Back to blog

How vvault Protects Your Account

Your account is the key to every unreleased file you own. Here is exactly what stands in front of it — and what does not.

·5 min read

Every protection on your music depends on one thing holding: that the person signing in as you is you. This is a plain account of what stands in front of your account, written so you can check it rather than take it on faith.

There is no password to steal

vvault has no password. You sign in with a one-time code sent to your email, or with Google or Apple. That removes the most common way accounts are lost: a password reused from a site that got breached two years ago, or typed into a convincing fake login page.

The codes are not a soft target either. They expire, they are refused after a small number of wrong attempts, and requests are rate-limited per IP address — so a code cannot be worn down by guessing.

Add a second factor

Email is still a single point of failure: whoever controls your inbox can request a code. In Settings → Security you can add a second factor — an authenticator app, a phone number, or a passkey — so that a compromised inbox is not enough on its own. If you keep unreleased work in vvault, turn this on today rather than the day you need it.

A PIN on the app itself

Most studio leaks are not remote attacks. They are an unlocked laptop in a room full of people. You can set a PIN that locks vvault itself, so an open browser is not an open vault.

The PIN is never stored in a form anyone can read back. It is hashed with scrypt using a salt unique to your PIN, compared in constant time so the comparison itself gives nothing away, and checked on the server — the browser never receives the hash and cannot be talked into approving itself.

What your account actually unlocks

Your audio does not sit at a public address. It lives in a private bucket, and every play and download is served through a signed link that expires — so a URL copied out of a browser is not a permanent key to your master. The rules about who can open what are enforced by row-level security in the database, underneath the interface: a request for something you may not have returns nothing, whatever the app did.

Traffic is encrypted in transit with TLS, files and database contents are encrypted at rest with AES-256 by our infrastructure providers, and your content is hosted in the European Union. vvault is operated from Belgium, so the GDPR applies to us directly.

What we do not have

Security pages usually list only wins, which is why nobody believes them. vvault has not had a third-party firm penetration-test the platform. We hold no SOC 2 or ISO 27001 certification. There is no bug bounty programme and no automated threat-monitoring vendor — reports reach a person, not a queue. And end-to-end encrypted messaging is iOS only: messages sent from the web app are protected in transit and at rest, but they are not end-to-end encrypted.

All four are on our Trust & Security page, and they will stay there until they are no longer true. If you find a vulnerability, email vvaultapp@gmail.com — it goes straight to the person who maintains the platform, and we will not pursue you for reporting something in good faith.

Related articles

Ready to send music like a pro?

Start free