Skip links

How our post-quantum security measures work

At Secrets Vault, we offer a secure and effortless way to access and protect sensitive information, simply by using post-quantum cryptography with a digital image.

Our core technology

Making post-quantum security simple

The core of our technology lies in how it simplifies the use of post-quantum cryptography, making it as easy as managing a visual image. To perform any cryptographic operation, users simply select an image (called a Keepic) to act as their key. It’s something tangible, memorable, and completely effortless.

Our technology is based on a proprietary cryptographic method called Calyptography, originally developed by Secrets Vault. It combines advanced computer vision and cryptographic techniques to make image-based security both powerful and practical.

Together, these techniques enable encryption, authentication, and other cryptographic protocols at a post-quantum level, simply by using an image as the main key component.

All cryptographic complexity is completely hidden from the user, ensuring a smooth and intuitive experience. Instead of managing complex passwords, installing dedicated software, or relying on hardware tokens, users simply manage an image of their choice.

Computer vision

From each image (Keepic), our system extracts unique and invariant random information.

• Unique: every image generates a different key.

• Invariant: the key stays the same even if resized or compressed.

This allows the same key to be recovered from the original image or any version shared online.

Post-quantum cryptography

The extracted invariant data is used to generate post-quantum cryptographic (PQC) keys, resistant to both current and future quantum attacks.

These PQC-compliant algorithms ensure your data remains protected well into the future.

Key security features

secrests-vault-secure-and-manage-your-passwords

PQC protection

Cryptographic keys generated from images meet post-quantum standards, keeping data secure today and resilient against future quantum threats.

secrets-vault-protect-your-sensitive-photos

Edge Privacy

Keys are generated directly on the user’s device, keeping cryptographic operations local and ensuring private keys and data never leave the user’s environment.

secrets-vault-protect-your-wallet-seed-phrases

Robust key generation

With resilient computer vision algorithms, users can recreate the key from compressed images, ensuring they can share or store them without losing access.

secrets-vault-preserve-your-familys-prized-secrets

Perfect imperceptibility

Unlike steganography, our method never alters the original image. There are no visible or digital traces indicating that the image was used for cryptographic purposes.

secrets-vault-share-confidential-documents

Ephemeral keys

Keys are generated on demand and never stored. After their purpose (like authentication) is complete, they’re erased from memory to reduce the risk of compromise.

secrets-vault-plan-for-your-digital-legacy

Multi-factor keys

Security improves by combining image-based key generation with factors like a PIN, password, or visual checks, making the key unique to the user and context.

secrets-vault-7

Protocol compatibility

Image-derived keys can support mechanisms like secret sharing or zero-knowledge proofs, enabling secure authentication and data protection in complex systems.

From core technology to real solutions

Building on this post-quantum foundation, we have developed two key solutions:

secrest-vault-visual-passcodes

Secrets Vault Identity

For post-quantum passwordless authentication.

Learn more
secrest-vault-visual-safeguard

Secrets Vault Data

For post-quantum data vault.

Learn more

Both leverage the same core technology to deliver next-generation security that’s both powerful and effortless to use.

secrets-vault-add-new-secret

How data is protected using post-quantum cryptography (PQC) and an image

Our solution implements post-quantum data protection through an image-based encryption protocol.

This protocol combines the generation of a post-quantum encryption key from a Keepic image with a zero-knowledge proof (ZKP) of that same image.

The proof is also post-quantum resilient and ensures that encrypted data stored on a remote server cannot be accessed unless the user first proves ownership of the correct image.

This prevents attackers from testing random images and allows the system to block such attempts after only a few failed attempts before any data is ever downloaded.

How we authenticate users with post-quantum cryptography and images

Image-based PQC authentication relies on a cryptographic challenge–response protocol designed for strong authentication. It combines the generation of a zero-knowledge proof of the Keepic, a post-quantum authentication key derived from the image, and an interactive challenge–response exchange.

The protocol is fully post-quantum resilient, meaning an attacker cannot derive the authentication key without first proving ownership of the correct image. It also includes rate-limiting mechanisms that detect and block brute-force attempts involving multiple images or image–PIN combinations.

secrets-vault-login

System security strength

By combining advanced cryptography with state-of-the-art image processing, Secrets Vault protects sensitive information and grants secure access to systems in a simple, intuitive way equivalent in strength to a 40-character random password (256-bit security).

