Security
Account:dir is built to give you a connected view of your accounts while protecting the secrets you choose to store. This page explains the security design we can describe publicly; it is not a promise that risk has been eliminated.
Vault encryption
Passwords, API keys, and other secrets saved in the vault are encrypted in your browser before upload with AES-GCM. A passphrase-based process uses PBKDF2 with 600,000 iterations and envelope encryption. The master key remains in browser memory during use, and your passphrase is not sent to our servers. We store encrypted vault content and cannot recover its plaintext for you through ordinary support access.
If you lose both your passphrase and recovery key, your encrypted secrets may be unrecoverable. Keep the recovery key in a separate safe place. We will never ask you to send us your passphrase, recovery key, or a saved secret by email or support message.
Account records and payments
Vault protection applies to secret content. Details used to connect accounts to providers, emails, projects, tags, costs, and renewals are processed separately so the Service can search and summarize them. See the Privacy Policy for those categories and how they are used.
Payments are processed by Stripe. Account:dir does not store full payment card numbers in its application database.
Your part in keeping the account safe
Use a unique sign-in password, a strong vault passphrase, and a device you trust. Protect your recovery key and review who can access your device and email account. If you suspect compromise, change your sign-in credentials using the available account controls and contact security@accountdir.com. We can help investigate account access, but we cannot decrypt vault secrets without your passphrase or recovery key.
Reporting a security issue
We welcome responsible reports through security@accountdir.com. See our Vulnerability Disclosure Policy for scope and reporting guidance.