Changelog ·
Zero-knowledge files: we can’t read them anymore
Your files, folders and product variables are now encrypted and signed in your browser before they reach us. We store and deliver them, but we hold no key that opens them.
Why we built it
Until today your files were encrypted on our servers, with keys our servers also held. That is how most file hosting works, and it means you have to trust the host. A privacy-first platform shouldn’t ask for that trust, so we made it technically impossible for us to read your content. A database leak, a stolen backup or a legal demand now gets encrypted data, not your builds.
What changed
- Your browser encrypts and signs every file, folder and product variable before upload.
- Three locks: end-to-end encryption with keys only you, your approved team and your app hold; a second lock at rest with a server key kept outside the database and backups; and a new one-time key for every download.
- Every upload is signed. The C++ SDK refuses any file your team didn’t sign, even one from our servers.
- Team members get their own keys. You compare a fingerprint and give access; Vaultix never does it for you.
- Your password no longer reaches us. Your browser sends a value derived from it and unlocks your keys locally.
- IsValidFileHash compares a keyed hash, so we never learn your files’ checksums.
What it brings you
- Your builds and configuration stay yours, even if our servers are breached.
- Nobody can swap a file on its way to your customers.
- Captured downloads are useless, and a key pulled from your app isn’t enough on its own.
- Nothing changes for your customers: the SDK decrypts in memory, so nothing extra lands on disk.
What to do now
Everyone
- Sign in to the dashboard once. Your browser sets up your personal keys.
New apps
- Encryption is on from the start. Save the 24-word recovery phrase when asked.
- Copy the SDK key (vxk_…) from App Settings → End-to-end encryption and add it with SetContentKey.
Existing apps
They keep working exactly as before. To turn encryption on:
- Update your app to the new C++ SDK. It works with your current files too.
- Turn on end-to-end encryption in App Settings, save the recovery phrase and copy the SDK key.
- Ship a build with SetContentKey. Files uploaded from now on need this build.
- Once your users have it, click Re-encrypt now to move older files over. The old copies are deleted afterwards.
Team members
- They sign in once and see their key’s fingerprint.
- The owner compares it in App Settings → End-to-end encryption and clicks Give access.
client.SetApiKey("ap_your_app_key");
client.SetContentKey("vxk_your_sdk_key"); // App Settings → End-to-end encryption
Also in this release
- The documentation is public, with one address per page and the same search as the dashboard (Ctrl K).
- Feature pages explain each part of Vaultix in detail.
- Old versions of replaced files are deleted for good after 8 days.
How end-to-end encryption works · C++ SDK reference · Zero-knowledge file delivery