Skip to content

Privacy and security

Encrypted on your device. Readable only by you.

NoxOne is built so that we cannot read your data even if we wanted to, even if we were asked to, and even if we were broken into.

Your password is the root of everything

Your password never leaves your device. Every key that protects your vaults, codes, files and messages is derived from it on your device, and only your devices ever hold those keys. Changing your password re-wraps your keys; nothing is re-uploaded.

What stays private

ServiceWhat only you can read
CodesSecrets and codes are never visible to us.
VaultTitles, usernames and passwords are never visible to us.
FilesFile names and contents are never visible to us. We count bytes for your quota, nothing more.
Private email addressMessages are sealed to your key the moment they arrive and are readable only on your devices.
Private phone numberTexts and voicemail are stored so only you can read them back.

Sharing without giving away keys

When you share a vault with your team, its key is sealed to each member individually; removing a member rotates the key. When you share authenticator codes for a while, your device shares the codes for that window only, never the secret, so the recipient cannot produce a code after the window ends.

Every new device confirms

After your password, a new device confirms with a code sent to an email address or phone number you verified. Devices you already use are not asked again. Sign out any device from the app or the account page.

Recovery is yours

A 24-word recovery phrase restores your account, sets a new password and signs out every other device. We cannot reset a password or recover an account without it. Organisations hold a recovery key of their own so shared data survives any departure.

Private addresses and numbers

Personal addresses and numbers receive only. What arrives is sealed to your key at that moment and opened only on your devices. Nothing forwards to your real inbox or phone, and nothing ties them to your identity.

How we operate

We keep as little as the service needs to run: your account, the devices you signed in, your plan, and encrypted data we cannot open. We do not publish the internals of our security design or the details of our infrastructure, and we do not sell or share data. Report a vulnerability to [email protected].