Vault Send Request How it works Security & Trust Pricing 🇬🇧 🇩🇪 🇫🇷
  • Send
  • Request
  • How it works
  • Security & Trust
  • Pricing
  • Trust Centre

    Every trust and compliance signal in one place.

    This hub bundles everything you need to assess Erseni Vault: how we secure your secrets, how we handle data, the measures we take, who processes data on our behalf, our live status and the limits we are honest about.

    Documents and pages

    Jump straight to the detailed pages behind each trust signal.

    Security & Trust

    Every security claim linked to the AGPL-3.0 source file, plus what the design does not protect against.

    Data protection

    Our privacy policy: what data we process, on which legal basis and for how long.

    Data Processing Agreement

    DPA under Art. 28 GDPR including technical and organisational measures and our deletion concept.

    Status

    Live operational metrics: active secrets, deployed build SHA, cryptography details and rate limits.

    How it works

    A step-by-step walkthrough of the zero-knowledge encryption flow.

    Build manifest

    The machine-readable manifest of the deployed build, so you can verify what is running.

    security.txt

    Our security contact and vulnerability disclosure details, per RFC 9116.

    Imprint

    The legal entity behind Erseni Vault and how to reach us.

    Pricing

    Free for personal use plus EU-hosted paid plans for teams. See all tiers.

    Technical and organisational measures (TOMs)

    The core measures that protect secrets handled by Erseni Vault.

    • Client-side, end-to-end encryption: secrets are encrypted in your browser before they ever reach the server.
    • Zero-knowledge server: the server only ever holds ciphertext and public keys, never plaintext or private keys.
    • Encryption in transit: all connections are served exclusively over TLS.
    • One-time, self-destructing links: a secret is deleted from the server once it has been retrieved.
    • No plaintext at rest: only encrypted payloads are stored, and only until retrieval or expiry.
    • Data minimisation: no account is required and we keep the metadata around a secret to a minimum.

    Subprocessors

    External providers that may process data on our behalf while operating the service.

    Hetzner Online GmbH Stripe Payments Europe, Ltd.

    Mail, analytics and error tracking run on instances we operate ourselves, with no third party involved:

    Stalwart Mail Server Matomo Analytics GitLab

    Full list of subprocessors with purpose, region and privacy notices: Subprocessors

    The complete and authoritative list of subprocessors is maintained in our Privacy Policy

    Anonymous use and the account mode

    Using Erseni Vault with an account is entirely optional and changes only which metadata we keep, never the content.

    • Anonymous use is the default and stays fully unlinked: no account is needed and nothing you send or request is tied to an identity.
    • If you sign in and use the dashboard, the server stores the token and status metadata (open, fulfilled, expired, with timestamps) of your own requests and links them to your account, never the content, which stays zero-knowledge and client-side encrypted.
    • This link is created only while you are signed in; anonymous sending and requesting remains completely unconnected.

    Known limitations

    We would rather be honest about the limits than overclaim. These are the ones you should be aware of.

    • You have to trust that the JavaScript delivered to your browser is the audited version; Subresource Integrity is not yet in place.
    • Metadata such as timing, approximate payload size and request logs remains visible to the server, even though the content is encrypted.
    • There has been no formal external security audit of the service yet.
    • End-to-end encryption cannot protect against a compromised device or browser at either end.
    Read the security details How it works
    Security & Trust Solutions Comparisons Pricing Status Source Privacy Policy DPA Imprint security.txt © 2026 Erseni Ltd. Zero-knowledge by design.