Local by default
Installed apps create and use vaults on the device. An account is not required for the local workspace.
Security
Locoris explains what stays local, what is encrypted, what metadata a service may need and what recovery can or cannot do.
Private vaults
Private vault content is encrypted by the client before it is sent to Locoris Cloud. The interface must make lock state and recovery limits visible before users depend on them.
Encryption guideInstalled apps create and use vaults on the device. An account is not required for the local workspace.
Private vault content is encrypted before hosted synchronization and decrypted by authorized clients.
Account, billing, device and operational metadata needed by the service is not described as zero knowledge.
A forgotten private-vault secret can make encrypted content unrecoverable. The product must say so at the decision point.
Precise Locoris backups and readable exports protect against different failure modes and should both be used.
Reports should include affected version, platform, reproduction steps and a safe proof of impact.