Multi-Factor Architecture

Security Factors Explained

Get a clear understanding of how Cipherwill's encryption works with various security factors, ensuring your digital assets are protected at every step.

See My Account Factors →

What are Security Factors?

Security factors are cryptographic pillars. Instead of relying on vulnerable centralized databases, Cipherwill uses these factors as unique inputs to derive local encryption keys. Your keys unlock the vault, ensuring only you or your designated beneficiaries can decrypt your data.

On-Device Generation

Factors trigger a local key-derivation function. We generate highly secure 256-bit entropy seeds directly in your browser. Our servers never see your password, passkey, or private key.

Supported Factors

Choose from industry-grade authentication devices and decentralized cryptographic vectors.

High

Master Password

User-generated client passphrase

A secure, user-managed password. We apply intense key-stretching (PBKDF2 with SHA-256) on your local device to generate robust cryptographic locks.

Algorithm256-bit PBKDF2 / AES
StorageDecrypted on-device dynamically
Extreme

FIDO2 Keys

Hardware cryptographic credential

Industry-standard hardware keys that resist phishing attacks by using asymmetric cryptography tied specifically to our origin hostname.

Algorithm256-bit ECC (secp256r1)
StorageOn-chip secure enclave
Ultimate

YubiKeys

Physical authenticator device

Integrate premium hardware authenticators. Decryption keys are unlocked via hardware-bound touch-to-approve user actions.

AlgorithmHMAC-SHA1 / Asymmetric RSA
StoragePhysical cryptographic chip
Extreme

Device Passkeys

Biometric Hardware Auth

Leverage TouchID, FaceID, or Windows Hello. Generates unique, tamper-proof device credentials that are completely un-phishable.

Algorithm256-bit ECC / WebAuthn
StorageSecure Enclave (Apple/Android)
Ultimate

Web3 Wallets

MetaMask & Ethereum keys

Sign on-device payloads with your Web3 keys. Cipherwill uses standard elliptic curve cryptography to link your decentralized identity securely.

Algorithmsecp256k1 Elliptic Curve
StorageLocal wallet extension storage

Encryption Status Matrix

The table below maps how your cryptographic protection scales depending on the security factors configured on both your account and your beneficiary's pipeline.

My Vault NodeBeneficiary NodeEnd-to-End Result
Unsecured
Unsecured
Data is completely unencrypted across both endpoints.
Secured
Unsecured
Data is securely encrypted for your vault, but remains unencrypted for your beneficiary's delivery pipeline.
Unsecured
Secured
Data is unencrypted for your primary access, but securely pre-encrypted for beneficiary delivery.
Secured
Secured
Full End-to-End Cryptographic Security. Maximum privacy and secure delivery unlocked for both endpoints.Recommended

Be ready for tomorrow.

Legacy planning isn't about the end; it's about giving your loved ones complete clarity. Create a secure, automated plan for your digital assets in under three minutes.