Security
Don't trust us. Verify.
This page exists so you can check our claims instead of believing them. It is also where the technical words live.
Where your data lives
Your memories, conversations, and files live in your own vault: a smart contract (called a canister) running on the Internet Computer, a public blockchain network run by independent node operators around the world. They are not rows in a company database. There is no Armacore server farm holding your life.
Only your signed-in identity can read your vault through the app's interfaces. Access is checked on every single call, on-chain.
What is encrypted, exactly
Sensitive content is encrypted with vetKD, the Internet Computer's threshold key system. The key that seals your data is split across many independent nodes and is never assembled in any one place. Not on your device, not on a node, and never by us.
Today that covers: the verbatim quotes behind your memories, sensitive personal details, your API keys, and any store credentials. The structured index of your memories (the part that lets your agent find things fast) is not yet encrypted at rest. We say this plainly because you should know what you're trusting. Encrypting that index without breaking recall is on our public roadmap.
How you sign in
Armacore signs you in through Internet Identity. Use your Google account or a passkey. Either way there is no Armacore password to steal, reuse, or leak.
What we can see
We can see operational signals: how many requests the system handles, error rates, and what we need to keep the lights on. The website uses one analytics tool to count visits.
We cannot browse your memories through any admin dashboard. No such dashboard exists.
Verify it yourself
Don't trust us. Check. Every canister Armacore runs is public and inspectable on the Internet Computer dashboard, including its code hash and its controllers. The app's vault canister is wajhi-daaaa-aaaae-qjeha-cai and the site you are reading is served from ugrvf-kqaaa-aaaae-qjeka-cai.
Where we are honest about gaps
We haven't completed a third-party security audit yet. It's planned. Until then, here is what you can verify yourself today: the canisters, their controllers, and the open behavior of the network they run on. We'd rather tell you the truth than show you a badge.
Inspect the vault canister live
wajhi-daaaa-aaaae-qjeha-cai