SECURITY

Orpeca is private by architecture, not by policy.

Orpeca deliberately separates the service that knows who you are from the trusted devices that can read your documents.

Trusted devices control access

A random Root Key is protected by platform hardware security. Normal use never asks you to memorize it.

Accounts cannot decrypt documents

Email and password identify you for pairing, invitations, billing, and analytics. They do not deliver document keys.

Relay, not hosted Vault

Encrypted frames move between authorized devices and expire after acknowledgement or a short timeout.

Browser sessions fail closed

Sign-out, expiry, or revocation clears temporary browser session material and requires approval again.

DataWhere it livesCan Orpeca read it?
Document contentTrusted devicesNo
Root and document keysProtected device storageNo
Account identityOrpeca control planeYes
Transient relay framesShort-lived relayNo

START ON YOUR DEVICE

Your account coordinates access. Your devices keep control.

Get Orpeca