From a cryptographic perspective, our method generates post-quantum cryptographic (PQC) keys that meet NIST security level 5, the highest defined standard for post-quantum resistance.

Quantum-safe strength

The algorithms used in our image-based key generation method and related protocols achieve quantum-safe protection.

All core cryptographic components are aligned with NIST PQC standards, ensuring long-term resilience against future quantum attacks.

Key algorithms include:

• Symmetric encryption: AES-256 (FIPS 197)

• Asymmetric encryption: ML-KEM-1024 (FIPS 203)

• Digital signature and authentication: ML-DSA-87 (FIPS 204)

Thanks to the modular architecture of our system and the adaptability of our computer vision layer, new algorithms can be seamlessly integrated as they are standardized (e.g., SLH-DSA, FN-DSA, or HQC), without the need to reassess image strength.

Our image-based key generation method can also operate with NIST-compliant pre-quantum cryptographic algorithms, such as RSA, ECDSA, or EdDSA (FIPS 186-5), ensuring compatibility with existing infrastructures.

Images resilient to modifications

Our computer vision makes image-based key generation robust to resizing, compression, or watermarking, so users can share images on any platform without losing security or functionality.

Zero-knowledge verification

All encryption and signature protocols protect the user’s secrets on-device and server-side. Using zero-knowledge proofs, the system verifies the correct Keepic image without revealing it, ensuring privacy and preventing impersonation.

On-device cryptographic operations

All encryption and security processes take place directly on your device, ensuring that Secrets Vault never accesses your secrets or Keepic. Our source code is fully open and available for your review.

The images remain unaltered

The image you provide as a Keepic remains completely unchanged, making it indistinguishable from any original image. In fact, you can use any public image as a Keepic without needing to modify or update it.

The cryptography mastermind

Jordi PuiggalĂ­, a recognized expert in cybersecurity and cryptography, has made extensive contributions to both academic and industry research. His publications frequently focus on election security, cryptographic protocols, and secure online voting systems. You can explore his most notable works here:

Publications

Jordi PuiggalĂ­

Co-founder & CTO

secrets-vault-50-papers

50+papers

Published research in cryptograhpy, cybersecurity and blockchain.

secrets-vault-49-patents

50 patents

Innovations in cryptographic protocols and secure technologies.

secrets-vault-30-years-experience

30 years of experience

Decades of expertise across IT, cryptography, cybersecurity and blockchain.

Technical advisory committee

At Secrets Vault, our commitment to innovation and security is bolstered by our esteemed technical advisory committee.

This growing group of leading experts helps shape our platform to ensure unparalleled security, resilience, and usability.

Drawing on decades of experience in cryptography, cybersecurity, blockchain and cutting-edge technologies, they provide invaluable guidance on safeguarding your digital assets.

Alex Puig

Crypto Advisor

With 15 years of experience in the crypto industry, pioneering innovation, shaping strategy, and effectively leading as the CEO and founder of several successful Web3 startups.

Gabriel Dos Santos

Technology Advisor

With 25 years in the IT industry, including experience with global startups and META in Silicon Valley, managing international IT teams, and specializing in scalable software and hardware architectures.

David MegĂ­as. Ph.D.

Security and privacy technologies Advisor

Director of IN3 at Universitat Oberta de Catalunya, expert in security and privacy, and author of numerous works on steganography, watermarking, and cybersecurity.

JesĂşs Choliz

IT and information security Advisor

Global CISO and Head of Cloud Governance at Adevinta, with deep expertise in software engineering, cloud governance, FinOps, security, data privacy, and IT transformation.

