Security

Don't take our word for it.
Watch the journey.

Your most sensitive data is protected by architecture, not promises. Follow a record from your device to the cloud and back — hover any stage to see exactly what happens to it.

End-to-end, step by step

The path of one record.

Hover or tap a stage. Nothing leaves your device until it's already encrypted.

on your device — plaintext

It starts — and stays — local.

Your portfolio, journal, notes and any broker/exchange API keys are written to local storage on the device you're using. This is the only place the plaintext ever exists in a form anything can read.

key derivation — on device

The key comes from your passphrase — and never leaves.

An encryption key is derived from your passphrase on your device. Your passphrase is never uploaded, and neither is the key derived from it. If you lose your passphrase, we cannot recover your end-to-end encrypted data — because we never had the means to.

encrypt — before any upload

Sealed with AES-256, on your device.

Before a single byte is sent, the record is encrypted on your device with AES-256. What leaves is a sealed envelope. The plaintext never crosses the network.

what actually travels

Only ciphertext travels.

The payload on the wire is ciphertext plus the minimal metadata needed to route and version it — timestamps and record identifiers. Without your key it is unreadable.

enc:v1 · 9f2a7c…e14b · aes-256-gcm · nonce=…

server — zero-knowledge

The server stores what it cannot read.

Our servers store the encrypted blob. We do not hold the key needed to decrypt it, so we cannot read your synced portfolio, journal, or API keys. The server's answer to "can you read this?" is false.

your other device — decrypt

Decrypted only where you hold the key.

On your other device — where your passphrase can derive the same key — the envelope is decrypted locally. The plaintext reappears only on hardware you control.

What this guarantees

Five properties, by design.

Plaintext never leaves

Encryption happens on your device before upload. The network only ever carries ciphertext.

Server stores ciphertext

We store encrypted blobs and minimal routing metadata — never readable content.

Passphrase never uploaded

Your passphrase and the key derived from it stay on your device. We can't recover them — or your data — if you lose them.

Device revocation

Remove a device from your account to stop it syncing. See your active devices in the app.

Key rotation

Change your passphrase to re-key your encrypted data, so old keys no longer apply going forward.

Broker keys stay put

Broker/exchange API keys are stored on-device and are never used to place real-money trades. Draft-only, always.

Honest by design

What we don't claim.

No system is perfectly secure. You are responsible for protecting your device, your credentials and your recovery keys. We use standard, well-understood cryptography — we don't invent our own, and we don't claim certifications we don't hold.

Payments are processed by Stripe; we don't store your full card details.

Responsible disclosure

Found a vulnerability? We want to hear from you. Email security@buildyourpocket.com and give us a reasonable chance to fix it before public disclosure.

Privacy or data requests: privacy@buildyourpocket.com. See the privacy policy and encrypted sync.

Security you can watch, not just trust.

Local-first, end-to-end encrypted, draft-only. Open the app and turn on sync when you're ready.