Frequently Asked Questions
How are my files protected?
Each document is encrypted on your iPhone with AES-256-GCM; its key is wrapped with X-Wing (X25519 + ML-KEM-768). Private keys are generated and used only inside Qpher's isolated key service. No API can export them. X-Wing is a hybrid built on an IETF draft around ML-KEM (NIST FIPS 203), designed to resist attack by a quantum computer.
Where are my private keys stored?
Private keys are generated and used only inside Qpher's isolated key service and are never exported. On your iPhone, you can lock the app with Face ID. Your files are encrypted and decrypted on your device; Qpher's isolated key service creates and recovers the one-time secret that protects each file's key.
Can Qpher read my documents?
Qpher is not zero-knowledge. Private keys are generated and used only inside an isolated key service and are never exported; on client-side paths (Vault, Organization send, .qpher) Qpher never sees the plaintext; the API's server-side mode receives plaintext over TLS, processes it in memory and does not store it.
Can I use Qpher Vault offline?
No. Encrypting, opening, sharing and importing each need a quick call to Qpher's isolated key service, which creates or
recovers the secret that protects your file's key. The file itself is encrypted and decrypted on your device. A
.qpher export can be moved offline (by AirDrop, USB and so on) and imported later when you are online.
What file types are supported?
PDF, Word, Excel, images and most other files you can share from your iPhone, up to your plan's file-size limit. The viewer (iOS Quick Look) opens PDFs, images, Office documents, text files and most audio and video.
What happens if I forget my password?
Tap Forgot password? on the sign-in screen, enter your email and follow the reset link. Your encryption keys are managed by Qpher's key service and are not derived from your password, so resetting your password does not affect your documents.
How do I upgrade my plan?
Open Settings, tap Plan & billing and choose a plan. Upgrades go through Apple In-App Purchase and take effect immediately. You can manage or cancel the subscription in iOS Settings → Subscriptions.
What is a .qpher file?
A .qpher file is a portable encrypted copy of a document, made by Qpher Vault. It contains:
- The encrypted file content
- The sender's digital signature (ML-DSA)
- Encryption bound to the recipient's keys (for a member of an organization, the organization's)
- Header integrity protection (AAD binding)
You can move .qpher files by AirDrop, email, USB or any other way. The recipient imports it into Qpher Vault to verify
and open it. See Export & Import.
Can I share files with someone who doesn't have Qpher Vault?
In-app sharing: yes. They get an invitation to install Qpher Vault; once they register and verify the email you shared to, the document is available to them.
Encrypted export (.qpher): the recipient needs a Qpher Vault account. If they don't have one, the app offers
Share via Qpher instead.
How do I know if my file has been tampered with?
Every document is encrypted with AES-256-GCM, which is authenticated: when you open a document, Qpher Vault checks its
header and its SHA-256 hash, and a changed file does not open. A Signed badge means a signature is on record; the app
does not re-check it when you open the document. For .qpher files, the sender's signature is checked during import,
and any change to the file makes the import fail.
Does Qpher Vault prevent screenshots?
It can't stop them. It detects screenshots and logs them against the document, and covers the document while the screen is being recorded.
Which standards and audits apply to Qpher Vault?
Qpher implements NIST FIPS 203, 204 and 205. Our cryptographic module has not been validated by NIST's CMVP, and no SOC 2 audit has been completed. See Compliance & Standards and the Trust Center.
How do I delete my account?
Open Settings and tap Delete account at the bottom. You can restore the account for 30 days. Deleting an account does not yet destroy its PQC private keys; they stay encrypted in the key service. Your Apple subscription is not canceled — cancel it in iOS Settings → Subscriptions. See Deleting Your Account.