ความปลอดภัย

เราจริงจังกับความปลอดภัยของคุณ — ทุกบิต ทุก byte

Zero-Knowledge Security Model

ข้อมูลของคุณถูกเข้ารหัสก่อนออกจากอุปกรณ์เสมอ SafeKey ไม่มีทางเห็นรหัสผ่านของคุณแม้แต่อักษรเดียว

🔑
Master Password
รหัสผ่านหลักของคุณ (ไม่ถูกส่งออก)
⚙️
PBKDF2 Key Derivation
SHA-256, 100K iterations + salt
🔐
AES-256-GCM
เข้ารหัสข้อมูลในเบราว์เซอร์
☁️
Ciphertext Only
Server ได้รับแค่ข้อมูลที่เข้ารหัส
🗄️
Secure Storage
เก็บในฐานข้อมูล ถอดรหัสไม่ได้
🛡️

AES-256-GCM

  • Advanced Encryption Standard 256-bit
  • Galois/Counter Mode (authenticated encryption)
  • Unique IV สุ่มใหม่ทุกครั้งที่เข้ารหัส
  • ตรวจสอบ data integrity ด้วย Auth Tag
🔑

PBKDF2 Key Derivation

  • Password-Based Key Derivation Function 2
  • Algorithm: SHA-256
  • Iterations: 100,000+
  • Salt: 256-bit random per user
  • Output: 256-bit encryption key
🔒

Account Security

  • Argon2id password hashing
  • CSRF token per session
  • Rate limiting: 5 tries/15min
  • Secure session cookies (HttpOnly)
  • Auto session timeout: 1 hour
🌐

Transport Security

  • HTTPS forced via .htaccess
  • HSTS header (production)
  • TLS 1.2+ recommended
  • No sensitive data in URL
📋

Security Headers

  • Content-Security-Policy
  • X-Frame-Options: DENY
  • X-Content-Type-Options: nosniff
  • Referrer-Policy: no-referrer
  • Permissions-Policy
👁️

Zero-Knowledge Proof

  • Server เก็บเฉพาะ ciphertext
  • ไม่มีการส่ง plaintext หรือ key
  • แม้ฐานข้อมูลถูกเจาะก็ถอดรหัสไม่ได้
  • Web Crypto API (Browser native)

เราไม่เก็บอะไร?

ด้วยสถาปัตยกรรม Zero-Knowledge นี่คือสิ่งที่เซิร์ฟเวอร์ของเราไม่มีทางรู้

Master Password ของคุณ
Encryption Key ที่ได้จาก PBKDF2
รหัสผ่านเว็บไซต์ต่างๆ ในรูปแบบ plaintext
เนื้อหา Secure Notes ที่ถอดรหัสแล้ว
ชื่อผู้ใช้ / URL ในรูปแบบที่อ่านได้ (ถ้าอยู่ใน vault)
ข้อมูลที่สามารถระบุตัวตนคุณได้ผ่าน vault

พร้อมปกป้องข้อมูลของคุณแล้วหรือยัง?

เริ่มต้นใช้งานฟรี ไม่ต้องใช้บัตรเครดิต

🔐 เริ่มต้นฟรีวันนี้