A proximity session has a budget. Contact invites and share manifests fit. PDF scans usually do not—so attachments leave on a bulk plane after SDP exchange, not stuffed into every control frame.
If a proximity bootstrap can live in an ordinary https link, the authenticator has already toured browser history, referrers, and OS camera → URL launch paths.
Ciphertext and the secret that opens it should not travel as one convenient email. NT² splits carriers—file or link—from OOB passphrase delivery, and treats Strong as machine-handoff.
Estate and emergency access tempt products to hold a second key “just in case.” NT² refuses that oracle. Legacy is a sealed package on a delay—not a support console unlock.
After a share leaves your vault, “did they open it?” and “can I kill it?” are sender questions. The answers live in a local outbox—not a cloud mailbox of readable mail.
Blind sync is easier to trust when you can picture the packet. The edge sees shapes, sizes, and progress—not titles, notes, or a searchable attic of your secrets.
Many apps call themselves offline-capable when they mean a read-only cache and a queue that hopes the tower returns. A local-first vault puts full CRUD on the device first. Sync is an optional second path.
Zero-knowledge is not a slogan about HTTPS. It is a permission list for the edge: what Workers may store, route, and bill for—and what they are never allowed to learn.
The link opens in a browser. The content stays encrypted until the recipient enters a share passphrase you chose. That is a different habit from attaching a file.
Self-sovereign identity is useful when you take the parts that fit a zero-knowledge vault—and refuse the parts that turn the product into a general DID wallet.
A cloud can help deliver sealed packages without becoming the place where pending shares live as readable mail. Relay indexes ciphertext. Inbox stays on the device.
Apple Notes was perfect for grocery lists, travel ideas, and quick reminders. Then it became the place for passport numbers, seed phrases, and bank details.
A share that opens with the same secret that unlocks the vault is not a handoff. It is a remote unlock of everything. NT² keeps those boundaries apart.
Cloud services often treat an email inbox as the root of an account. An encrypted vault needs a different proof: control of a signing key, shown by answering a one-time challenge.
An account table can contain no plaintext vault items and still create a dangerous password-testing surface. We removed the columns that could turn a database copy into an offline guessing or recovery system.
A vault does not need to enter a shared plaintext mailbox to sync. Its public cryptographic identity can name a dedicated edge coordinator that notifies replicas and points them to encrypted frames it cannot open.
Sync does not have to turn a local vault into a cloud database. The edge can identify an account, store opaque replica frames, and deliver updates without learning what those updates contain.
One screen can make two security events look like a single login. We keep them separate because opening encrypted data and proving an identity to a server are different jobs with different risks.
In the era of massive cloud-first applications, we often overlook a powerful alternative: the Progressive Web App (PWA). Why maintain a heavy, expensive, and potentially vulnerable server infrastructure when the modern browser is capable of running a full-featured, secure, and high-performance application entirely on the user's device?