Locally encrypted
AES-GCM 256 with a random IV per item and a key derived locally with PBKDF2-SHA-256.
Security
Local storage is not a security shortcut. ArchitekIA separates storage, decryption, preview and sharing.
AES-GCM 256 with a random IV per item and a key derived locally with PBKDF2-SHA-256.
Imported files remain encrypted bytes. No file is executed automatically and imported SVG is never injected into the DOM.
default-src 'none'The CSP starts from default-src none, uses nonce-bearing scripts and strict-dynamic, loads no remote font and requires no network connection for the local space.
Two-year HSTS with subdomains, nosniff, no-referrer, frame-ancestors none, COOP, COEP, CORP, Origin-Agent-Cluster and a restrictive Permissions-Policy.
Only HTTP and HTTPS links without embedded credentials are accepted. The selected file is never uploaded to the server. ArchitekIA reads only useful titles, URLs and folders, then encrypts imported bookmarks in your local vault.
No tracker · No forced cloud · No account.
Local encryption protects content at rest. It cannot protect an already compromised device, a malicious browser, an intrusive extension or a weak passphrase.
Encrypted backups remain essential so local storage is not mistaken for permanent archiving.