Your identities and their vaults are client-side encrypted. Only you hold the keys. We can't see your passwords, credentials, or personal information. Built secure from day one.
We protect your data in two distinct ways: Application Security (zero-knowledge encryption for your identity data) and Communications Security (privacy-first handling of phone calls and messages).
Zero-knowledge encryption, authentication, and account recovery systems that protect your identity data.
Zero-knowledge encryption, authentication, and account recovery systems that protect your identity data.
How we handle phone calls and messages while minimizing data collection and complying with telecom laws.
How we handle phone calls and messages while minimizing data collection and complying with telecom laws.
Security isn't an afterthought at WIGGWIGG. It's our foundation. We use zero-knowledge encryption for your identity data and implement privacy-first practices for all communications.
Security isn't an afterthought at WIGGWIGG. It's our foundation. We use zero-knowledge encryption for your identity data and implement privacy-first practices for all communications.
Your password opens the door. A second factor checks that it's really you. And neither one decrypts your data for you.
A passkey replaces the code you type with what your device already knows how to do: your fingerprint, your face, or the device PIN.
A six-digit code that changes every 30 seconds, generated by the authenticator app of your choice.
Before you turn on your very first second factor, we ask you to have a recovery key in place: the 24 words you write down and keep. Nobody here can reset your keys for you: a lost device must never be able to lock you out for good.
Before you turn on your very first second factor, we ask you to have a recovery key in place: the 24 words you write down and keep. Nobody here can reset your keys for you: a lost device must never be able to lock you out for good.
A passkey and an authenticator code protect access to your account. They don't unlock your data: the key that decrypts your vault and your identities is derived from your password, and your 24-word recovery phrase remains the only way to rebuild it.
A passkey and an authenticator code protect access to your account. They don't unlock your data: the key that decrypts your vault and your identities is derived from your password, and your 24-word recovery phrase remains the only way to rebuild it.
Explore our multi-layered security architecture. Each layer protects you differently, and together they provide defense in depth.
Your password never leaves your device. We prove you're you using cryptographic signatures, not by storing your credentials.
How Authentication WorksTwo-way authentication where the website proves its identity to you before you enter your full password.
How Anti-Phishing WorksYour ultimate backup: a 24-word phrase that can restore account access when you've lost everything else.
How Recovery WorksUp to five checks, depending on the channel, assess calls, texts, and MMS. Carrier lookup and community reports have their own switches; STIR/SHAKEN and neighbor-spoof are always read when they apply.
How the Spam Filter WorksThe full technical account: threat model, cryptographic architecture, data classification, and an honest list of our limitations. Written for a skeptical, technical reader.
Read the WhitepaperFound a flaw? Here's how to report it, in good faith and without fear: our scope, the rules, a real safe harbor, and what to expect in return.
Read the Disclosure PolicyOur public commitment to platform integrity. What WIGGWIGG is for, what it must never be used for, and how we enforce it.
Read Our CommitmentDiscover a better way to manage separate identities, sealed with zero-knowledge encryption.