We designed Celestial so that trusting us requires as little faith as possible. Here is exactly how your data is protected — no marketing hand-waving, just the cryptography.
Zero-knowledge means the encryption keys that protect your vault are derived from, and controlled by, you — never us. Your master password is never transmitted to our servers, never stored, and never recoverable. What we hold on your behalf is a blob of ciphertext that is mathematically useless without your key.
If an attacker breached every server we own, exfiltrated every database, and read every log line, they would still find nothing but random-looking bytes. That is the design.
You can watch a faithful version of this pipeline run in your own browser on the Open Vault page — it uses the exact same Web Crypto primitives (PBKDF2 + AES-GCM) described above.
Optional two-factor authentication (TOTP, WebAuthn hardware keys, or passkeys), login anomaly detection, device approval, and configurable session timeouts.
Hosted on ISO 27001-certified EU data centres, isolated networks, encrypted-at-rest storage, least-privilege access, and 24/7 monitoring with tamper-evident audit logging.
Mandatory code review, automated dependency and secret scanning, signed releases, reproducible builds, and a documented incident-response runbook.
A 28-character recovery key generated at signup lets you regain access if you forget your master password — held only by you, never by us.
Trust should be earned and checked. Celestial's cryptographic core and infrastructure are reviewed by independent third parties, and we align our controls with recognised standards:
Security researchers are partners, not adversaries. If you believe you've found a vulnerability, email contact@celestialdatavault.com with the subject line [SECURITY]. We acknowledge reports within 48 hours, work with you on a fix, and reward qualifying findings. Please give us reasonable time to remediate before any public disclosure.
We publish a live system status page, notify affected users of any security incident without delay, and will never introduce a backdoor, master key, or key-escrow mechanism. If that ever changed, our zero-knowledge design would make it impossible to do so silently — and we'd tell you first.
We're happy to walk compliance, legal and security teams through every detail.
Contact security →