M&A. Capital raising. Diligence. Sealed in your browser before it is uploaded, so what we store is ciphertext and what we hold is nothing.

What the platform can and cannot do
0
keys held by the server
A Vault is sealed in your browser. A database dump reads as ciphertext.
AES-256
GCM on every document
Authenticated encryption. Tampering is refused, never silently accepted.
ML-KEM-1024
plus P-384, on every shared key
The post-quantum hybrid ASD's ISM wants in new software by 2030.
600,000
PBKDF2-SHA512 rounds
Behind a vault password. Or a passkey, or a recovery code.
What we can still see: how many documents a room holds, roughly how large they are, when they were added and opened, and the email address of everyone invited. Use a code name for the deal, which is what the room shows by default.
GuardStein Deal Room
A conventional data room asks you to trust that its staff will not look. This one cannot.
Documents live in bundles, the unit you disclose. Each bundle has its own key, and letting someone in means wrapping that key to them. There is no permission flag to misconfigure.
A reviewer opens a link and reads. The link identifies them and decrypts nothing; a passphrase sent by a second channel does the decrypting, and never reaches us.
PDFs, Word, spreadsheets and decks open in the browser, watermarked with the reader and the time. Every open is logged in a hash-chained trail, guests included.
Named people read a document and agree to a sentence, signing over the document they decrypted in their own tab, with a drawn mark and each place on the page inside the signature.
Name one document as the NDA and nobody on the other side receives a key for anything else until their NDA ceremony completes. A screen that forgot to ask would have nothing to show.
Export a signed copy and anyone can check every signature offline. One click more confirms the keys, the ceremony and our own countersignature on the record.
Who you are, and who can open what
Signing in and opening a Vault are two different locks, because the server that knows who you are still cannot decrypt for you.
Live, in your browser
Exactly what a Vault does when you save a note and when you share it.
Type a secret, seal it, and see the envelope byte for byte as our servers would store it. Then wrap that key to a reviewer with ML-KEM-1024, the way a deal room shares a document key, and watch them open it without ever learning your passphrase. Nothing is sent.
Your browser: plaintext
Type a secret and a passphrase. Encryption happens here, on your device. The plaintext never leaves this tab.
Server storage: sealed
Ciphertext only. No key ever leaves your browser, so this is all we could ever hand to anyone, or lose in a breach.
bbv1: envelope.A Vault’s decryption key is derived on your device at unlock, from the authenticator itself, and is never written to the passkey sync, the browser’s credential store, or our servers. The attacks that recover synced passkeys steal a passkey’s sign-in key, which is a different secret. On a Vault, that is at worst a sign-in problem, never a decryption one.
The code that holds your keys runs in your browser, and we serve it. A build altered after it left our pipeline could read what the page decrypts. That is true of every end-to-end encrypted product with a web client, and we would rather say it than imply otherwise. Every script carries an integrity hash so a modified file is refused, the exact build running is shown inside the product with its commit, and the cryptography is in the open on this page so it can be checked against what ships.
GuardStein Notes
Plain Markdown with front matter, and a link graph that builds itself from [[wikilinks]] and unlinked mentions.
GuardStein NotesSticky notes and connectors, merged without conflicts, live presence.
Live boardsDescribe an architecture and get an editable draw.io diagram.
AI diagramsSealed in your browser before storage. The server keeps ciphertext and no key.
End-to-end encryptionAn expiry, a code to one named address, and a log of every open.
Share linksClaude Code and Claude Desktop through the MCP server, no keys to copy.
MCP integrationA print-styled PDF with every diagram drawn properly.
PDF exportReal files into Teams, Miro boards alongside, your own S3 bucket.
IntegrationsTransparent pricing
Personal
Freeforever
Premium
A$10per seat, per month
If a subscription lapses, a workspace becomes read-only, never deleted.
Sealed in the browser, signed in the browser, verified by anyone. Discover how a deal gets done without a key ever leaving your side.