Security and two-key encryption strategy
Caregiver Dashboard uses a zero-knowledge, two-key model so the server stores encrypted data and encrypted key envelopes, but does not hold the secrets needed to decrypt family care data in plaintext.
What "two-key" means
- Each user has a personal RSA key pair generated on-device.
- Each family has a separate symmetric Family Key used to encrypt care payloads.
- The Family Key is wrapped (encrypted) for each authorized user with that user's public key.
- Only a device with the matching private key can unwrap the Family Key and decrypt family records.
Result: server-side services can store and route encrypted envelopes, but cannot decrypt family data because private keys are never server-owned.
How it works in practice
- On account creation, the app generates a personal key pair on-device.
- The private key is encrypted locally using a passphrase-derived key.
- A random 32-byte Family Key is generated for the family context.
- App data is encrypted with the Family Key before it is written to sync payload envelopes.
- When inviting a member, the Family Key is wrapped for the invitee's public key and stored as an envelope.
- On login, the user unlocks their private key, unwraps the Family Key, then decrypts family payloads.
Encryption type and strength
| Layer | Algorithm | Strength details | Use |
|---|---|---|---|
| Payload encryption | AES-256-GCM | 256-bit key, 96-bit IV (12 bytes), 128-bit auth tag | Encrypts care payload envelopes with confidentiality plus integrity/authentication (AEAD). |
| Family key wrapping | RSA-OAEP with SHA-256 (recorded as RSA-OAEP-256) | 3072-bit RSA modulus, OAEP padding, SHA-256 hash | Encrypts the Family Key per authorized user. |
| Private-key protection | PBKDF2 + AES-256-GCM | Default PBKDF2-SHA-256 with 210,000 iterations and 16-byte salt, then 256-bit AES-GCM key | Encrypts the user's private key at rest on device storage. |
Integrity and tamper resistance
- AES-GCM provides authenticated encryption, so tampered ciphertext fails verification during decryption.
- Additional authenticated data (AAD) binds envelope metadata such as circle/family scope, entity type, and key version.
- Key rotation and member-removal flows re-wrap Family Keys so access can be revoked without exposing plaintext data.
Important note
This page is a high-level explanation for product users and operational stakeholders. It does not replace security reviews, threat modeling, or compliance controls.