Most apps ask you to believe they'll keep your data safe. Threadlock is built so belief isn't required — your data is locked before it ever reaches us, with keys only you hold. Here's exactly how.
"Zero-knowledge" means we have zero knowledge of your content. Your messages, files, notes, and passwords are encrypted on your own device — turned into unreadable code — before they're ever sent to our servers. The key that unlocks them never leaves your device and is never shared with us.
So even if someone broke into our servers, or a court ordered us to hand over everything, all they'd get is scrambled data we can't unlock. We didn't just promise not to look — we built the system so we can't.
Everything starts on your device — your phone or computer — where only you have access.
Before anything leaves, it's scrambled with AES-256 — the same encryption standard trusted by banks and governments worldwide. The key is derived from your passcode and stays on your device.
We receive and store an unreadable encrypted blob. We never see the original — not the text, not the file, nothing.
The data stays encrypted the entire way. It's only decrypted at the other end, by someone who holds the right key. End to end.
Military-grade, industry-standard encryption on your content — the gold standard, unbroken in practice.
Your encryption keys are derived on your device from your passcode. We never receive or store them.
Passcodes are put through PBKDF2 key-stretching — never stored in plain form, hard to brute-force.
Optional protections that show a fake vault under coercion, so a forced unlock reveals nothing real.
Secure Send links can expire or delete after one view — no lingering copies left behind.
We don't profile you, sell data, or run ads. There's no business reason for us to hoard your information.
We will never tell you Threadlock is "unhackable." No system is, and anyone who claims otherwise is selling you something.
What we will tell you is the truth: the things you lock stay locked, because we designed the system so we can't open them. The things a service genuinely needs to function — like your email address to send you a notification — a server has to be able to read, and we're upfront that this is true of every app, not just ours.
Real security isn't a marketing claim. It's an architecture you can understand — and we'd rather explain it honestly than dazzle you with promises we can't keep.
Encrypt. Send. Protect. — the way it should have been all along.
Open Threadlock →