Collaboration with third parties

At Secrets Vault, we believe that advancing cybersecurity and cryptography requires continuous collaboration with top experts and research institutions.

secrests-vault-secure-and-manage-your-passwords

Our partnerships

Our partnerships with leading research centers and universities underscore our commitment to pushing the boundaries of secure technology, enabling us to rigorously test and validate our protocols against the latest security standards.

secrets-vault-protect-your-sensitive-photos

Specialists

By working alongside specialists in cryptography, computer vision, and cybersecurity, we gain invaluable insights into emerging threats, explore innovative defense techniques, and refine our solutions using the latest research.

secrets-vault-protect-your-wallet-seed-phrases

Collaborations

These collaborations directly enhance the quality and resilience of our solutions, integrating insights from fields such as image processing, blockchain, homomorphic encryption, zero-knowledge proofs, post-quantum cryptography, and multi-party computation.

secrets-vault-preserve-your-familys-prized-secrets

Challenges

This commitment keeps Secrets Vault at the forefront of security, delivering solutions that are not only innovative but also robust against future challenges.

If you’re interested in collaborating with us scientifically, discussing our security protocols, or exploring our source code, please complete this form and share your specific areas of interest.

Contact us

How it works FAQ’s

Visual Cryptography is a technique that uses images to encrypt or decrypt information in a visual way. A common example is a secret-sharing scheme that creates two separate images which, when overlaid, visually reveal a hidden image.

However, traditional Visual Cryptography has key limitations. It’s highly sensitive to image changes: resizing, compression, or watermarking can break up the scheme, and it usually requires unaltered images for recovery. Moreover, it only protects visual information, so it cannot be used to secure general binary data.

Calyptography, on the other hand, has no such limitations. It can protect any type of digital asset, not just visual content, and remains resilient to common image alterations like compression and resizing. It represents a significant step forward in applying images as cryptographic elements rather than as simple containers.

Steganography is a method for hiding secret data within another digital medium, such as an image or file. To do this, the medium is modified, for example, by changing the least significant bits of pixel values to embed hidden identifiers for fingerprinting or watermarking.

The goal is to make the hidden data imperceptible, but modern AI and computer vision tools can often detect these subtle modifications. Moreover, the amount of data that can be hidden is limited, and users must work with the modified version of the image to recover the secret.

Calyptography eliminates these limitations:
– It does not alter a single bit of the image, ensuring perfect imperceptibility.
– Users can use any copy of the original image, even if compressed or resized, without losing security.
– It is inherently robust to image modifications, maintaining reliability across storage and sharing platforms.

Calyptography turns images into cryptographic elements rather than secret carriers, enabling a secure and untraceable way to protect information.

Traditionally, sensitive data is protected using password-based encryption, where cryptographic keys are derived from user passwords. Achieving a 128-bit security strength typically requires at least a 21-character random password, something complex and hard to remember (e.g., jlE5FSPTT7fi4YnZ63Xy2).

Weaker or more predictable passwords significantly reduce encryption strength, making data vulnerable to brute-force attacks.

Images offer a much better alternative. Each image is composed of thousands (or millions) of pixels, each containing unique color data. Even a small 200Ă—200-pixel image can contain over 120,000 bits of entropy, nearly 1,000 times the strength of a 21-character password.

Using the Calyptography method, Secrets Vault generates 256-bit, quantum-safe keys from images, equivalent to a 42-character random password, but far easier to use and remember.

Yes, as long as the changes don’t significantly alter the essence of the image (e.g., heavy cropping).

Our protocol is specifically designed to handle typical image manipulations that occur when storing or sharing images on external platforms, such as social networks or cloud services.

Unlike other methods, where even a single pixel change can prevent recovery, Secrets Vault’s technology extracts invariant image information. This allows the same data to be securely recovered even after resizing, compression or watermarking, making sharing and storage both flexible and secure.

No, there are no specific limitations on the type or length of data that can be protected. Practical limits are defined by the user’s device and the selected service license. Currently, data protection sizes can reach 1 gigabyte or more, depending on the plan and processing capabilities.

Only a minimum size is required to ensure enough entropy for secure protection. The current lower limit is 50,000 pixels (around a 224Ă—224-pixel image).

This threshold is already well below the size of most modern images. For instance, a standard VGA image (640Ă—480) contains over 300,000 pixels, well above the minimum.

Future updates may lower this requirement further, but current limits are already optimized for today’s typical image resolutions.

No. The security strength of our scheme is independent of image size.

This means the image can be resized, for example, scaled down for sharing without reducing its cryptographic strength.

