How our post-quantum security measures work
At Secrets Vault, we offer a secure and effortless way to access and protect sensitive information, simply by using post-quantum cryptography with a digital image.
Our core technology
Making post-quantum security simple
The core of our technology lies in how it simplifies the use of post-quantum cryptography, making it as easy as managing a visual image. To perform any cryptographic operation, users simply select an image (called a Keepic) to act as their key. It’s something tangible, memorable, and completely effortless.
Our technology is based on a proprietary cryptographic method called Calyptography, originally developed by Secrets Vault. It combines advanced computer vision and cryptographic techniques to make image-based security both powerful and practical.
Together, these techniques enable encryption, authentication, and other cryptographic protocols at a post-quantum level, simply by using an image as the main key component.
All cryptographic complexity is completely hidden from the user, ensuring a smooth and intuitive experience. Instead of managing complex passwords, installing dedicated software, or relying on hardware tokens, users simply manage an image of their choice.

Computer vision
From each image (Keepic), our system extracts unique and invariant random information.
• Unique: every image generates a different key.
• Invariant: the key stays the same even if resized or compressed.
This allows the same key to be recovered from the original image or any version shared online.
Post-quantum cryptography
The extracted invariant data is used to generate post-quantum cryptographic (PQC) keys, resistant to both current and future quantum attacks.
These PQC-compliant algorithms ensure your data remains protected well into the future.
Key security features

PQC protection
Cryptographic keys generated from images meet post-quantum standards, keeping data secure today and resilient against future quantum threats.

Edge Privacy
Keys are generated directly on the user’s device, keeping cryptographic operations local and ensuring private keys and data never leave the user’s environment.

Robust key generation
With resilient computer vision algorithms, users can recreate the key from compressed images, ensuring they can share or store them without losing access.

Perfect imperceptibility
Unlike steganography, our method never alters the original image. There are no visible or digital traces indicating that the image was used for cryptographic purposes.

Ephemeral keys
Keys are generated on demand and never stored. After their purpose (like authentication) is complete, they’re erased from memory to reduce the risk of compromise.

Multi-factor keys
Security improves by combining image-based key generation with factors like a PIN, password, or visual checks, making the key unique to the user and context.

Protocol compatibility
Image-derived keys can support mechanisms like secret sharing or zero-knowledge proofs, enabling secure authentication and data protection in complex systems.
From core technology to real solutions
Building on this post-quantum foundation, we have developed two key solutions:
Both leverage the same core technology to deliver next-generation security that’s both powerful and effortless to use.

How data is protected using post-quantum cryptography (PQC) and an image
Our solution implements post-quantum data protection through an image-based encryption protocol.
This protocol combines the generation of a post-quantum encryption key from a Keepic image with a zero-knowledge proof (ZKP) of that same image.
The proof is also post-quantum resilient and ensures that encrypted data stored on a remote server cannot be accessed unless the user first proves ownership of the correct image.
This prevents attackers from testing random images and allows the system to block such attempts after only a few failed attempts before any data is ever downloaded.
How we authenticate users with post-quantum cryptography and images
Image-based PQC authentication relies on a cryptographic challenge–response protocol designed for strong authentication. It combines the generation of a zero-knowledge proof of the Keepic, a post-quantum authentication key derived from the image, and an interactive challenge–response exchange.
The protocol is fully post-quantum resilient, meaning an attacker cannot derive the authentication key without first proving ownership of the correct image. It also includes rate-limiting mechanisms that detect and block brute-force attempts involving multiple images or image–PIN combinations.

