Security

How your key works, and what we can see

A security product should never overclaim. This page explains the design in plain words, lists what our servers can read for each part of Atrium, and says where the protection stops.

The key, in plain words

  1. Your master password stays on your device. Your browser turns it into a key using Argon2id, a deliberately slow function that makes guessing expensive. We receive only a value derived from it that lets us confirm you typed it correctly. That value can't decrypt anything.
  2. That key unlocks your account key. Your account key is random and is stored on our servers only in encrypted ("wrapped") form. It is unwrapped in your browser's memory when you unlock.
  3. The account key unlocks everything else. Each vault, notes workspace and calendar has its own key, and each vault item and note has its own key beneath that. Content is encrypted with AES-256-GCM.
  4. By default, keys live in memory only. They are never written to disk, and they are dropped when the vault locks: after 15 minutes idle, or when you close the tab. You can choose Keep this browser unlocked for longer instead (12 hours up to 90 days, or while signed in). Turning that on stores a device-bound key in your browser — generated so it can never be exported, even by our own code — plus a matching encrypted envelope on our server; together the two reopen your vault without your master password, and the vault survives closing the tab. Anyone using this signed-in, unlocked browser can open your vault, so only choose it on a device you trust. See Auto-lock and the clipboard.

Sharing (inside a Family, Business or Enterprise team) uses public-key encryption: to share, your device seals the item's key to the other person's public key, and only their device can open it. Our servers pass the sealed box along without being able to open it.

What our servers can and cannot see

PartWe can seeWe cannot see
AccountYour email address, sign-in times, devices and sessions, plan and billing recordsYour master password, your keys
VaultHow many items you have and their rough type, sizes, timestamps, folder and sharing structure, schedules, audit eventsItem names, usernames, passwords, authenticator keys, notes, file names and file contents
NotesHow your folders nest, sizes, when notes change, version count, whether a note is sharedNote titles, file names, text, tags, links and attachments
CalendarEvent start and end times, repeat rules, reminder times, calendar colours. Calendars you subscribe to by link (including holiday calendars) come from outside, so our server fetches them and can read them; they are stored encrypted with our key, not yoursTitles and details of events in your own calendars, including events you import from ICS files
External calendarsCalendars and events you connect from Google, Microsoft or CalDAV — fetched by our servers and stored encrypted with our key, not yours, so they can stay in syncNothing beyond what's already visible in those external calendars
TeamsThat a sealed copy of each member's account key is held for the team's owner, when it was made and whether it's currentThe key inside it: only the owner's private key opens it, and we release it to them only when they remove that member or close the account
Accounts for childrenThat a Family owner holds a sealed recovery copy of a child's account key, and every recovery started or completedThe child's content: the recovery copy opens only on the owner's device, through a 24-hour recovery the child is emailed about
SupportOur support team can view your account's settings and records read-only. If the account owner turns support access on, they can also make changes and sign in as the owner; every grant and support session is recorded and emailed to youYour keys and anything encrypted with them — support tools have no way to decrypt
Keep-unlockedWhether you've turned on "Keep this browser unlocked" and for how longThe device key that opens it — it never leaves your browser and can't be exported, even by us
ListsHow many lists and items you have, whether each item is done and when it was checked off, due dates, repeat rules and priority, who an item is assigned to in a shared list, and the kind of listList and item names, quantities, notes and links
ContactsHow many contacts and groups you have, their record type, sizes, timestamps and sharing structureNames, numbers, addresses, birthdays and notes
BudgetsHow many accounts, transactions and bills you have, their record type, sizes, timestamps and sharing structureAmounts, payees, categories, balances and notes
PollsQuestions and ballots, so we can run the page and tally resultsWho cast which ballot, when a poll is set to anonymous
InvitationsRSVP status, headcount and your guest list, so we can enforce capacity and send remindersMeal choices, dietary needs and answers to your own questions — sealed in the guest's browser
RegistryItem details and claims, so the public page can show what's still availableYour private notes and thank-you drafts
FormsStandard-mode answers, so routing, search and exports work. Private-mode file uploads too — encrypting those is a known gap, not yet fixedPrivate-mode text answers, sealed to your reviewers
BookingYour booking page and its types (public by design), your working hours, and a guest's name and email for long enough to send a confirmationThe guest's answers to your own questions, sealed to your key

Polls, Invitations, Registry and Forms are built to be opened by people who don't have an account, so our servers read more for them than for the vault, notes and calendar. More detail on each: What we can and cannot see and the product page.

