How your information is protected
What is true today, what the architecture guarantees, and what we are still building.
One key per person
Every person’s information is encrypted with a key of their own, unlocked by their own sign-in. There is no master key at Unidy: no single credential opens everybody’s information, and none can be handed to a member of staff, because it does not exist.
This is deliberate. A stolen copy of our database is not a breach of everyone at once. It is millions of separate locks.
What happens today
While you are signed in, our servers decrypt what you asked to see and send it to your screen. Nothing readable is stored afterwards, and your key cannot be used without your sign-in.
To be precise: this protects you against stolen databases and stolen backups, which is how personal data usually leaks. On its own it does not protect you against someone who has taken live control of our running servers.
What we are building
We are working toward decryption that happens only on your own device, so that readable information never exists on our servers at all, not even for a moment.
We will say so plainly when it is finished. Until then, we will not claim it.
What sharing really means
When you share, Unidy creates a copy containing only the fields you chose, marked with who is receiving it and when. Your original document is never sent.
Access expires on its own, and you can revoke it at any time. We will not pretend revocation is magic: if someone has already downloaded a copy, no system can erase it from their computer. The mark on that copy is what makes misuse traceable.
If you are no longer here
An architecture that keeps us out of your information cannot make an exception after your death. The instructions have to be set while you are alive.
We are designing this around people you designate, categories of information you choose in advance, several independent approvals rather than one, and a delay before anything opens. It stays changeable by you at any time, and every access is recorded.
Reporting a problem
If you find a security weakness, write to hello@unidy.com. We will answer, and we will never threaten anyone who reports a problem in good faith.