Skip to content

Architecture

VaultKeepR is split into an open-source core and private clients. The vaultkeepr-public repository holds the cryptographic SDK packages (MIT licensed, published to npm under the @vaultkeepr scope) and the Solidity contracts. The web app, browser extension, and iOS/Android apps live in a private repository.

PackageRole
@vaultkeepr/coreVault crypto: XChaCha20-Poly1305, Argon2id, ECIES envelopes, TOTP, passkeys, BIP-39, import/export for 10+ manager formats
@vaultkeepr/syncCross-device synchronization built on Automerge CRDTs
@vaultkeepr/ipfsContent-addressed vault storage: CID handling and multi-gateway fetching with failover
@vaultkeepr/recoveryFragmented recovery with on-chain contract reads on Base
@vaultkeepr/smart-accountERC-4337 account abstraction: identity derivation and on-chain sync
@vaultkeepr/wallet-messagesEIP-4361 and delegation message schemas for signed sessions
@vaultkeepr/cloudZero-knowledge encrypted cloud storage (S3-compatible)
@vaultkeepr/loggerStructured logging that redacts keys, CIDs, and addresses
@vaultkeepr/legacyDigital inheritance types and beneficiary management

Other packages cover premium license validation, email aliases, i18n (English and French), shared UI components, Sentry adapters, and native OCR (VisionKit on iOS, ML Kit on Android). Install the core with npm install @vaultkeepr/core.

Three Solidity contracts are deployed on Base L2 and covered by Foundry tests:

ContractPurpose
VaultKeeperCidRegistryOn-chain registry of vault location pointers
VaultKeeperFragmentsOn-chain storage for recovery fragments
VaultKeeperLegacyTime-locked inheritance to named beneficiaries

The contracts hold public pointers and encrypted payloads only. They never hold keys or funds.

DataWhere
Vault plaintextDevice memory only, while unlocked
Derived keysDevice memory (SessionKeyStore holds session copies)
Master passwordUser’s memory only; never transmitted or stored
Encrypted vault snapshotsIPFS and S3-compatible storage, addressed by CID
Recovery fragmentsIPFS, plus pointers in the VaultKeeperFragments contract
Vault location pointersVaultKeeperCidRegistry on Base L2
Legacy instructionsVaultKeeperLegacy, time-locked, encrypted payloads

Hosted APIs support the client workflows without replacing end-to-end encryption. They accept already-encrypted vault payloads for pinning or relay, verify wallet signatures, and record the current CID for an address. Other endpoints can serve non-secret metadata, such as fragmented-recovery manifests keyed by a hash of a recovery identifier. Nothing in this design assumes a server can decrypt your vault. Exact routes and deployments may change; the open-source packages remain the reference for implementers.