Skip to content
Vando

Security

One failure shouldn’t become every failure.

No system is unbreakable, and we won’t claim ours is. Vando is designed so that losing one thing, your phone, a password, even our servers, doesn’t hand over everything. These are the design goals for the first release; the full security design will be published before anyone is asked to trust it with real secrets.

What we’re building in

If something goes wrong

What happensWhat it could getWhat stops the rest
Your phone is stolen, unlockedItems locked with only your face or passcodeItems that also need your key, a person or a wait. Cut the phone off from any computer.
Our servers are breachedScrambled vault copies and account detailsNo key to open them; approvals need your phone’s signature.
Your email is taken overAlerts and the ability to start a recoveryRecovery needs your kit, a device or your people, and waits while your devices can cancel.
An AI agent goes rogueWhat you let it do without askingRisky actions and secrets ask your phone; pause cancels everything at once.
Someone fakes your mum’s voiceYour trust, if you don’t check“Is this really Mum?” asks her phone, not her voice.

Honest limits: a Vando app update we ship could be malicious; someone who knows your phone passcode can open anything locked only with it; and a secret shown to a person can’t be un-shown. The design says each of these out loud where it matters.

What if Vando disappears?

Your data is yours. You can export everything, any time, in open formats, and your recovery kit works without us. We’d rather you trust us because leaving is easy.

Built on the platform, not around it

Face ID and fingerprints are your phone’s own. Keys live in its secure chip. We don’t store biometrics, and we don’t use voice as proof.