How HeroVault Works

HeroVault is built around one idea: you should be the only one who can unlock your vault. Not us. Not anyone else.

01

Client-side encryption

Your vault is encrypted before it leaves your device

Everything is encrypted fully client-side using AES-256-GCM. We never receive unencrypted vault data, and we never store your encryption keys.

What this means:

Your secrets are unreadable to HeroVault
A server breach can't reveal your passwords
Decryption happens only on your device
02

Key fragmentation

No single key to steal

Instead of relying on a single "master key", HeroVault splits the vault key into fragments using Shamir's Secret Sharing (SSS).

What this means:

A fragment alone is useless
Multiple fragments are required to reconstruct the key
No single system can expose your vault
03

NFT Access Key

Your NFT is the authorization layer

Your NFT acts as the proof that you're the rightful owner of the vault. Only NFT ownership can authorize the reconstruction of the fragments needed to unlock your data.

This authorization mechanism is built on Ternoa, a blockchain infrastructure designed for secure data ownership. Ternoa’s protocol has been independently audited, providing a robust foundation for NFT-based access control.

What this means:

No master password to remember or leak
Access is tied to ownership, not a secret you can copy
Unlocking is cryptographic, not trust-based
04

Backup & recovery

Recovery is real — but sovereignty has a cost

During setup, you download a backup file. This backup is required to restore access later.

Important: If you lose your backup and you lose access to your NFT, we cannot recover your vault. That's the tradeoff of true zero-knowledge sovereignty.

05

Storage on private IPFS

Your encrypted vault isn't trapped on our servers

Your encrypted vault is stored on a private IPFS network (distributed nodes). Even if HeroVault disappears, your encrypted vault remains available.

What this means:

No central storage lock-in
Your vault stays portable and resilient
Only you can decrypt it anyway
06

Email Aliasing

Hide your real email everywhere

HeroVault includes email aliasing powered by HeroMail:

What this means:

Create a unique alias for every service
Emails sent to aliases are automatically forwarded to your real inbox
No mailbox to manage, no inbox stored
Disable any alias instantly to stop spam or tracking
07

Autofill

Autofill that's built to be reliable

HeroVault focuses on reliable autofill for login forms. We use lightweight AI-enhanced detection to improve recognition without slowing down your browser.

Be the hero of your data

No master password. No central authority. Just you and your vault. Join the beta and take control.