Security
Brightery Vault is a password, OTP, private-note and encrypted-file vault operated as a Brightery product. It never pretends to be Google, Facebook, a browser, a bank, or another password service.
Data protection
Vault payloads are encrypted with authenticated XChaCha20-Poly1305 encryption. Long-lived API/device credentials are stored as hashes. Web sessions use secure HttpOnly cookies, CSRF protection and rate limiting.
Device access
Chrome, Firefox and Android clients use an explicit device-pairing approval screen. A device receives a revocable token only after the signed-in account owner approves it.
Report a security issue
Use the Support page to contact Brightery. Never send vault passwords, OTP secrets or recovery codes in a support message.