Skip to main content

Encrypt & Store

Each document is encrypted on your iPhone with AES-256-GCM; its key is wrapped with X-Wing (X25519 + ML-KEM-768).

How encryption works​

When you encrypt a file, Qpher Vault:

  1. Generates a random 256-bit file key on your iPhone
  2. Encrypts the file with that key (AES-256-GCM)
  3. Asks Qpher's isolated key service for a one-time X-Wing shared secret and uses it to wrap the file key
  4. Uploads the encrypted file and the wrapped key to storage in the United States (Cloudflare R2)
  5. Clears the file key and the shared secret from memory

Private keys are generated and used only inside Qpher's isolated key service. No API can export them.

Encrypt a file​

  1. On the Documents tab, tap + and choose Encrypt document
  2. Choose where the file comes from — Files, Camera, Photos or Scan Document — and pick it
  3. Sign this document is on by default; leave it on to sign the document in your name
  4. Tap Encrypt & Save. Qpher Vault encrypts the document on your iPhone and uploads it

Use the iOS share sheet to send a file from another app straight into Qpher Vault.

Badges​

BadgeMeaning
ProtectedThe document is encrypted and stored in your vault
SignedA signature is on record for the document

What you can encrypt​

PDF, Word, Excel, images and most other files you can share from your iPhone, up to your plan's file-size limit.

Limits​

Your plan sets your storage space, the largest file you can encrypt and how many documents you can encrypt each month. Settings shows your storage and how many encryptions you have left this month; plans and prices are under Settings → Plan & billing and on qpher.ai/vault.