System security strength
By combining advanced cryptography with state-of-the-art image processing, Secrets Vault protects sensitive information and grants secure access to systems in a simple, intuitive way equivalent in strength to a 40-character random password (256-bit security).
From a cryptographic perspective, our method generates post-quantum cryptographic (PQC) keys that meet NIST security level 5, the highest defined standard for post-quantum resistance.
Quantum-safe strength
The algorithms used in our image-based key generation method and related protocols achieve quantum-safe protection.
All core cryptographic components are aligned with NIST PQC standards, ensuring long-term resilience against future quantum attacks.
Key algorithms include:
• Symmetric encryption: AES-256 (FIPS 197)
• Asymmetric encryption: ML-KEM-1024 (FIPS 203)
• Digital signature and authentication: ML-DSA-87 (FIPS 204)
Thanks to the modular architecture of our system and the adaptability of our computer vision layer, new algorithms can be seamlessly integrated as they are standardized (e.g., SLH-DSA, FN-DSA, or HQC), without the need to reassess image strength.
Our image-based key generation method can also operate with NIST-compliant pre-quantum cryptographic algorithms, such as RSA, ECDSA, or EdDSA (FIPS 186-5), ensuring compatibility with existing infrastructures.


Images resilient to modifications
Our computer vision makes image-based key generation robust to resizing, compression, or watermarking, so users can share images on any platform without losing security or functionality.

Zero-knowledge verification
All encryption and signature protocols protect the user’s secrets on-device and server-side. Using zero-knowledge proofs, the system verifies the correct Keepic image without revealing it, ensuring privacy and preventing impersonation.

On-device cryptographic operations
All encryption and security processes take place directly on your device, ensuring that Secrets Vault never accesses your secrets or Keepic. Our source code is fully open and available for your review.

The images remain unaltered
The image you provide as a Keepic remains completely unchanged, making it indistinguishable from any original image. In fact, you can use any public image as a Keepic without needing to modify or update it.
The cryptography mastermind
Jordi PuiggalĂ, a recognized expert in cybersecurity and cryptography, has made extensive contributions to both academic and industry research. His publications frequently focus on election security, cryptographic protocols, and secure online voting systems. You can explore his most notable works here:

Jordi PuiggalĂ
Co-founder & CTO

50+papers
Published research in cryptograhpy, cybersecurity and blockchain.

50 patents
Innovations in cryptographic protocols and secure technologies.

30 years of experience
Decades of expertise across IT, cryptography, cybersecurity and blockchain.
Technical advisory committee
At Secrets Vault, our commitment to innovation and security is bolstered by our esteemed technical advisory committee.
This growing group of leading experts helps shape our platform to ensure unparalleled security, resilience, and usability.
Drawing on decades of experience in cryptography, cybersecurity, blockchain and cutting-edge technologies, they provide invaluable guidance on safeguarding your digital assets.

Alex Puig
Crypto Advisor
With 15 years of experience in the crypto industry, pioneering innovation, shaping strategy, and effectively leading as the CEO and founder of several successful Web3 startups.

Gabriel Dos Santos
Technology Advisor
With 25 years in the IT industry, including experience with global startups and META in Silicon Valley, managing international IT teams, and specializing in scalable software and hardware architectures.

David MegĂas. Ph.D.
Security and privacy technologies Advisor
Director of IN3 at Universitat Oberta de Catalunya, expert in security and privacy, and author of numerous works on steganography, watermarking, and cybersecurity.

JesĂşs Choliz
IT and information security Advisor
Global CISO and Head of Cloud Governance at Adevinta, with deep expertise in software engineering, cloud governance, FinOps, security, data privacy, and IT transformation.
Collaboration with third parties
At Secrets Vault, we believe that advancing cybersecurity and cryptography requires continuous collaboration with top experts and research institutions.



Our partnerships
Our partnerships with leading research centers and universities underscore our commitment to pushing the boundaries of secure technology, enabling us to rigorously test and validate our protocols against the latest security standards.

Specialists
By working alongside specialists in cryptography, computer vision, and cybersecurity, we gain invaluable insights into emerging threats, explore innovative defense techniques, and refine our solutions using the latest research.

Collaborations
These collaborations directly enhance the quality and resilience of our solutions, integrating insights from fields such as image processing, blockchain, homomorphic encryption, zero-knowledge proofs, post-quantum cryptography, and multi-party computation.

Challenges
This commitment keeps Secrets Vault at the forefront of security, delivering solutions that are not only innovative but also robust against future challenges.
If you’re interested in collaborating with us scientifically, discussing our security protocols, or exploring our source code, please complete this form and share your specific areas of interest.






