Security architecture

Your backup should stay yours.

VaultMyPhone is built so the mobile app talks to your VaultMyPhone server, not directly to permanent infrastructure credentials.

On-device encryption

Backup objects use AES-256-GCM encryption before they are uploaded. Integrity metadata is calculated for encrypted objects.

Short-lived access

The server issues short-lived signed upload/restore URLs. Permanent object-storage secrets stay on the server.

Recovery keys

The Android app requires customers to save and confirm their recovery key before encrypted backups begin.

Biometric lock

The mobile app can require biometric or device-credential authentication before opening backup and recovery settings.

Device revocation

Customers can revoke a registered device, invalidate its API sessions and stop backup access from that device.

Account deletion

VaultMyPhone provides both in-app deletion requests and a public web deletion resource.