Security model

Use the right protection for the right information.

Guidance and high-sensitivity secrets do not require the same security model, so CAPSULENE provides two Capsule types. This page explains exactly what each one protects, what CAPSULENE can and cannot read, and how your account itself is secured.

Security model

Two Capsule types. Two security models.

Never put passwords, seed phrases, or private keys in a Text Capsule. Use a Key holder for anything that grants access to money or accounts.

Text Capsule

For guidance, instructions, messages, and context

Encrypted in transit and at rest. CAPSULENE processes the content so it can be delivered to the recipient you chose.

  • Rich-text or plain-text content, up to 32 KiB
  • Encrypted in storage under a service-held key
  • Delivered as a link the recipient opens — no account needed

Not zero-knowledge: in principle CAPSULENE’s systems can access the content. Keep passwords, seed phrases, and private keys out of Text Capsules.

Key holderZero-knowledge

For high-sensitivity secret material

Encrypted on your device and protected by 2-of-3 key sharing. CAPSULENE cannot decrypt the protected secret by itself.

  • AES-256-GCM in your browser via the Web Crypto API
  • The key splits into three shares: yours, your recipient’s, and one for CAPSULENE
  • Any two shares open it; a single share reveals nothing

CAPSULENE holds one share and the ciphertext. Stored server data alone cannot decrypt the secret — recovery requires your share or your recipient’s.

Key holder · zero-knowledge

Split apart before it ever leaves your device.

A Key holder is encrypted in your browser and its key is split into three shares. CAPSULENE keeps one share and the ciphertext — so stored server data alone cannot decrypt the secret, and recovery always needs your share or your recipient’s.

AES-256-GCM envelope encryption

A random 256-bit data key seals your secret with authenticated AES-GCM in your browser. CAPSULENE stores only the sealed envelope — never its contents.

Shamir’s Secret Sharing · 2-of-3

Threshold cryptography over the GF(256) finite field splits the data key into three shares. Two reconstruct it; one alone is mathematically useless.

Three holders, never pooled

You keep one share, your recipient keeps one, CAPSULENE keeps one. No single holder — and no single server — can open the Capsule alone.

Client-side, end-to-end for this type

Encryption and decryption run in your browser via the Web Crypto API. The plaintext of a Key holder never crosses the network.

Audited secret-sharing library

The key splitting uses Privy’s Shamir secret-sharing library, independently audited by Cure53 and Zellic. Shares export as portable SLIP-39 recovery words.

Files sealed on your device

A Key holder can also encrypt whole files locally. The encrypted files are never uploaded — you store them where you choose, and only the shares open them.

Works even if CAPSULENE disappears

A self-contained offline decryptor — one HTML file built from the same code as the app — opens your encrypted files and shares with no internet and no CAPSULENE.

Want the mechanics step by step? Read the key-share exchange in the guide → · Shamir’s Secret Sharing, explained →

Encrypted files

Files stay on your device. Always.

A Key holder can encrypt whole files — documents, a keystore, a video message — under the same 2-of-3 shares. Each file gets its own random key, wrapped by the Capsule’s key, and is encrypted in authenticated chunks so any tampering is detected. The encrypted files are never uploaded: you store them wherever you trust, and only the shares open them. Your recipient decrypts them on the delivery page with no account, and a self-contained offline decryptor keeps them openable even without CAPSULENE.

See the step-by-step guide →

Your account

The account is protected too.

Sign-in uses one-time e-mail codes, Google, or a passkey — there is no reusable CAPSULENE password to leak.

Passkey sign-in (WebAuthn)

Sign in with your device’s fingerprint, face, or PIN. Passkeys are phishing-resistant public-key credentials and always additive: e-mail codes and Google keep working. Up to five per account.

Authenticator-app 2FA

An opt-in TOTP second factor gates sign-in — at every login or once a day, your choice. Codes live in your authenticator app.

Single-use recovery codes

Eight one-time backup codes, shown exactly once and stored only as hashes. The lost-phone escape hatch that never weakens the lock.

Backup e-mail recovery

A backup address is the only way back into your account if you lose your primary e-mail. Recovery through it is deliberately slow and visible: a 48-hour window your usual address can cancel.

Login-required check-ins

For the most sensitive Capsules, a check-in only counts after signing in with two-factor authentication — so access to your mailbox alone cannot fake that you are available.

Payments by Stripe

Stripe acts as merchant of record and handles cards, invoices, and applicable taxes at checkout. CAPSULENE never sees or stores your card details.

Transparency

What we have not done yet.

Independent audit. CAPSULENE itself has not yet had an independent product audit. The Shamir library behind Key holders has (Cure53 and Zellic). An audit of the full product is on our roadmap, and we would rather say so than let you assume otherwise.

Questions about the model? Security FAQ → · support@capsulene.com

Protection for the secret. Continuity for everything around it.

Create a Text Capsule for the guidance, and a Key holder only for what truly needs zero-knowledge.

One thing that matters
  • One account, one wallet, one instruction
CAPSULENE Continuity layer
  • Recipient
  • Conditions
Yours to control until then
Trusted recipient
  • Delivered

The right guidance, to the right person, at the right time.

One account, one wallet, one instruction flow into the CAPSULENE continuity layer, where recipient and conditions are defined and yours to control until then. Condition met: delivered. The right guidance, to the right person, at the right time.