OneConductor is BYOK — bring your own keys — which means the vault is the single most important thing we build. Below is the plain-English version of how it works, and further down, the technical detail for anyone who wants to verify our claims rather than trust them.
Encryption at rest and ephemeral decrypt protect your keys from a data breach of our storage and from casual exposure in logs. They do not make OneConductor immune to every attack: a compromised device, a malicious browser extension, or a court order compelling disclosure are outside what any SaaS vault can promise to defeat. If you need keys that are provably never decryptable by any party but you, self-hosting is the honest answer — we're building toward that option, not claiming it today.