys, and recovery codes are never transmitted in the clear. What follows describes — in plain terms — what Vestry can and cannot do with your documents.


§ 01

Encryption & key management

Encrypted on your device. Before it ever reaches us.

Documents are encrypted client-side using AES-256-GCM and XChaCha20-Poly1305. Each document has its own key, wrapped by an account-level key derived from your passphrase. The server stores ciphertext only. Keys rotate every 90 days.

Documents are content-addressed, versioned, and cryptographically signed for tamper detection. A document's identity is its contents — not a row in a database.


§ 02

Authentication & device security

Passkeys, by default.

New devices require a second factor. Sessions expire after 30 minutes of inactivity or 12 hours absolute. We don't make you log in every day — and we don't let a forgotten laptop stay open forever.

Account recovery uses a 2-of-3 Shamir secret split: any two of a trusted device, a printed recovery kit, or a named steward. No phone call to support can let you back in. That is deliberate.


§ 03

Data residency & infrastructure

United States, partitioned by state.

U.S. vaults default to U.S. regions, with state-level partitioning for California, New York, Texas, and Washington. Infrastructure runs on AWS and is audited by Vanta.

Deleted documents undergo a 30-day cryptographic shred. We give you a receipt when destruction is complete.


§ 04

Audit & transparency

Every view, on the record.

All activity — views, shares, key rotations, steward changes — appears in your audit log within 60 minutes. Unusual activity triggers an email alert. The audit log is a property of the vault; it cannot be edited by us.

If Vestry is subpoenaed, we can provide only encrypted data. We cannot decrypt it. Beginning Q1 2027, we will publish transparency reports describing the volume and outcomes of any such requests.


§ 05

Compliance roadmap

What we have done. What we are doing.

WhenWhat
LiveEncryption at rest & in transit · quarterly access reviews · incident response procedures
Q2 2026External penetration testing
Q3 2026SOC 2 Type I certification (AICPA TSC framework)
Q1 2027Customer-facing transparency reports on government requests