Application Security

Zero-knowledge encryption protects your identity data. We can't see your passwords, personal information, or recovery phrase. Even if we wanted to.

Security by Design

How we protect your data

We Can't See Your Data

Zero-knowledge encryption means your data is encrypted on your device before it reaches our servers. We never have access to your encryption keys.

Anti-Phishing Protection

Your unique security marker proves you're on the real WIGGWIGG site (if you turned it on at sign-up or in Settings). Its seed is stored sealed under a key derived from the first characters of your password, so a stolen database can't mass-render markers.

Modern encryption, built from audited libraries

Hybrid encryption: AES-256-GCM for the content, with the content key sealed by X25519 key agreement, HKDF-SHA256 derivation and XChaCha20-Poly1305, built from the same primitives behind Signal and TLS 1.3.

Canadian Company, Protected Data

Canadian company subject to Canadian privacy laws (PIPEDA). Zero-knowledge encryption ensures your sensitive data is protected regardless of server location.

Your Data, Your Control

WIGGWIGG uses zero-knowledge architecture, meaning your identity data (names, addresses, passwords, notes) is encrypted on your device before upload. One exception: the forwarding phone number on an identity is server-readable so we can route calls.

We cannot see your passwords, personal information, or recovery phrase. No one at WIGGWIGG can decrypt your data. Not even with legal requests.

Client-side encryption

No server access to keys

You control your data

No password resets

Deep Dive

Application Security Documentation

Learn how we protect your identity data with zero-knowledge encryption

Zero-Knowledge Encryption

We can't see your data, even if we wanted to

  • AES-256 encryption

  • Client-side encryption

  • No key access

  • Encrypted before it leaves your device

Learn more about application security

Anti-Phishing Protection

Built-in protection against phishing attacks

  • Security marker

  • Visual verification

  • Unique avatar

  • Audio signature

Learn more about application security

Recovery Phrase

Your only way to recover access if you lose your password

  • Your only backup

  • 24-word security

  • Offline storage

  • No password reset

Learn more about application security
How It Works

Multiple Layers of Protection

Every piece of your identity data is protected by multiple security layers working together

Learn more about how we protect your communications: Communications Security

Common Questions About Application Security

What is zero-knowledge encryption?

Zero-knowledge encryption means your data is encrypted on your device before it reaches our servers. We never have access to your encryption keys, so no one at WIGGWIGG can decrypt your identity information, passwords, or personal data. Only you can unlock your data with your password.

What happens if I forget my password?

If you forget your password, you can restore access using your 24-word recovery phrase. This is why we strongly recommend saving your recovery phrase in a secure location when you first create your account. Without your password or recovery phrase, we cannot recover your account. This is by design to protect your privacy.

How does anti-phishing protection work?

Before you enter your full password, we show you a unique security marker (phrase, color pair, and avatar, with an optional audio signature) that only the real WIGGWIGG can display, if you turned it on at sign-up or in Settings. Its seed is stored sealed under a key derived from the first characters of your password, so a stolen database can't mass-render markers. If your security marker doesn't match, don't enter your password. You're likely on a fake site.

Can WIGGWIGG employees see my data?

No. Your identity data (names, addresses, passwords, notes) is encrypted on your device before upload. Even if we wanted to, we cannot decrypt your information. We use zero-knowledge architecture specifically so we cannot access your data. Not even with legal requests. One exception: the forwarding phone number on an identity is server-readable so we can route calls.

What's the difference between application security and communications security?

Application security covers your identity data (names, passwords, personal details). Communications security covers phone calls and SMS/MMS messages. For communications protected by our current sealing method, stored content is sealed to the account communication key, which a supported client opens after sign-in and unlock. A small set retained from the private beta remains readable under our older server-side encryption until a separate re-sealing process. For communications sealed this way, the difference from the vault is not the protection at rest but when that protection begins: we choose to scan SMS and MMS in real time, in memory, before encryption. Preservation or reporting duties can apply if review confirms the content is illegal. A few named exceptions stay readable by our servers; they are listed on the Communications Security page.

How do I know my data is actually encrypted?

Encryption of your vault, identities and contacts happens in your browser with Web Crypto and audited JS/WASM libraries. You can inspect network traffic to verify that this content is sent to our servers as ciphertext. Operational data and telephone content in transit follow separate paths and may be readable by our servers or providers, as described on the Communications Security page. For inbound messages protected by our current sealing method, the one-time key is sealed to the account communication key, which a supported client opens after sign-in and unlock. A small set retained from the private beta remains readable under our older server-side encryption until a separate re-sealing process.

What if WIGGWIGG gets hacked?

Even if someone breaches our servers, your identity data and vault remain protected. All they would find is encrypted ciphertext that cannot be decrypted without your password. We never store your password, and we never store an encryption key in a form we can open. This is the core principle of zero-knowledge architecture.

Can I export my data?

Yes. You can export your account data (JSON or HTML) and your vault (Bitwarden JSON or CSV, unencrypted, for moving to another manager). Encrypted-only fields stay encrypted in the account export; WIGGWIGG cannot open them.

Ready for Zero-Knowledge Security?

Get started with WIGGWIGG today and experience true data privacy