Event times are readable to us on purpose: without them we could not send reminders or work out repeating events. Reminder emails contain the time only, never the title.

Schedules on time-locked items are readable too, because our server enforces them with its own clock. It holds an extra lock layer on a scheduled item and removes it only inside the window. That layer controls when an item can open; it can't decrypt the item.

Importing and exporting the vault happen the same way: a file you import is parsed in your browser and every item is encrypted before it's uploaded, and an export is decrypted in your browser and written straight to your disk. Either way the plaintext never reaches us. More detail: Importing and exporting your vault.

What this protects against

  • A stolen copy of our database or backups: it contains ciphertext and wrapped keys.
  • Our own staff and administrators: our admin tools have no way to decrypt your data.
  • Someone reading traffic between you and us: only ciphertext crosses the wire, inside TLS.

Where the protection stops

  1. Tampered code from our server. Like any encrypted web app, the Atrium web app runs code our server sends to your browser. If that code were tampered with, it could capture your master password as you type it. We reduce this risk with a strict Content Security Policy and by never receiving your password or keys, but we do not claim it is solved. The browser extension (available as a direct download; store listings are pending) helps here: its code is installed on your computer rather than downloaded from us on each visit.
  2. A compromised device. Malware, a keylogger or a malicious browser extension on your device can see what you see and type. No password manager can defend against that.
  3. A weak master password. Argon2id makes guessing slow, and the setup screen shows password strength, but a guessable password is still guessable.
  4. Things you've already seen. Once a time-locked item opens, or a shared item is read, the information can be copied. Time-locking controls the app, not memory. Opening a scheduled item also needs a connection to our server during its window.
  5. Lost master password and lost Recovery Kit. If you lose both, your data cannot be recovered by anyone, including us. This is the price of having no back door.
  6. A team owner's copy of your key. In a Family, Business or Enterprise team, your device seals a copy of your account key to the team's owner and signs it. Our servers hold it under a second layer and release it to the owner only if they remove you or close the account; then what you stored in the team becomes theirs to review. That rule is enforced by our servers, not by encryption: someone in full control of our servers, working with the owner, could release it early. You're told this before you join, and every release is recorded in the audit log.

Recovery

At setup you save a Recovery Kit, as a text file or a QR code. It holds a recovery key that can unwrap your account key, so you can set a new master password if you forget the old one. Using it also removes any passkey unlock you had set up, so you'll re-add those afterwards. Keep the kit somewhere safe and offline, away from the device it protects.

There is no override for our staff or for team admins. There are two exceptions, both disclosed before they apply. The team owner's sealed copy of each member's key, described above, opens only after that member is removed or the account is closed, and only for the owner. And on a Family account, the owner holds a sealed recovery copy for each account they set up for a child, so they can help the child back in; that recovery takes 24 hours, the child is emailed when it starts, and the child then chooses a new master password and Recovery Kit. A member who loses both their master password and their Recovery Kit while still a member can't be recovered by anyone. Shared vaults are the way to make sure a team keeps access to what it needs.

More detail: Your Recovery Kit and What we can and cannot see.

Reporting a vulnerability

If you've found a security problem, please tell us through the contact form and put "security" in your message. We'll prioritise it.

One platform, every app, one extremely affordable price.

Try Atrium free for 14 days. No card and nothing charged when the trial ends; subscribe within a day of it ending to keep your data. Your notes and calendars export in open formats.

How we protect it