ความปลอดภัย
เราจริงจังกับความปลอดภัยของคุณ — ทุกบิต ทุก byte
Zero-Knowledge Security Model
ข้อมูลของคุณถูกเข้ารหัสก่อนออกจากอุปกรณ์เสมอ SafeKey ไม่มีทางเห็นรหัสผ่านของคุณแม้แต่อักษรเดียว
🔑
Master Password
รหัสผ่านหลักของคุณ (ไม่ถูกส่งออก)
→
⚙️
PBKDF2 Key Derivation
SHA-256, 100K iterations + salt
→
🔐
AES-256-GCM
เข้ารหัสข้อมูลในเบราว์เซอร์
→
☁️
Ciphertext Only
Server ได้รับแค่ข้อมูลที่เข้ารหัส
→
🗄️
Secure Storage
เก็บในฐานข้อมูล ถอดรหัสไม่ได้
🛡️
AES-256-GCM
- • Advanced Encryption Standard 256-bit
- • Galois/Counter Mode (authenticated encryption)
- • Unique IV สุ่มใหม่ทุกครั้งที่เข้ารหัส
- • ตรวจสอบ data integrity ด้วย Auth Tag
🔑
PBKDF2 Key Derivation
- • Password-Based Key Derivation Function 2
- • Algorithm: SHA-256
- • Iterations: 100,000+
- • Salt: 256-bit random per user
- • Output: 256-bit encryption key
🔒
Account Security
- • Argon2id password hashing
- • CSRF token per session
- • Rate limiting: 5 tries/15min
- • Secure session cookies (HttpOnly)
- • Auto session timeout: 1 hour
🌐
Transport Security
- • HTTPS forced via .htaccess
- • HSTS header (production)
- • TLS 1.2+ recommended
- • No sensitive data in URL
📋
Security Headers
- • Content-Security-Policy
- • X-Frame-Options: DENY
- • X-Content-Type-Options: nosniff
- • Referrer-Policy: no-referrer
- • Permissions-Policy
👁️
Zero-Knowledge Proof
- • Server เก็บเฉพาะ ciphertext
- • ไม่มีการส่ง plaintext หรือ key
- • แม้ฐานข้อมูลถูกเจาะก็ถอดรหัสไม่ได้
- • Web Crypto API (Browser native)
เราไม่เก็บอะไร?
ด้วยสถาปัตยกรรม Zero-Knowledge นี่คือสิ่งที่เซิร์ฟเวอร์ของเราไม่มีทางรู้
❌
Master Password ของคุณ
❌
Encryption Key ที่ได้จาก PBKDF2
❌
รหัสผ่านเว็บไซต์ต่างๆ ในรูปแบบ plaintext
❌
เนื้อหา Secure Notes ที่ถอดรหัสแล้ว
❌
ชื่อผู้ใช้ / URL ในรูปแบบที่อ่านได้ (ถ้าอยู่ใน vault)
❌
ข้อมูลที่สามารถระบุตัวตนคุณได้ผ่าน vault