
Security
Effective date:
19 August 2026
Holacrafts is designed so that control over protected content stays with the user.
Security is built into the architecture of Holacrafts - from how your content is encrypted to how access is granted.

End-to-end encryption
Your protected content is end-to-end encrypted.
Encryption happens on the client before synchronization, and decryption happens on an authorized client.
Holacrafts infrastructure may store and synchronize encrypted data, but it does not receive the usable decryption keys required to read your protected content.
Encrypted data is not the same as access. Access requires the corresponding cryptographic key.

Local-first by design
Holacrafts is built around a local-first architecture.
Your Space is not simply a view of data that exists only on Holacrafts servers. Data stored locally remains encrypted on your device and can remain accessible through the application without being decrypted by Holacrafts infrastructure.
Synchronization and other network-dependent functionality require Holacrafts services, but server access is not what gives you the cryptographic ability to read your protected content.

Private by default
Private content is accessible only to the owner of the Space.
Access to other people is granted through an explicit user action.
Invite-only access lets you grant access to an intended recipient.
Public Link access makes selected content accessible to anyone who receives the complete link. The decryption secret carried with the complete Public Link is not provided to Holacrafts servers.
You decide what becomes accessible and to whom.

App and web
Holacrafts supports both application and web experiences.
Protected content does not become readable to Holacrafts simply because it is synchronized, shared, or accessed through a supported web experience.
Available functionality may differ between the app and the web, but the same security principle remains: protected content requires the corresponding cryptographic access.

Technical documentation
This page provides a simplified overview of the Holacrafts security model.
More detailed documentation covering the architecture, security boundaries, encryption model, sharing model, and threat model will be available in the Holacrafts public technical documentation.

Contact
For questions, contact us at:
devs@digniti.tech