PRESERVED RESEARCH • INDEPENDENT KEYS • TWO AUTHENTICATED LAYERS
One private vault.
Two separate inputs.
Protect notes and attachments with your passphrase, then wrap that encrypted layer with a visual-pattern key. Keep both inputs and the downloaded vault yourself.
1. Keep your two inputs
No server can reset or recover either input. Use a password manager and keep the pattern separately.
2. Protect or restore
The label, note and attachment metadata are encrypted together. Add a note, a file, or both.
Save the downloaded .zmath file. This copy contains ciphertext, not your note or inputs.
Maximum vault size: 20 MiB. A selected file takes priority over pasted JSON. This opens Shield .zmath v1 files, not ZME1 or .ztz formats.
Separate derivations
Each layer uses its own random 32-byte salt, PBKDF2-HMAC-SHA-256 at 600,000 iterations, a non-exportable AES-256-GCM key and random 12-byte IV.
Portable recovery
The .zmath file has everything needed except your two inputs. Timestamp and algorithm metadata remain visible; the label, note and original filename are encrypted.
Local source custody
The original Shield module and six tests are preserved byte-for-byte. The new interface has no remote API, tracking, browser key store or login.