Trust & Safety
Built on security from day one
Anchora was designed with the assumption that the data inside is irreplaceable. Every layer of the platform exists to protect that data - at rest, in transit, and at the moment of release.
Encryption at rest
All vault records are encrypted with AES-256 before being written to the database. Encryption keys are managed and rotated securely, separately from the encrypted data itself.
Encryption in transit
Every connection between your browser and Anchora servers is protected by TLS 1.3. We enforce HSTS and reject downgrade attempts.
Restricted vault access
Vault contents are protected by strict access controls and only accessible through your authenticated session. Internal access is limited, monitored, and logged.
Multi-factor authentication
MFA is available on all accounts and required for high-sensitivity actions. We support authenticator apps (TOTP) and email-based one-time codes.
Rate limiting & abuse prevention
All API endpoints are rate-limited. Authentication endpoints implement progressive backoff and account lockout after repeated failed attempts.
Immutable audit logs
Every action in the platform - login, vault edit, trusted contact change, release stage - is written to an append-only audit log. Logs are retained for a minimum of three years.
The staged release safeguard
Releasing your vault records to your trusted contact is irreversible. Anchora requires multiple independent confirmations before any release proceeds.
- 1
Inactivity detection
Anchora detects that no login or account activity has occurred within your configured window.
- 2
Escalating notifications
Multiple warning emails are sent to you across several days. Any normal account activity immediately resets the inactivity counter.
- 3
Trusted contact identity verification
Your trusted contact verifies their identity as an added layer of confirmation, alongside being guided through discovery of the released records.
- 4
Staged discovery process
Your trusted contact is guided through discovery for each asset in a controlled sequence, with each stage requiring confirmation.
Responsible disclosure
If you discover a security vulnerability in Anchora, please report it to us privately. We take all reports seriously and will respond within 72 hours.
Report a vulnerabilitysecurity@anchora.com.ng - PGP key available on request.