We currently maintain a minimum effective resolution of 50,000 pixels (about 224Ă—224) to ensure consistent 256-bit quantum-resilient security.

We are actively researching improvements that could lower this limit even further without compromising protection.

The Keepic is essential for recovering your secret. Without it, recovery is impossible even if you still have access to the Kvault. Losing the Keepic is like losing the password or encryption key that protects your data.

We recommend storing multiple copies of your Keepic in secure, reliable locations. Since the Keepic can be any public image, you can safely choose one that’s widely accessible (for example, a museum painting) or store it on public platforms or social media without worrying about compression or resizing. Because the Keepic is never altered, it remains indistinguishable from any ordinary image, blending seamlessly among publicly shared visuals.

No. The encrypted data is protected using post-quantum cryptographic algorithms, meaning it cannot be decrypted, not now, and not even when quantum computers become available.

Additionally, our solution prevents unauthorized data access. Encrypted information cannot be downloaded from the server unless the user first proves knowledge of the correct Keepic through a zero-knowledge verification process. This mechanism greatly reduces the risk of data exposure, even if an attacker were to compromise the authentication process.

All cryptographic operations are performed entirely on the user’s device, ensuring that neither the secret nor the Keepic ever leaves the user’s control.

The only component transmitted externally is the Kvault, which is securely managed by the Secrets Vault platform. Alongside it, a Keepic commitment is sent for future recovery. This commitment allows Secrets Vault to verify, using zero-knowledge proofs, that the user possesses the correct Keepic, without ever revealing the image itself.

This process ensures that the Keepic always remains private and prevents impersonation or unauthorized recovery attempts.

The strength of cryptography is based on the computational power required to break encryption, that is, to find the private key protecting the information. Current algorithms are designed to resist attacks from classical computers, and their strength scales according to technological progress (following Moore’s Law, where computing power roughly doubles every 1.5–2 years).

However, quantum computers will fundamentally change this balance. They can execute algorithms that exploit quantum mechanical properties to solve problems exponentially faster than classical systems.

For example, Shor’s algorithm (not “Groove”) allows quantum computers to find private keys from current asymmetric encryption systems (like RSA or ECC) in hours or days, instead of thousands of years. When quantum computers reach sufficient stability (measured in qubits), they will be able to decrypt any information protected with traditional cryptography.

While today’s quantum computers are still in early development, it is widely recognized as a matter of when, not if, this threat becomes real.

Post-Quantum Cryptography (PQC) refers to a new generation of cryptographic algorithms designed to remain secure even against quantum computing attacks.

PQC algorithms can be executed on today’s standard computers, but are mathematically resistant to quantum-based attacks that could break existing systems. This means that data protected with post-quantum algorithms will remain safe both now and in the quantum future.

When quantum computers become capable of breaking today’s algorithms, data protected by traditional encryption will no longer be secure.

However, the risk is already present today through what is known as a “harvest-now, decrypt-later” attack. In this scenario, attackers collect encrypted data now, such as passwords, seed phrases, contracts, or confidential communications and wait until quantum computers can decrypt it. This could expose years of private information in the future.

In the short term, this primarily threatens data privacy. In the medium term, it could compromise authentication credentials and digital signatures, allowing attackers to reconstruct private keys and impersonate legitimate users.

Migrating to post-quantum cryptography now is the only way to prevent these future threats.

Yes. Governments and regulatory institutions are already setting deadlines for organizations to transition to post-quantum security. Entities that handle confidential or critical data are the first to be affected.

Depending on the country:
– By 2026: Organizations must have a post-quantum migration plan in place.
– By 2030: Critical systems are expected to be fully quantum-safe.
– By 2035: The migration should be completed across all remaining systems.

This transition is being driven by global initiatives such as NIST’s Post-Quantum Cryptography Standardization Project, which is defining the next generation of cryptographic standards to ensure long-term data security.

Any more questions?

Contact our team!

CONTACT US
Privacy Summary

This website uses cookies so that we can provide you with the best possible user experience. The cookie information is stored in your browser and performs functions such as recognizing you when you return to our site or helping our team understand which sections of the site you find most interesting and useful.