16 April 2026

Your Documents Are Encrypted

Why Your Documents Are Encrypted Before They Ever Get to Our Server.

This is the question that separates a genuine security tool from a marketing claim: "What if you get hacked?"

The answer matters, which is why we built Agathon around a specific encryption model that makes that question less catastrophic.

Every document you upload to Agathon gets encrypted twice. First, we encrypt your document with its own unique encryption key. Then, we encrypt that key with another key. This is called envelope encryption, and it's the same approach used by banks, governments, and anyone else handling genuinely sensitive material.

Why two layers? Because it means a breach doesn't hand over your entire vault in one go. Compromising the encrypted documents without the keys is like stealing a locked safe — the money's still locked inside. Compromising the keys without the documents is like stealing the combination to an empty vault. You need both to get anywhere, and they're managed separately.

Your two-factor authentication secret — the code that generates your login codes — gets the same treatment. It's encrypted at rest. It's shown to you exactly once, the moment you set it up. After that, it's not re-displayed, not logged, not accessible through any "forgot my secret" flow. This mirrors the best practices used by places like Amazon and Google: a secret that only needs to be seen once shouldn't be casually re-shown.

The underlying principle is simple: a dead man's switch holds some of the most important information in your life. Trust can't be claimed in a marketing line. It has to be built into the architecture. Encryption at rest, key separation, and one-time secret disclosure aren't luxuries. They're the foundation.

« Back to News