AES-GCM
Authenticated encryption in the browser. Plaintext files are not uploaded.

Architecture
Files are encrypted in the browser with authenticated AES-GCM before upload. Integrity is checked on decrypt. Vault keys are wrapped with a key derived from your passphrase on your device. We never receive the passphrase.
Server-side storage is ciphertext. We cannot open your files. Account email and operational metadata are still ours to hold. That is not “no data even when compelled.”
Authenticated encryption in the browser. Plaintext files are not uploaded.
Your passphrase wraps the vault key locally. Losing it means we cannot recover the vault.
Account email, ciphertext blobs, and operational logs. We say this out loud.
What we can honestly say
There is no security whitepaper or audit PDF on this site. Report a concern anytime at admin@verndr.com. The web vault is invitation-only Alpha.