Security & Trust
Security is treated as a foundational requirement of Han Lu, not an optional layer.
Hardware Authentication
All authenticated accounts require hardware security keys (WebAuthn / FIDO2). Password-based authentication is not used.
Encryption
Sensitive records (notes, credentials, and designated data) use end-to-end encryption. Zero-knowledge design is applied where appropriate so that content remains inaccessible without the user’s keys.
Guest Portals
Guest access operates under independent encryption contexts. Each portal is strictly scoped, time-controllable, and immediately revocable by the creating member.
Access Codes
Two-word access codes grant visibility solely to the resources explicitly attached to them. They do not provide broader account access.