2xBROpen local vault ↗
SIGNATURE / LOCAL WORKSPACE / VAULT V1.0

Keep it here.
Not forever.

VAULT is intentional browser-local workspace for objects you need again after this tab or session. Every item has an expiry. Protected items encrypt both bytes and private metadata before IndexedDB storage; nothing is uploaded.

Open VAULT →
STORELOCAL / INDEXEDDBEXPIRE1H / 24H / 7DPROTECTAES-256-GCMCONTINUEHANDOFF / TOOLS
LOCAL WORKSPACE / INDEXEDDB0 ITEMS0 B STOREDBEST-EFFORT STORAGENO SERVER PAYLOAD
EXPIRES AUTOMATICALLY

VAULT v1 has no “forever” mode. You can extend an item explicitly later.

OBJECT NONETTL 24 HOURSMODE LOCALLIMIT 128 MB

Protected mode encrypts stored data at rest. It does not protect a passphrase typed into an already compromised page, browser profile or operating system.

03 / LOCAL LIBRARY

Working set with an exit date.

Expired records are removed automatically when VAULT opens. Browser storage can still be cleared by the browser, profile cleanup or the user.

0ITEMS
VAULT 0 B / 512.00 MB SOFT LIMITBROWSER ESTIMATE UNAVAILABLE
EMPTY / LOCAL

No stored objects.

Use VAULT directly or send an output here through HANDOFF.

DROP FILE / SAVE LOCALLY
01 / INTENTIONALNot a cache pretending to be a product.

Every saved object has a visible lifetime, explicit delete action and bounded local storage ceiling. Expired objects are purged automatically when VAULT opens.

02 / PROTECTEDEncrypt bytes and metadata at rest.

Protected entries use PBKDF2-SHA-256 and AES-256-GCM with random salt/IVs. The passphrase is never stored. Losing it means losing access.

03 / VERIFIEDRestore only matching bytes.

VAULT stores the original SHA-256 inside the entry metadata and verifies the restored file before download or routing.

04 / BOUNDARYLocal storage is not magic security.

Encryption protects stored data at rest. It cannot protect a passphrase typed into an already compromised page, browser profile or operating system.