Security

Clear boundaries are part of the protection.

Locoris explains what stays local, what is encrypted, what metadata a service may need and what recovery can or cannot do.

Private vaults

Encryption starts before hosted storage.

Private vault content is encrypted by the client before it is sent to Locoris Cloud. The interface must make lock state and recovery limits visible before users depend on them.

Encryption guide
Locoris private vault security state
Protection mode, synchronization state and recovery boundaries are visible at the point of use.

Local by default

Installed apps create and use vaults on the device. An account is not required for the local workspace.

Client-side encryption

Private vault content is encrypted before hosted synchronization and decrypted by authorized clients.

Metadata is documented

Account, billing, device and operational metadata needed by the service is not described as zero knowledge.

Recovery has limits

A forgotten private-vault secret can make encrypted content unrecoverable. The product must say so at the decision point.

Backups remain separate

Precise Locoris backups and readable exports protect against different failure modes and should both be used.

Responsible reporting

Reports should include affected version, platform, reproduction steps and a safe proof of impact.