Hybrid key establishment
ML-KEM-768 and ephemeral P-256 ECDH create independent shared secrets. MystSafe combines them and binds the result to the intended vault, devices, object, and purpose.
Quantum-safe security
MystSafe combines NIST-standardized post-quantum algorithms with established classical cryptography. Every trusted device creates its own keys, encrypts secret payloads locally, and rejects updates that fail the expected cryptographic checks.
Hybrid by design
Post-quantum and classical protections are both part of the design. Key establishment combines two independent shared-secret paths, while security-sensitive updates must pass both signature paths.
Post-quantum layerNIST-standardized algorithms
Classical layerEstablished cryptography
One authenticated envelopeEncrypted device-to-device update
ML-KEM-768 and ephemeral P-256 ECDH create independent shared secrets. MystSafe combines them and binds the result to the intended vault, devices, object, and purpose.
ML-DSA-65 and ECDSA P-256 sign the same security context. A protected update is accepted only when both signatures and the expected device identities verify.
AES-256-GCM protects secret payloads and wrapped content keys. Fresh nonces and SHA3-256 commitments help bind integrity to the exact protocol content.
More than algorithm names
The cryptography is reinforced by per-device keys, strict update verification, and operating-system-protected access.
Every device generates independent encryption and signing identities. Existing private device keys are not copied to a newly paired device.
Recipients check the expected vault, object, signer, trusted-device state, integrity, and freshness before accepting and decrypting an update.
Keychain policy and local user presence protect stored key material. Face ID, Touch ID, a device passcode, or macOS authentication authorizes access; biometrics are not used as cryptographic keys.
MystSafe apps use the same quantum-safe cryptography in Free and Pro.