Vault Security
Marvelist Vault is an optional feature that adds an extra layer of encryption to the contents of lists
you choose to protect. When you protect a list, its tasks, notes, checklist items and comments are
encrypted with keys unique to your account before they are written to our database, so those contents
cannot be read directly from the database, a backup, or an export.
What Vault Adds
All Marvelist data is already encrypted at rest at the storage layer (Azure Storage Service Encryption with platform-managed keys) and in transit (TLS). That baseline is transparent — the database decrypts on every read — so it isn't what makes Vault different.Vault adds application-layer encryption: the contents of a protected list are encrypted before
they are written to the database, so reads of those values return ciphertext rather than readable text.
Key Management (envelope encryption)
- A single root key lives in a secrets manager (Cloudflare Secrets Store), a separate trust boundary from the database.
- Each user has a personal key, stored only in wrapped (encrypted) form.
- Each protected list has its own content key, used to encrypt that list's content.
- The content key is wrapped by the user's personal key, which is wrapped by the root key.
- The application can unwrap these keys in-process to serve a protected list to its owner or collaborators. This is a deliberate design choice: it makes Vault compatible with sharing, sync and normal app behaviour, at the cost of not being zero-knowledge.
- At enrolment, a one-time, high-entropy recovery code protects a second wrapped copy of the user's personal key as a break-glass backstop. Marvelist does not store the recovery code.
Algorithms
AES-256-GCM for content, AES Key Wrap for keys, and PBKDF2 to derive the recovery key.The Separation that Matters
The protection boundary is the gap between the database and the key store. A copy of the database — a dump, backup, binlog or query log — does not contain the root key, so protected content stays ciphertext.Threat Model
Leaked/stolen database dump, backup, binlog, or query log
Protected by Vault? – Yes – yields only ciphertext; the root key is in a separate store.
Someone reading the database directly without the key store
Protected by Vault? – Yes.
The Marvelist assistant / AI connectors seeing the content
Protected by Vault? – Yes – protected lists are excluded entirely.
Sensitive text leaking into push notification payloads
Protected by Vault? – Yes– notifications are genericised.
A compromised live server, or a malicious/compelled operator with access to the running app + key store
Protected by Vault? – No – the running app can decrypt to serve the data.
A collaborator you shared the list with
Protected by Vault? – No – by design they can read it.
Lost device
Protected by Vault? – Not a data-loss event – keys are server-held; the recovery code is an extra backstop.
Have a question about this policy?
Reach out to Tophhie Cloud if you have any questions, concerns, or requests relating to this policy. We'll get back to you as soon as we can.